The 5 security gaps we find in almost every Microsoft 365 tenant

Zybim guides · from real assessment data

Run enough assessments and the same gaps appear so reliably you could bet on them. Here are the five, in the order we usually find them — and roughly how long each takes to fix.

1. MFA enabled, not enforced

The most dangerous gap because it feels solved. MFA is "on" — available, registered by some users — but no conditional access policy actually requires it on every sign-in. Attackers only need the accounts where it's optional. Fix: one conditional access policy; an afternoon including comms.

2. Legacy authentication still open

IMAP, POP, SMTP AUTH and older clients authenticate without MFA support — a bypass lane around everything above. Password-spray attacks target these endpoints specifically. Fix: block via conditional access after checking what still uses it; a day with monitoring.

3. Over-privileged and dormant admin accounts

Ex-employees with lingering Global Admin, service accounts with owner rights, five people holding a role one person needs. Every extra admin is an extra jackpot. Fix: role review plus privileged identity management; a half-day review, ongoing discipline.

4. No device compliance requirements

Corporate data opens on any device — personal laptops with no disk encryption, phones without PINs. One lost device becomes a breach. Fix: Intune compliance policies tied to conditional access; a sprint, rolled out in rings.

5. Auditing off or unread

When an incident happens, the first question is "what did they touch?" — unanswerable without the unified audit log, and undetectable without anyone watching sign-in anomalies. Fix: enabling audit is minutes; the watching part is what monitoring retainers are for.

The common thread

None of these require new spend — they're configuration of licenses you already own. What they require is someone looking, ranking, and executing. That's precisely what an assessment produces.

How exposed is your tenant? Find out in two minutes with the free, read-only Microsoft 365 security assessment.

Run the free assessment