If your Microsoft 365 tenant was set up more than two or three years ago — or inherited from a previous IT provider and left alone since — there’s a good chance several important settings haven’t been touched since the day someone first clicked through the setup wizard.
That’s not a knock on you or your previous provider. Microsoft genuinely has tightened its defaults over the past few years, and new tenants get meaningfully better protection out of the box than they used to. The catch, and it’s a big one, is that those improvements don’t apply retroactively. A setting Microsoft changed for brand-new tenants in 2024 doesn’t quietly update itself in yours. Your historical sharing links, inbox rules, and app consents stay exactly as they were the day they were created.
We run into this constantly with small businesses across South Bend, Goshen, Elkhart, and Mishawaka — tenants that were set up correctly for the standards of 2019 or 2021, and simply never revisited as Microsoft’s baseline moved forward. Nobody did anything wrong. The world around the configuration just changed underneath it.
Here are five settings worth checking in your own tenant, especially if it’s more than two or three years old, was set up by a previous provider, or hasn’t been audited in a while. A quick note before we start: some of these require Microsoft 365 Business Premium, E3, or E5 licensing to change, so if a toggle is grayed out for you, your license tier is most likely the reason. A couple of these changes will also generate support questions from your own team, because they change how something already works day-to-day. None of them need to happen all at once.
1. The default sharing link in SharePoint and OneDrive
When someone in your organization shares a file from SharePoint or OneDrive, the link they generate has a default scope. In tenants set up before Microsoft tightened the new-site defaults, that scope is often “Anyone with the link,” which means anyone who receives the URL can open the file without ever signing in. No expiration. No record of who else the link got forwarded to along the way.
Newer Teams-created sites now default to “Only people in your organization.” Older sites and the tenant-level setting often still allow Anyone links. A departing employee who emailed a proposal to their personal account six months ago still has a working link today, unless someone manually revoked it in the meantime.
The default sharing link type sits in the SharePoint admin center under Policies > Sharing. Switching the tenant default to “Specific people” forces every new link to require authentication. You can also set a maximum expiration for any remaining “Anyone” links so they time out automatically instead of living forever.
Rough time to change: 15 minutes. This has no impact on existing links until they’re regenerated, which makes it one of the lower-risk changes on this list.
2. External email forwarding rules
Microsoft now blocks automatic email forwarding to external addresses at the tenant level by default, through the outbound spam policy. This rolled out as part of Microsoft’s broader secure-by-default push.
Forwarding rules created before that change can still be active, though, and tenants with custom outbound spam policies configured years ago may not reflect the current default at all. A user who set up a rule a few years ago to forward every email to a personal Gmail address may still be quietly exporting your data, depending on how their rule was constructed and whether it predates the policy change.
Verify two things. In the Microsoft Defender portal, under Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy, confirm the “Automatic forwarding rules” setting is set to “Off” or “Automatic – System-controlled.” Then audit existing inbox rules across your users for any forward-to-external configurations. The Microsoft Purview audit log lets you search specifically for inbox rule creation events, which is the fastest way to find anything historical.
Rough time: 10 minutes to verify the tenant setting, longer to review existing rules across all mailboxes depending on team size.
3. Historical third-party app consents
A Microsoft-managed user consent policy was enabled by default in July 2025, preventing users from consenting to most third-party applications that request access to their files and sites. New consent requests now route to an admin for review instead of being approved by whoever clicked “allow” first.
The change only applies going forward. Apps that were granted user consent before the policy took effect still have whatever permissions they were originally given, including the ability to read mail, calendars, and files on behalf of the user. Some of those apps may be tools an employee installed years ago and no longer uses, or apps installed during a one-off project that nobody remembers approving in the first place.
To review what’s already there, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent and look at what currently has access to mail, files, or calendars. Anything you don’t recognize, or no longer need, can be revoked from the same screen in a couple of clicks.
Rough time: 30 to 60 minutes for the review, depending on how many historical apps have accumulated in the list.
4. Mailbox and tenant audit log retention
The default audit log retention period in Microsoft 365 changed in October 2023. Audit (Standard) logs are now retained for 180 days, up from the previous 90 days. Customers with E5 licensing or the Microsoft Purview Audit (Premium) add-on get a full year of retention for Exchange, SharePoint, OneDrive, and Entra ID audit records, with other activity types staying at 180 days.
If you’re in healthcare, financial services, legal, or any other regulated industry, 180 days may not match your actual retention obligations. HIPAA, the FTC Safeguards Rule, and most state bar rules around client data assume you can produce records on request, and the relevant period is often measured in years, not months.
Audit retention policies live in the Microsoft Purview compliance portal under Audit > Audit retention policies. Extending retention beyond 180 days requires E5 or the Purview Audit add-on. The configuration itself takes about 15 minutes once you’ve confirmed your license supports it.
Rough time: 15 minutes to configure, once licensing is confirmed.
