5 Microsoft 365 Settings Worth Checking in Your Tenant

Five Microsoft 365 Settings Older Tenants Should Review

Microsoft has improved many default security settings in Microsoft 365 over the past few years. That is good news for new tenants. But it can leave older tenants with gaps that are easy to miss.

If your Microsoft 365 tenant was created before 2022, some older settings may still be active. Microsoft may have changed the default for new tenants, but that does not always change your tenant. It also does not remove old sharing links, user-approved apps, inbox rules, or other access that was granted in the past.

That means your business may have more exposure than you think. A file link from months ago may still work. An old app may still have access to mail or files. A forwarding rule may still send company email to a personal address.

These are not rare edge cases. They are common in tenants that are more than two or three years old, were set up by a prior IT provider, or have not had a recent security review.

Here are five Microsoft 365 settings worth checking.

Before You Start

A few items on this list may need Microsoft 365 Business Premium, E3, E5, or a Microsoft Purview add-on. If a setting is grayed out, your license may be the reason.

Also, some changes may affect how your team works. You do not need to change everything at once. A careful rollout is better than a rushed one, especially when access and sign-ins are involved.

1. Check the Default Sharing Link in SharePoint and OneDrive

When a user shares a file from SharePoint or OneDrive, Microsoft 365 creates a sharing link. That link has a default scope. In some older tenants, the default may still be “Anyone with the link.”

That setting can create real risk. Anyone who receives the URL can open the file without signing in. There may be no expiration date. There may also be no clear record of who else received the link after it was forwarded.

Newer Teams-created SharePoint sites now default to “Only people in your organization.” But older sites and tenant-level settings may still allow “Anyone” links. So a user who shared a proposal months ago may have created a link that still works today. If that user later sent the link to a personal account, the access may remain unless someone revokes it.

To review this, go to the SharePoint admin center. Open Policies, then Sharing. Look for the default link type.

Changing the tenant default to “Specific people” is safer for most businesses. It requires the person opening the link to authenticate. You can also set a maximum expiration date for any remaining “Anyone” links so they time out on their own.

This change usually takes about 15 minutes. It does not affect existing links until those links are created again. That makes it a good early control to review, but it may need user communication before you change it.

2. Review External Email Forwarding Rules

Automatic email forwarding can send company data outside your business without anyone noticing. A user may have created a rule years ago to forward all email to a personal Gmail account. That rule may still be active.

Microsoft now blocks automatic external forwarding by default at the tenant level through the outbound spam policy. This was part of Microsoft’s secure-by-default work.

But older rules can still be present. Also, tenants with custom outbound spam policies from years ago may not match the current Microsoft default.

You should verify two things.

  • Check the tenant-level outbound spam policy.
  • Audit existing inbox rules for forwarding to external addresses.

In the Microsoft Defender portal, go to Email & Collaboration, then Policies & Rules, then Anti-spam policies. Open the Anti-spam outbound policy. Confirm that “Automatic forwarding rules” is set to “Off” or “Automatic – System-controlled.”

Then review user inbox rules. Look for rules that forward or redirect email to outside addresses. The Microsoft Purview audit log can help you search for inbox rule creation events.

The tenant setting may take about 10 minutes to verify. Reviewing rules across all mailboxes will take longer. The time depends on the number of users and the amount of history in the tenant.

3. Remove Old Third-Party App Consents

Third-party app consent is another area where old access can stay active for years.

In July 2025, Microsoft enabled a Microsoft-managed user consent policy by default. This blocks users from approving most third-party apps that ask for access to files and sites. New consent requests are routed to an admin for review.

That change helps with new requests. It does not remove old approvals.

Apps approved before the policy took effect may still have the access they were granted. Some may be able to read mail, calendars, or files on behalf of the user. Some may be tools used for one project and then forgotten. Others may be apps an employee installed years ago and no longer uses.

To review these apps, go to Microsoft Entra ID. Open Enterprise Applications, then All applications. Sort by user consent. Look for apps with access to mail, files, calendars, or sites.

If you do not recognize an app, review it before you leave it in place. If the app is no longer needed, revoke its access from the same screen.

This review usually takes 30 to 60 minutes. The actual time depends on how many apps are listed. It has no direct user-facing impact unless you remove an app someone still uses.

4. Confirm Audit Log Retention

Audit logs help you understand what happened in Microsoft 365. They can show sign-ins, mailbox activity, file activity, and other events. They matter during security reviews, incident response, and compliance requests.

Microsoft changed the default audit log retention period in October 2023. Audit Standard logs are now kept for 180 days. Before that, the default was 90 days.

