20 July 2026
5 Microsoft 365 Settings Worth a Second Look in Your Tenant

Photo by cottonbro studio on Pexels
A Microsoft 365 tenant set up three or four years ago, and left alone since, is running a different security posture to one Microsoft would hand you today. Not because anyone made a bad decision at the time. Because Microsoft keeps quietly raising the bar for new tenants, and none of those changes apply retroactively to the one you already have.
That gap tends to show up most clearly when a business switches IT provider and someone finally goes looking through the tenant properly for the first time in years. Settings that were correct when they were set stay exactly where they were, no matter how many rounds of "secure by default" changes Microsoft has shipped since.
Below are five worth checking, in the order we'd actually work through them, starting with the ones nobody will notice and finishing with the one that needs the most care. A couple require Business Premium, E3 or E5 licensing to change, so if a toggle is greyed out, that's most likely why.
Start with the settings nobody will notice
These two can be checked and, if needed, changed without generating a single support ticket. Get them out of the way first.
What third-party apps are still holding permissions from years ago
Since mid-July 2025, Microsoft has been switching any tenant still running its older "let users consent to anything" setting over to a tighter default. Under the new one, a user can no longer approve a third-party app that's asking for high-risk access, such as reading files in OneDrive or SharePoint, on their own. Only an admin can grant that now. Apps asking for low-risk permissions from a verified publisher can still get self-service consent.
That only governs requests going forward, though. Anything a member of staff approved before the switch, including tools from a project that wrapped up two years ago, or an app someone tried once and forgot about, keeps whatever access it was originally given.
Microsoft Entra ID > Enterprise Applications > All applications, sorted by user consent, shows what's actually holding access to mail, files or calendars right now. Anything unrecognised or no longer in use can be revoked from the same screen. Budget half an hour to an hour, more if the list is long.
How far back your audit trail actually goes
Since 17 October 2023, standard audit log records have been kept for 180 days by default, up from 90. If you're on Microsoft 365 E5 or have the Purview Audit add-on, core records (Exchange, SharePoint, OneDrive, Entra ID) hold for a year by default, extendable further.
For most businesses that's plenty. For a firm bound by a professional body's own record-keeping expectations, a default measured in months might not match what your regulator or insurer expects you to be able to produce on request. Worth checking against whatever your industry actually requires before assuming the Microsoft default is good enough.
The setting lives in the Purview compliance portal under Audit > Audit retention policies. Extending it past 180 days needs E5 or the add-on. Once the licensing's confirmed, changing the policy itself takes about 15 minutes.
Then the two that will need a quick heads-up to the team
Neither of these is difficult to change. Both will eventually prompt a question from someone who's used to doing things the old way, so a short heads-up beforehand saves a confused support ticket later.
Whether email can still be auto-forwarded to a personal address
Microsoft's outbound spam policy now blocks automatic forwarding to external addresses by default, closing off a route that used to let a departing employee, or a compromised account, quietly redirect a mailbox's contents outward. The setting has three states: off, on, or "automatic, system-controlled" (which now behaves the same as off).
Two things worth checking. First, that your tenant's outbound spam policy is actually set to off or automatic, not on, in the Microsoft Defender portal under Email & Collaboration > Policies & Rules > Anti-spam policies. Second, and more important, that no inbox rule set up before this became the default is still quietly forwarding somebody's mail externally. The tenant-level block stops new rules, it doesn't retroactively remove one that already exists. The Purview audit log lets you search for inbox rule creation events if you want to check.
What happens when someone clicks "share"
A file shared from SharePoint or OneDrive gets a link, and that link has a default scope. On an older tenant that's never had the setting touched, that default is often "anyone with the link", meaning whoever receives the URL can open the file without signing in at all. No expiry, no record of how many times it's been forwarded on.
Newer SharePoint sites created through Teams already default to "only people in your organisation". The tenant-wide default for everything else, though, doesn't shift on its own. It sits in the SharePoint admin centre under Policies > Sharing, and switching it to "specific people" means every new link needs the recipient to sign in. Existing links keep behaving as they always have until they're regenerated, so this won't retroactively lock anyone out of a file they're already using.
Worth a short note to the team before flipping this one. Anyone in the habit of sharing a link and pasting it straight into an email will notice the recipient suddenly needs to authenticate.
If Microsoft 365 Copilot is anywhere on the roadmap, this particular setting matters even more than usual. Copilot can only surface what a user's existing permissions already allow, so a sharing default left wide open here is exactly the kind of gap worth closing before a Copilot rollout, not after.
The one that deserves the most care: MFA enforcement
Security Defaults, Microsoft's baseline multi-factor authentication setting, has been switched on automatically for every new tenant created since 22 October 2019. A tenant older than that has no baseline MFA enforcement unless somebody turned it on by hand.
The usual complication is what happens when Conditional Access gets introduced later. Conditional Access, available from Business Premium upward, is the more flexible way to enforce MFA, and Microsoft expects it to take over from Security Defaults rather than run alongside it. If that handover was done in a hurry, it's easy to end up with Security Defaults switched off and a Conditional Access policy that doesn't actually cover everyone, most often admin accounts or a break-glass emergency login that got excluded on purpose and never revisited.
Three places to check: Entra ID admin centre under Properties > Manage Security Defaults, to see whether it's on or off; Protection > Conditional Access, to confirm a policy is enforcing MFA for every user including admins; and specifically, any break-glass account, to make sure "excluded for emergency access" hasn't quietly become "excluded, full stop".
Microsoft is also removing the option to skip this. MFA became mandatory for admin actions in the Azure portal, Entra admin centre and Intune admin centre from October 2024, reaching every Azure tenant by March 2025. The Microsoft 365 admin centre itself started phasing in the same requirement from February 2025, with full enforcement due to land by February 2026. Whatever your tenant's current MFA coverage looks like, admin accounts are heading toward mandatory MFA regardless of what you decide, so there's an argument for getting ahead of it on everyone rather than waiting for Microsoft to force the issue.
Budget the most time for this one, and don't try to do it in the last twenty minutes of a Friday. It's the change most likely to lock someone out if it's rushed.
None of this needs doing in one sitting
The two silent checks cost less than a couple of hours between them and can happen today. The forwarding and sharing settings are worth a short message to the team before you touch them. MFA is worth its own properly scheduled slot, not squeezed in around something else.
If your Microsoft 365 tenant came with the business, was set up by whoever had IT before you switched providers, or simply hasn't been looked at since it was first configured, a proper review is part of our Microsoft 365 and cloud work. Get in touch if you'd rather have someone else work through this list.