5. MFA enforcement and Security Defaults
MFA enforcement is the area most likely to be inconsistent in older tenants, and it’s also the highest-stakes item on this list. Microsoft introduced Security Defaults in late 2019, and the feature now enforces MFA automatically on new tenants from day one. Microsoft has also been progressively making MFA mandatory for admin actions in the Microsoft 365 admin center and Azure portal through 2024 and 2025.
Tenants created before Security Defaults rolled out may have no baseline enforcement at all. There’s also a common configuration trap worth knowing about. When an admin enables a Conditional Access policy — available with Business Premium and above — Microsoft expects you to take over MFA enforcement through that policy, and may turn Security Defaults off as part of the transition. If that transition was done quickly, you can end up with Security Defaults off and a Conditional Access policy that doesn’t actually cover every user, leaving gaps nobody notices until it’s too late.
Check three places. In the Entra ID admin center under Properties > Manage Security Defaults, confirm whether Security Defaults is on or off. Under Protection > Conditional Access, confirm a policy is actively enforcing MFA for all users, including administrators. Pay particular attention to break-glass admin accounts, which are sometimes excluded from Conditional Access for emergency access reasons and left with no MFA as a result — a reasonable idea in principle that quietly becomes a serious gap if it’s forgotten.
Rough time: about an hour, longer if Conditional Access has been configured with several existing policies you need to map out first.
A sensible order to roll the changes out
Some of these changes are completely silent to your users. Others change how something they do every day works, so the order you tackle them in matters more than you might expect.
Audit log retention (#4) and the historical app consent review (#3) carry no user-facing impact at all. Start there — they’re pure upside with zero disruption.
Verifying external forwarding (#2) is silent unless someone happens to have a legitimate forwarding rule, which is rare in most small businesses. Do this next.
The sharing default (#1) will eventually generate a few user questions, particularly from anyone used to clicking “share” and pasting the link straight into an email without a second thought. Communicate the change before you flip the tenant setting, and the questions mostly answer themselves.
The MFA and Conditional Access review (#5) is the highest-stakes change on this list and the one most likely to lock people out if it’s done badly. Save it for last, and budget the time to do it properly rather than rushing it in between other tasks.
What it actually costs to leave these alone
None of these five settings feel urgent on their own, which is exactly why they tend to sit unaddressed for years. Nobody wakes up worried about SharePoint sharing defaults. The cost shows up later, and usually all at once, in a way that’s much harder to unwind than the original fix would have been.
We’ve seen a version of this play out more than once with businesses in the South Bend and Elkhart area: a departing employee’s “Anyone with the link” share from two years earlier gets forwarded one more time, lands somewhere it shouldn’t, and now there’s a client asking uncomfortable questions about who’s seen their contract terms. None of that required a hacker. It just required a default nobody ever revisited, sitting quietly until circumstances lined up.
The same logic applies to cyber insurance. If your renewal application asks whether MFA is enforced tenant-wide and Security Defaults quietly got switched off eighteen months ago during a Conditional Access rollout, that’s not a hypothetical gap — it’s the exact kind of answer that gets scrutinized after a claim. Treating these five settings as a once-a-year checklist, rather than a “set it and forget it” configuration from day one, is the difference between catching the drift early and discovering it during an incident.
Frequently Asked Questions
Are my Microsoft 365 settings still vulnerable if my tenant was set up recently?
New tenants get more protection out of the box than tenants set up a few years ago. Even so, certain settings, including sharing scope, app consents granted by users, and historical inbox rules, need to be reviewed in any tenant regardless of age.
What is the current Microsoft 365 default for “Anyone with the link” sharing?
At the tenant level, many existing tenants still permit “Anyone with the link” sharing. Newer Teams-created SharePoint sites default to “Only people in your organization.” Verify both the tenant-level setting and the site-level setting if you want to know what your users actually see in practice.
Did Microsoft turn off external email forwarding by default?
Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. Existing inbox rules created before that change may still be active and worth auditing individually.
How long are Microsoft 365 audit logs kept by default?
180 days for Audit (Standard), as of October 2023. One year for key workloads (Exchange, SharePoint, OneDrive, Entra ID) if you have E5 or the Microsoft Purview Audit (Premium) add-on.
Does Security Defaults cover all my users?
On a new tenant, yes, including MFA enforcement. On an older tenant that has had Conditional Access policies enabled, Security Defaults may have been turned off, and MFA coverage now depends entirely on how Conditional Access has been configured.
Graham’s Take
Almost every tenant we audit for a new client across Michiana has at least two or three of these five settings sitting in their old, less-protected state. It’s rarely anyone’s fault — Microsoft moved the target and nobody sent out a memo. If it’s been a while since anyone looked under the hood of your tenant, this is exactly the kind of thing we check during a free checkup, and we’ll tell you plainly what we find, whether or not you decide to work with us.
