<img alt="" src="https://www.instinct365intelligent.com/810470.png" style="display:none;">
  • IBM Select Partner 2025
  • ISO9001, 14001, 27001
  • Service Delivery Champion 2025
Crown Commercial Service Supplier IBM Platinum Partner
Celerity Logo
Solutions & Services
  • Data Resilience
    Data Resilience

    Secure data optimisation & proactive backup

  • Software
    Software

    Proactive Licensing, Compliance & Asset Management

  • Cyber Security
    Cyber Security

    Agile, Modular, & Secure Cyber Security & Managed Siem

  • Infrastructure
    Infrastructure

    Manage & Transform Multi-Cloud, Hybrid & On-Premise

Managed Backup Disaster and Cyber Recovery CopyAssure®
Software Licensing Management Managed Licence Compliance Software Asset Management Managed AI
Managed Siem MDR & MXDR Exposure Management Incident Response & Consultancy Secrets & Service Management
Infrastructure Advisory Infrastructure Transformation Managed Services FinOps as a Service Software Resell Hardware Resell
Client Outcomes Partners
Industries
Healthcare
Local Government
Financial Services
Retail
Manufacturing
Insights
All Resources
Technology Topics & Trends
About
Our Story
Our People
Accreditations
Corporate Social Responsibility
Careers
Contact
  • Contact
  • Sign In
×
  • Solutions & Services
  • Client Outcomes
  • Partners
  • Industries
  • Insights
  • About
Solutions & Services
  • Data Resilience

    • Managed Backup
    • Disaster and Cyber Recovery
    • CopyAssure®
  • Software

    • Software Licensing Management
    • Managed Licence Compliance
    • Software Asset Management
    • Managed AI
  • Cyber Security

    • Managed Siem
    • MDR & MXDR
    • Exposure Management
    • Incident Response & Consultancy
    • Secrets & Service Management
  • Infrastructure

    • Infrastructure Advisory
    • Infrastructure Transformation
    • Managed Services
    • FinOps as a Service
    • Software Resell
    • Hardware Resell
Industries
  • Healthcare
  • Local Government
  • Financial Services
  • Retail
  • Manufacturing
Insights
  • All Resources
  • Technology Topics & Trends
About
  • Our Story
  • Our People
  • Accreditations
  • Corporate Social Responsibility
  • Careers
  • Contact
Cyber Security

Microsoft 365 is secure. But is your tenant configured securely?

Hannah Boswell
Hannah Boswell

21 July 2026

Time to read

Loading read time...

Share this post

Table of contents

  • A realistic attack path
  • Configuration weaknesses that matter
  • Questions every organisation using Microsoft 365 should be able to answer
  • Find out where your tenant stands
Find out more

 

Blog header (5)

A common misunderstanding about Microsoft 365 security is that using the platform automatically means the environment is secure. That is not how attackers see it.

Most Microsoft 365 incidents do not start with someone hacking Microsoft. They start with someone signing in as a real user, abusing an existing configuration, or using permissions that were never meant to be so broad. That makes identity one of the most important security layers in Microsoft 365, and one of the easiest to get wrong.

 

A realistic attack path

An attacker performs password spraying against Microsoft 365 accounts. Rather than trying thousands of passwords on one account, they try a small number of common passwords across many users, avoiding the lockouts that would otherwise give them away.

If one password works, the obvious question is whether MFA is enabled. The better question is whether every authentication path is protected by MFA.

This is where legacy authentication becomes dangerous. Legacy protocols do not support modern MFA controls, so even when an organisation believes MFA is enabled, an attacker with a valid username and password may still be able to authenticate through an older protocol if it remains allowed. This is not a Microsoft 365 platform problem. It is a tenant configuration problem.

Threat actors such as APT28 (Fancy Bear) have used credential-based attacks and valid accounts as part of their operations. In a Microsoft 365 environment, that becomes especially relevant when older authentication methods, weak Conditional Access policies, or poorly monitored accounts are still in place.

