Microsoft has tightened a lot of the default settings in Microsoft 365 over the past few years. A tenant set up today comes with more protection out of the box than one set up before about 2022. The catch is that older settings don’t update themselves. A default Microsoft changed for new tenants in 2024 doesn’t reach back and change yours, and the user consents, inbox rules, and sharing links granted before the change are all still live.
When we take over a Microsoft 365 tenant we didn’t build, these are the first five settings we check. They’re worth a look in any tenant that’s more than two or three years old, was set up by a previous IT provider, or hasn’t been audited in a while.
A few notes before you start. Some of these require Microsoft 365 Business Premium, E3, or E5 licensing to change, so if a toggle is grayed out, your license tier is usually why. A couple will generate help desk tickets, because they change how something already works. And none of them need to be flipped all at once.
1. The default sharing link in SharePoint and OneDrive
When someone shares a file from SharePoint or OneDrive, the link they generate has a default scope. In tenants set up before Microsoft tightened the defaults, that scope is often “Anyone with the link,” which means anyone who receives the URL can open the file without signing in. No expiration, and no record of who else the link was forwarded to.
Newer Teams-created sites now default to “Only people in your organization.” Older sites, and the tenant-level setting, often still allow Anyone links. The employee who emailed a proposal to their personal account six months ago still has a working link, unless someone revoked it by hand.
You’ll find the default link type in the SharePoint admin center under Policies > Sharing. Switching the tenant default to “Specific people” forces every new link to require a sign-in. You can also set a maximum expiration on any remaining “Anyone” links so they time out on their own.
Rough time: 15 minutes. It doesn’t touch existing links until they’re regenerated.
2. External email forwarding rules
Microsoft now blocks automatic email forwarding to outside addresses at the tenant level by default, through the outbound spam policy. That came in with Microsoft’s secure-by-default push.
Forwarding rules made before that change can still be running, though, and tenants with custom outbound spam policies set up years ago may not match the current default. A user who built a rule a few years back to forward everything to a personal Gmail account may still be quietly exporting your data, depending on how the rule was built and whether it predates the policy.
Check two things. In the Microsoft Defender portal, under Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy, confirm “Automatic forwarding rules” is set to “Off” or “Automatic – System-controlled.” Then audit the inbox rules across your users for any forward-to-external setups. The Microsoft Purview audit log lets you search for inbox-rule creation events.
Rough time: 10 minutes to check the tenant setting, longer to review existing rules across every mailbox.
3. Old third-party app consents
Microsoft now applies a managed user-consent policy by default for new tenants, which stops users from consenting to most third-party apps that ask for access to their mail, files, and calendars. New requests route to an admin for review instead.
That change only applies going forward. Apps that were granted user consent before it took effect still hold whatever permissions they were given, including the ability to read mail, calendars, and files on someone’s behalf. Some are tools an employee installed years ago and no longer uses, or apps approved during a one-off project nobody remembers.
To see what’s already there, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent and look at what currently has access to mail, files, or calendars. Anything you don’t recognize or no longer need can be revoked from the same screen.
Rough time: 30 to 60 minutes, depending on how many old apps are in the list.
4. Audit log retention (and whether it’s even on)
Microsoft changed the default audit log retention in October 2023. Audit (Standard) logs are now kept for 180 days, up from 90. With E5 licensing or the Microsoft Purview Audit (Premium) add-on, you get a year of retention for Exchange, SharePoint, OneDrive, and Entra ID records, with other activity staying at 180 days.
Here’s the part most checklists skip: on the Business plans most small companies run (Business Basic, Standard, and Premium), audit logging isn’t always on by default. Before you count on having any history at all, confirm it’s actually turned on. There’s nothing worse than going to investigate an incident and finding the logs were never being kept.
And if you’re in healthcare, financial services, legal, or another regulated field, 180 days may fall short of what you’re required to keep. HIPAA, the FTC Safeguards Rule, and most state bar rules around client data assume you can produce records on request, and the window there is usually measured in years, not months.
Audit retention policies live in the Microsoft Purview portal under Audit > Audit retention policies. Extending past 180 days needs E5 or the Purview Audit add-on. The setup itself takes about 15 minutes once you’ve confirmed your license covers it.
