Across most of the Microsoft 365 tenants we assess, the same handful of gaps show up again and again. None of them require a big project to fix — they just tend to get missed during initial setup and never revisited.
1. Legacy authentication is still enabled
Protocols like POP, IMAP, and older SMTP auth bypass modern MFA prompts entirely. If they're still enabled on your tenant, they're one of the most common entry points for credential-stuffing attacks. Blocking legacy auth is usually a single Conditional Access policy.
2. Admin accounts don't require phishing-resistant MFA
Global Admin and other privileged roles are the highest-value targets in your tenant. A simple push-notification MFA is better than nothing, but it's also the easiest factor to bypass with MFA-fatigue attacks. Privileged accounts deserve a stronger method — a hardware key or certificate-based auth.
3. Mailbox forwarding rules are unmonitored
Auto-forwarding rules that silently copy mail to an external address are a classic sign of a compromised mailbox — and they're rarely reviewed until something goes wrong. A recurring report of external forwarding rules takes minutes to set up and can catch a compromise early.
None of these are exotic findings — they're the kind of thing a structured assessment against a framework like CISA's SCuBA baselines will surface reliably. If you're not sure where your tenant stands on any of these, that's exactly what our M365 Security Assessment is for.