 

Configuration weaknesses that matter

Individually, these can look like small issues. Together, they can create a path from one compromised password to mailbox access, data exposure, business email compromise, or privilege escalation:

  • Legacy authentication still allowed
  • MFA not enforced for all users and administrators
  • Conditional Access policies with too many exclusions
  • Service accounts without proper controls
  • Too many Global Administrators
  • Guest accounts with long-term access
  • OAuth applications with excessive permissions
  • Mailbox forwarding rules that are not monitored
  • Inactive accounts that still have access

 

Questions every organisation using Microsoft 365 should be able to answer

  • Do we know whether legacy authentication is fully blocked?
  • Are all privileged accounts protected with strong MFA?
  • Can risky sign-ins be blocked automatically?
  • Do we review OAuth application permissions?
  • Are external users and guest accounts still required?
  • Do we monitor mailbox rules and forwarding?
  • Do we know how many users have administrative privileges?

If any of these are hard to answer with confidence, that is a sign the tenant configuration hasn't kept pace with how the environment has grown and changed.

Microsoft 365 provides strong security capabilities, but those capabilities only reduce risk when they are correctly configured, actively maintained, and regularly reviewed. Security in Microsoft 365 is not a one-time setting. It is ongoing identity governance, configuration management, monitoring, and verification.

The real question is not whether Microsoft 365 can be secure. It is whether your Microsoft 365 tenant is configured in a way that matches the threats attackers actually use, and this is exactly what Celerity's Managed SIEM and MDR services are designed to monitor and enforce, day to day.

 

Find out where your tenant stands

The only way to answer these questions with certainty is to assess your tenant against a recognised security standard, not assumptions.

Celerity's independent CIS Benchmark assessment reviews your Microsoft 365 configuration against the industry's leading hardening framework, covering identity, authentication, mailbox controls, and administrative access, and shows you exactly where the gaps are.

 

Get your independent CIS benchmark assessment

Latest News

All Resources
Why Effective IT-OT Monitoring Requires Visibility Across the Entire Attack Chain
Why Effective IT-OT Monitoring Requires Visibility Across the Entire Attack Chain

Blog

Why Effective IT-OT Monitoring Requires Visibility Across the Entire Attack Chain

Cyber Security
Holly Ellwood
Holly Ellwood

24 August 2026

Read blog article
One Year on from the JLR Cyber Attack: what could have changed the outcome?
One Year on from the JLR Cyber Attack: what could have changed the outcome?

Blog

One Year on from the JLR Cyber Attack: what could have changed the outcome?

Cyber Security
Holly Ellwood
Holly Ellwood

18 August 2026

Read blog article
Celerity Announced as Sponsor of the 2026 Oxygen Awards
Celerity Announced as Sponsor of the 2026 Oxygen Awards

News

Celerity Announced as Sponsor of the 2026 Oxygen Awards

Hannah Boswell
Hannah Boswell

14 August 2026

Read News
Logo WHITE-cropped
phone 0845 565 2097
email info@celerity-uk.com
Vector
9001_Certification Badges_RGB_(0421)_4 14001 Certification Badges_RGB_(0421)_4 27001 Certification Badges_RGB_(0421)_4 cyberessentials_certification mark plus_colour

Transforming Technology. Empowering People.

QUICK LINKS
  • Technology Topics & Trends
  • Clients
  • Partners
  • Policies
  • Cyber Security Managed Services
  • Managed Cyber Security
  • Cyber Security Managed Service Provider
  • Managed Cyber Security Services
  • Cyber Security Risk Management
LATEST BLOGS
  • Why Effective IT-OT Monitoring Requires Visibility Across the Entire Attack Chain
  • One Year on from the JLR Cyber Attack: what could have changed the outcome?
  • Celerity Announced as Sponsor of the 2026 Oxygen Awards

Ⓒ Celerity 2026 All Rights Reserved

Privacy

Terms

 

  • There are no suggestions because the search field is empty.