5. MFA enforcement and Security Defaults
MFA enforcement is the setting most likely to be inconsistent in older tenants. Microsoft introduced Security Defaults in late 2019, and it now turns on MFA automatically for new tenants. Microsoft has also been steadily making MFA mandatory for admin actions in the Microsoft 365 admin center and Azure portal across 2024 and 2025.
Tenants created before Security Defaults rolled out may have no baseline enforcement at all. There’s also a common trap. When an admin turns on a Conditional Access policy (available with Business Premium and up), Microsoft expects you to take over MFA enforcement through that policy and will often switch Security Defaults off. If that handoff was rushed, you can end up with Security Defaults off and a Conditional Access policy that doesn’t cover everyone.
Check three places. In the Entra admin center under Properties > Manage Security Defaults, see whether Security Defaults is on or off. Under Protection > Conditional Access, confirm a policy is actively enforcing MFA for all users, administrators included. Pay special attention to break-glass admin accounts (the emergency-access logins), which are sometimes excluded from Conditional Access for good reason and then left with no MFA as a result.
This is the highest-stakes change on the list and the one most likely to lock people out if it’s done badly, so it’s worth treating as its own project. It’s the kind of review we run as part of a client’s cybersecurity work.
Rough time: about an hour, longer if Conditional Access already has several policies you need to map.
A sensible order to roll the changes
Some of these are invisible to your team. Others change how something they do every day works, so the order matters.
Audit log retention (#4) and the old app-consent review (#3) have no user-facing impact. Start there.
Checking external forwarding (#2) is silent unless someone has a legitimate forwarding rule, which is rare. Do that next.
The sharing default (#1) will eventually prompt questions, especially from anyone used to hitting “share” and pasting the link into an email. Tell people before you flip the tenant setting.
The MFA and Conditional Access review (#5) is the highest-stakes change and the easiest to get wrong. Save it for last and give it the time it needs.
Working through a tenant this way is the kind of thing we handle as part of managed IT, so if it’s more than you want to take on in-house, we can run it with you.
Frequently asked questions
Are my Microsoft 365 settings still a risk if my tenant is new?
New tenants get more protection out of the box than tenants set up a few years ago. Even so, a few settings, including sharing scope, app consents granted by users, and historical inbox rules, are worth reviewing in any tenant regardless of age.
What’s the current Microsoft 365 default for “Anyone with the link” sharing?
At the tenant level, many existing tenants still permit “Anyone with the link” sharing. Newer Teams-created SharePoint sites default to “Only people in your organization.” Check both the tenant-level setting and the site-level setting to know what your users actually see.
Did Microsoft turn off external email forwarding by default?
Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. Inbox rules created before that change may still be active and are worth auditing.
How long are Microsoft 365 audit logs kept by default?
180 days for Audit (Standard), as of October 2023. One year for the key workloads (Exchange, SharePoint, OneDrive, Entra ID) if you have E5 or the Microsoft Purview Audit (Premium) add-on. On Business-tier plans, also confirm auditing is switched on in the first place.
Does Security Defaults cover all my users?
On a new tenant, yes, including MFA enforcement. On an older tenant that has had Conditional Access policies turned on, Security Defaults may have been switched off, and MFA coverage then depends on how Conditional Access is configured.
Sources and further reading
- Microsoft Learn: Manage sharing settings for SharePoint and OneDrive
- Microsoft Learn: External email forwarding in Microsoft 365
- Microsoft Learn: Configure how users consent to applications
- Microsoft Learn: Manage audit log retention policies
- Microsoft Learn: Configure Security Defaults for Microsoft Entra ID
- CISA: Microsoft 365 Secure Configuration Baselines (SCuBA)
If you’re not sure when your tenant was last reviewed, or whether any of these settings need attention, your IT provider should be able to walk through them with you. If you don’t have one, reach out to us and we’ll help you sort it out.
—
Want a straight read on your IT?
Book a 15-minute call and we'll give you an honest take on where you stand — no pressure, no scare tactics. If staying put is the right move for now, we'll tell you that too.