Customers with E5 licensing or the Microsoft Purview Audit Premium add-on get one year of retention for Exchange, SharePoint, OneDrive, and Entra ID audit records. Other activity types remain at 180 days.

For some businesses, 180 days is not enough. Healthcare, financial services, legal, and other regulated industries may need records for longer. HIPAA, the FTC Safeguards Rule, and many state bar rules around client data assume records can be produced when needed. In many cases, that period is measured in years, not months.

To review this setting, go to the Microsoft Purview compliance portal. Open Audit, then Audit retention policies. If you need to extend retention beyond 180 days, confirm that your licensing supports it.

The setup itself may take about 15 minutes after licensing is confirmed. The harder part is deciding what your business needs to retain and for how long.

5. Review MFA and Security Defaults

MFA enforcement is often inconsistent in older tenants.

Microsoft introduced Security Defaults in late 2019. New tenants now get MFA protection through Security Defaults. Microsoft has also been making MFA mandatory for admin actions in the Microsoft 365 admin center and Azure portal during 2024 and 2025.

But tenants created before Security Defaults may not have the same baseline protection.

There is also a common setup problem. If an admin enables Conditional Access, Microsoft expects that policy to handle MFA enforcement. Conditional Access is available with Business Premium and above. In some cases, Security Defaults may be turned off once Conditional Access is used.

That can be fine if Conditional Access is configured well. But if the change was rushed, the tenant may end up with Security Defaults off and Conditional Access policies that do not cover every user.

Check three places.

  • In the Entra ID admin center, go to Properties, then Manage Security Defaults. Confirm whether Security Defaults is on or off.
  • Under Protection, then Conditional Access, confirm that an active policy enforces MFA for all users.
  • Pay close attention to administrator and break-glass accounts.

Break-glass admin accounts are sometimes excluded from Conditional Access for emergency access. That can be valid. But if they are excluded and have no MFA, they become a serious risk.

This review may take about an hour. It can take longer if the tenant has several Conditional Access policies that need to be mapped. This is the highest-stakes item on the list because a poor change can lock users out.

A Sensible Order for These Changes

Not every setting has the same user impact. Some reviews are quiet. Others change how people share files or sign in.

Start with audit log retention and third-party app consent. These usually do not affect daily user work. They help you understand what records you keep and what outside apps still have access.

Next, review external email forwarding. This is usually silent unless someone has a real business need for a forwarding rule. In many small businesses, that is rare.

After that, review the sharing default in SharePoint and OneDrive. This change can create questions from users who are used to clicking Share and pasting a link into email. Tell people what is changing before you switch the setting.

Save MFA and Conditional Access for last. This work matters a lot, but it also carries the most risk if handled poorly. Map your current policies first. Confirm who is covered. Review admin and break-glass accounts with care.

Frequently Asked Questions

Are My Microsoft 365 Settings Still Vulnerable if My Tenant Was Set Up Recently?

New tenants get more protection by default than older tenants. But every tenant still needs review. Sharing scope, user-approved apps, and old inbox rules can create risk no matter when the tenant was created.

What Is the Current Default for “Anyone With the Link” Sharing?

Many existing tenants still allow “Anyone with the link” at the tenant level. Newer Teams-created SharePoint sites default to “Only people in your organization.” Check both tenant-level and site-level settings to know what your users actually see.

Did Microsoft Turn Off External Email Forwarding by Default?

Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. But inbox rules created before that change may still be active, so they should be audited.

How Long Are Microsoft 365 Audit Logs Kept by Default?

Audit Standard logs are kept for 180 days as of October 2023. With E5 or the Microsoft Purview Audit Premium add-on, key workloads such as Exchange, SharePoint, OneDrive, and Entra ID can have one year of retention.

Does Security Defaults Cover All Users?

On a new tenant, Security Defaults can enforce MFA across users. On an older tenant with Conditional Access enabled, Security Defaults may have been turned off. In that case, MFA coverage depends on how Conditional Access policies are configured.

Final Takeaway

Microsoft 365 has better default security than it used to. But older tenants can keep older settings. That means your risk may not match what Microsoft now recommends for new tenants.

The biggest gaps are often simple to check. Look at file sharing defaults, external forwarding, old app consent, audit log retention, and MFA enforcement. You may not need to change everything right away. But you do need to know what is active today.

If your tenant has not been reviewed in a while, ask your IT provider to walk through these settings with you. If you do not have an IT provider, Caldera Cybersecurity can help you review what is in place and decide what needs attention.

at-table-with-computer-6803531/” target=”_blank” rel=”noreferrer noopener”>Featured Image Credit

 

This Article has been Republished with Permission from The Technology Press.

Related articles

You may also be interested in

Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.
Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Hot daily news right into your inbox.