Microsoft has strengthened several default settings in Microsoft 365 over the past few years. Newer tenants get better protection out of the box than tenants configured in 2021 or earlier. The problem is that legacy settings stay in place — a default tightened for new tenants in 2024 doesn’t automatically update in yours, and older sharing links, inbox rules, and app consents established before the change remain active.

If your Microsoft 365 environment is more than two or three years old, was set up by a previous IT provider, or Hasn’t been reviewed recently, these five settings are worth verifying.

A couple of notes before you start: some of these require Business Premium, E3, or E5 licensing, so grayed-out toggles usually indicate a license tier issue rather than a configuration problem. And a few of these changes will generate support requests from your team because they alter how something already works. None of them need to happen simultaneously.

1. The Default Sharing Link in SharePoint and OneDrive

When someone shares a file from SharePoint or OneDrive, the link they generate has a default scope. In tenants configured before Microsoft tightened new-site defaults, that scope is often “Anyone with the link” — meaning anyone who receives the URL can open the file without signing in, with no expiration and no record of who forwarded it.

Newer Teams-created sites now default to “Only people in your organization.” Older sites and the tenant-level setting often still allow Anyone links. A departing employee who emailed a proposal to their personal account six months ago may still have a working link.

The default sharing link type sits in the SharePoint admin center under Policies → Sharing. Switching the tenant default to “Specific people” requires authentication for every new link. You can also set a maximum expiration period for any remaining Anyone links so they time out automatically. Rough time to change: about 15 minutes, with no impact on existing links until they’re regenerated.

2. External Email Forwarding Rules

Microsoft now blocks automatic email forwarding to external addresses at the tenant level by default, through the outbound spam policy. This change rolled out as part of Microsoft’s secure-by-default effort.

Forwarding rules created before that change can still be active, though. Tenants with custom outbound spam policies configured years ago may not reflect the current default. A user who set up a rule three years ago to forward every email to their personal Gmail address may still be doing so.

Verify two things: in the Microsoft Defender portal under Email & Collaboration → Policies & Rules → Anti-spam policies → outbound policy, confirm the “Automatic forwarding rules” setting is off or system-controlled. Then audit existing inbox rules across your users for any forward-to-external configurations. The Microsoft Purview audit log lets you search for inbox rule creation events. The tenant setting takes about 10 minutes to verify; reviewing existing user rules takes longer depending on team size.

3. Historical Third-Party App Consents

Microsoft introduced managed user consent policies in 2025 that prevent most users from consenting to third-party applications requesting access to their files and sites. New consent requests now route to an admin for review.

That change applies going forward. Apps granted user consent before the policy took effect still have whatever permissions they were given, including the ability to read mail, calendars, and files on behalf of the user. Some of those apps may be tools an employee installed years ago and no longer uses.

To review what’s already authorized, go to Microsoft Entra ID → Enterprise Applications → All applications. Sort by consent type and look at what currently has access to mail, files, or calendars. Anything you don’t recognize or no longer need can be revoked from the same screen. Budget 30 to 60 minutes for the review, depending on how many historical apps are in the list.

4. Audit Log Retention

The default audit log retention period in Microsoft 365 changed in October 2023. Standard logs are now retained for 180 days, up from 90. Customers with E5 licensing or the Purview Audit add-on get one year of retention for key services.

If your business operates in a regulated industry — healthcare, legal, financial services — 180 days may not match your retention obligations. HIPAA, the FTC Safeguards Rule, and most state bar rules around client data assume you can produce records on request across periods measured in years, not months. Florida Bar rules on client file retention, for example, extend well beyond a six-month audit window.

Audit retention policies live in the Microsoft Purview compliance portal under Audit → Audit retention policies. Extending retention beyond 180 days requires E5 or the Purview Audit Premium add-on. The configuration itself takes about 15 minutes once you’ve confirmed your license supports it.

5. MFA Enforcement and Security Defaults

MFA enforcement is the setting most likely to be inconsistent in older tenants. Microsoft introduced Security Defaults in late 2019, and the feature enforces MFA for all users, blocks legacy authentication, and protects privileged operations.

Tenants set up before Security Defaults were introduced, or that were configured with Conditional Access policies instead, may have gaps — accounts that were excluded from MFA requirements for convenience and never revisited, or legacy authentication protocols still enabled that bypass MFA entirely.

To check your current state: go to Microsoft Entra ID → Properties → Manage Security Defaults to see if Security Defaults are on. If Conditional Access is handling MFA instead, review the policies for any exclusions, guest account gaps, or legacy authentication exceptions. The risk sits in what’s been excluded, not in the policy itself.

If you’d like to run through any of these in your tenant, we’re happy to take a look.