Security

Five things a Microsoft 365 audit finds in almost every tenant

After enough tenant reviews the same findings keep appearing — nearly always in environments the client believed were fine.

Queue Bytes 14 May 2026 2 min read

Most tenants we audit were set up years ago, under time pressure, by somebody competent who has since moved on. Nothing is obviously broken. That is exactly why nobody looks.

These five come up again and again.

1. Legacy authentication is still enabled

Basic authentication does not support MFA. That is the whole problem: an attacker with valid credentials bypasses your conditional access entirely by connecting over a legacy protocol.

It usually survives because one application still depends on it — a scanner, an old CRM connector, a reporting tool. The fix is not complicated, but it does require finding out what would break first. Run conditional access in report-only mode for four weeks, read the sign-in logs, deal with whatever appears, then disable it.

2. Admin accounts belonging to people who left

Nine in one recent audit. Two were consultants from a project that finished in 2021.

Privileged role membership drifts quietly because adding someone is a two-minute task with an obvious business reason, and removing them is nobody’s job. A quarterly review of privileged roles takes twenty minutes and is the highest-value recurring security task most organisations are not doing.

While you are in there: check that break-glass accounts exist, are excluded from conditional access, and that the credentials are somewhere you could actually reach during an outage.

SharePoint and OneDrive default to permissive sharing because Microsoft’s defaults optimise for collaboration. Over five years that produces thousands of documents accessible to anyone holding a URL, with no expiry.

Nobody chose this. It accumulated. In one healthcare engagement we revoked over 2,100 public links, and the client had no idea any of them existed.

You can audit this yourself from the SharePoint admin centre. Most people find the number uncomfortable.

4. No retention policy, or one nobody understands

Two failure modes, opposite directions. Either nothing is retained and a departed employee’s mailbox is gone before Legal asks for it, or everything is retained forever and you are storing — and therefore liable for — fifteen years of correspondence nobody needs.

Retention should be a deliberate decision tied to your actual obligations. It rarely is.

5. Licences nobody uses

Not a security finding, but it comes up in nearly every audit and it often pays for the engagement.

Accounts for leavers still licensed. Users on E5 who need E3. Duplicate add-ons bought separately that a bundle already includes. The licence report is a five-minute export and the savings are frequently four figures a year.

What an audit produces

A scored review against CIS benchmarks, every finding rated by risk and remediation effort, and a plan you can sequence against budget. The effort rating matters as much as the risk one — a critical finding that takes twenty minutes should be done today, and a moderate one requiring a six-week rollout needs planning.

You keep the report regardless of who does the remediation. If a provider will not give you the findings unless you buy the fix, that tells you something.

If your tenant has never been reviewed against a benchmark, that is worth changing.

Tell us what is breaking.

A short call, an honest read on whether we are the right fit, and a fixed-price proposal after discovery. No obligation and no sales sequence afterwards.

Book a consultation hello@queuebytes.com

Mon–Fri, 09:00–18:00 · Emergency cover 24/7