Tutorial

Microsoft 365 Hardening: 12 Settings Most UAE Tenants Have Wrong

We audit Microsoft 365 tenants every week. The same dozen misconfigurations appear in almost all of them. Here they are, with the fix for each.

5 September 2026 · Microsoft 365, Hardening, Security, Tutorial

Most Microsoft 365 tenants in the UAE were set up quickly, by someone who had licences to activate and users to migrate. Security came later, if at all. When we audit a tenant, these are the twelve findings that appear most often. Each takes minutes to hours to fix and closes a real attack path.

1. Legacy authentication is still allowed

IMAP, POP and SMTP basic authentication bypass MFA entirely. Block them with a conditional access policy. Check sign-in logs first for any old scanner or application still using them.

2. MFA depends on users enabling it

Security Defaults or per-user MFA leaves gaps. Use conditional access to require MFA for all users, all apps, with a stronger requirement for admins.

3. Global Administrators read email

Every admin should have a separate, MFA-protected admin account used only for administration. Aim for two to four Global Admins, not twelve.

4. No break-glass account

Create two emergency accounts excluded from conditional access, with long random passwords stored offline, and alert on any sign-in.

5. External sharing is wide open

SharePoint and OneDrive default to allowing anonymous links. Set the tenant to "Existing guests" or "New and existing guests", set links to expire, and review sites shared externally.

6. Auto-forwarding to external addresses is allowed

A compromised mailbox with a hidden forwarding rule to a Gmail address is how invoice fraud starts. Block external auto-forwarding in the outbound spam policy and alert on new inbox rules.

7. DMARC is not enforced

SPF and DKIM are often set; DMARC is usually missing or on p=none. Move to quarantine, then reject, so your domain cannot be spoofed against your own customers.

8. Safe Links and Safe Attachments are off

If you have Business Premium or E5, Defender for Office 365 is included and often unconfigured. Turn on Safe Links, Safe Attachments and anti-phishing impersonation protection for your executives.

9. Users can consent to any app

OAuth consent phishing tricks users into granting a malicious app access to their mailbox. Restrict user consent to verified publishers and low-risk permissions; route the rest to admin approval.

10. Audit logging is not retained

Unified audit logging should be on and, for regulated firms, retained beyond the default. When an incident happens, the log is the difference between knowing what was taken and guessing.

11. Guest accounts never expire

Run an access review. Most tenants have dozens of guests from former projects, suppliers and ex-employees' personal accounts, all still able to sign in.

12. Nobody owns Secure Score

Microsoft Secure Score lists your gaps in priority order. Assign an owner, review it monthly, and treat anything under 60 percent as a project.

Doing it properly

All twelve can be fixed in a day of careful work, tested in report-only mode first so nothing breaks for users. Binary Minds offers a fixed-price Microsoft 365 tenant hardening service that covers these and about forty further checks, with a before-and-after Secure Score report you can give to auditors or insurers.

If you want a quick self-check, open the Microsoft 365 admin centre, go to Secure Score, and look at your top five recommended actions. They will almost certainly be on this list.

Back to the blog · Request a free IT quote