Microsoft has tightened several default settings in Microsoft 365 over the past few years. Newer tenants get more protection out of the box than tenants set up before 2022 or so. The catch is that legacy configurations stay in place. A setting changed for new tenants in 2024 does not retroactively change in yours, and historical user consents, inbox rules or sharing links granted before the change are still active.

Here are five settings worth checking in your tenant, especially if it is more than two or three years old, was set up by a previous IT provider, or has not been audited in a while.

A couple of caveats before we start. Some of these settings require Microsoft 365 Business Premium, E3 or E5 licensing to change, so if a toggle is greyed out, your licence tier is most likely the reason. A few of these changes will generate support tickets from your team, because they change how something already works. None of them need to be flipped all at once.

1. The default sharing link in SharePoint and OneDrive

When someone in your organisation shares a file from SharePoint or OneDrive, the link they generate has a default scope. In tenants set up before Microsoft tightened the new-site defaults, that scope is often "Anyone with the link," which means anyone who receives the URL can open the file without signing in. No expiry. No record of who else the link was forwarded to.

Newer Teams-created sites now default to "Only people in your organisation." Older sites and the tenant-level setting often still allow Anyone links. A departing employee who emailed a proposal to their personal account six months ago still has a working link, unless someone manually revoked it.

The default sharing link type sits in the SharePoint admin center under Policies > Sharing. Switching the tenant default to "Specific people" forces every new link to require authentication. You can also set a maximum expiry for any remaining "Anyone" links so they time out automatically.

Rough time to change: 15 minutes. This has no impact on existing links until they are regenerated.

2. External email forwarding rules

Microsoft now blocks automatic email forwarding to external addresses at the tenant level by default, through the outbound spam policy. This rolled out as part of Microsoft's secure-by-default effort.

Forwarding rules created before that change can still be active, though, and tenants with custom outbound spam policies configured years ago may not reflect the current default. A user who set up a rule a few years ago to forward every email to a personal account may still be exporting your data, depending on how their rule was built and whether it predates the policy.

Verify two things. In the Microsoft Defender portal, under Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy, confirm the "Automatic forwarding rules" setting is set to "Off" or "Automatic - System-controlled." Then audit existing inbox rules across your users for any forward-to-external configurations. The Microsoft Purview audit log lets you search for inbox rule creation events.

Rough time: 10 minutes to verify the tenant setting, longer to review existing rules across all mailboxes.

3. Historical third-party app consents

A Microsoft-managed user consent policy was enabled by default in July 2025, preventing users from consenting to most third-party applications that request access to their files and sites. New consent requests now route to an admin for review.

The change applies going forward. Apps that were granted user consent before the policy took effect still have whatever permissions they were given, including the ability to read mail, calendars and files on behalf of the user. Some of those apps may be tools an employee installed years ago and no longer uses, or apps installed during a one-off project that nobody remembers approving.

To review what is already there, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent and look at what currently has access to mail, files or calendars. Anything you do not recognise or no longer need can be revoked from the same screen.

Rough time: 30 to 60 minutes for the review, depending on how many historical apps are in the list.

4. Mailbox and tenant audit log retention

The default audit log retention period in Microsoft 365 changed in October 2023. Audit (Standard) logs are now retained for 180 days, up from the previous 90. Customers with E5 licensing or the Microsoft Purview Audit (Premium) add-on get one year of retention for Exchange, SharePoint, OneDrive and Entra ID audit records, with other activity types staying at 180 days.

If you are in healthcare, financial services, legal or another regulated industry, 180 days may not match your retention obligations. The Privacy Act, APRA's standards for financial services, and the record-keeping rules that apply to law and accounting practices generally assume you can produce records on request, and the relevant period is often measured in years, not months.

Audit retention policies live in the Microsoft Purview compliance portal under Audit > Audit retention policies. Extending retention beyond 180 days requires E5 or the Purview Audit add-on. The configuration itself takes about 15 minutes once you have confirmed your licence supports it.

5. MFA enforcement and Security Defaults

MFA enforcement is the area most likely to be inconsistent in older tenants. Microsoft introduced Security Defaults in late 2019, and the feature now enforces MFA automatically on new tenants. Microsoft has also been progressively making MFA mandatory for admin actions in the Microsoft 365 admin center and Azure portal through 2024 and 2025.

Tenants created before Security Defaults rolled out may have no baseline enforcement. There is also a common configuration trap. When an admin enables a Conditional Access policy, which is available with Business Premium and above, Microsoft expects you to take over MFA enforcement through that policy and may turn Security Defaults off. If the transition was done quickly, you can end up with Security Defaults off and a Conditional Access policy that does not cover every user.

Check three places. In the Entra ID admin center under Properties > Manage Security Defaults, confirm whether Security Defaults is on or off. Under Protection > Conditional Access, confirm a policy is actively enforcing MFA for all users, including administrators. Pay particular attention to break-glass admin accounts, which are sometimes excluded from Conditional Access for emergency access reasons and left with no MFA as a result. It is worth remembering that MFA on its own is not the finish line, but inconsistent enforcement is still the first gap an attacker looks for.

A sensible order to roll out the changes

Some of these changes are silent to your users. Others change how something they do every day works, so the order matters.

  • Audit log retention (#4) and the historical app consent review (#3) carry no user-facing impact. Start there.
  • Verifying external forwarding (#2) is silent unless someone has a legitimate forwarding rule, which is rare. Do this next.
  • The sharing default (#1) will eventually generate user questions, particularly from anyone used to clicking "share" and pasting the link into an email. Communicate the change before you flip the tenant setting.
  • The MFA and Conditional Access review (#5) is the highest-stakes change and the one most likely to lock people out if it is done badly. Save it for last and budget the time to do it properly.

None of this is exotic work, but it does reward a careful hand. If your tenant has not been reviewed in a while, this is exactly the kind of thing a Cyber Health Check surfaces before it becomes a problem.

Frequently asked questions

Are my Microsoft 365 settings still vulnerable if my tenant was set up recently?

New tenants get more protection out of the box than tenants set up a few years ago. Even so, certain settings, including sharing scope, app consents granted by users, and historical inbox rules, need to be reviewed in any tenant regardless of age.

What is the current Microsoft 365 default for "Anyone with the link" sharing?

At the tenant level, many existing tenants still permit "Anyone with the link" sharing. Newer Teams-created SharePoint sites default to "Only people in your organisation." Verify both the tenant-level and site-level settings if you want to know what your users see in practice.

Did Microsoft turn off external email forwarding by default?

Yes. Microsoft's outbound spam policy now blocks automatic external forwarding by default at the tenant level. Existing inbox rules created before that change may still be active and worth auditing.

How long are Microsoft 365 audit logs kept by default?

180 days for Audit (Standard), as of October 2023. One year for key workloads such as Exchange, SharePoint, OneDrive and Entra ID if you have E5 or the Microsoft Purview Audit (Premium) add-on.

Does Security Defaults cover all my users?

On a new tenant, yes, including MFA enforcement. On an older tenant that has had Conditional Access policies enabled, Security Defaults may have been turned off, and MFA coverage now depends on how Conditional Access has been configured.