<img alt="" src="https://www.instinct365intelligent.com/810470.png" style="display:none;">
Celerity Logo
Solutions & Services
  • Data Resilience
    Data Resilience

    Secure data optimisation & proactive backup

  • Software
    Software

    Proactive Licensing, Compliance & Asset Management

  • Cyber Security
    Cyber Security

    Agile, Modular, & Secure Cyber Security & Managed Siem

  • Infrastructure
    Infrastructure

    Manage & Transform Multi-Cloud, Hybrid & On-Premise

Managed Backup Disaster and Cyber Recovery CopyAssure®
Software Licensing Management Managed Licence Compliance Software Asset Management Managed AI
Managed Siem MDR & MXDR Exposure Management Incident Response & Consultancy Secrets & Service Management
Infrastructure Advisory Infrastructure Transformation Managed Services FinOps as a Service Software Resell Hardware Resell
Client Outcomes Partners
Industries
Healthcare
Local Government
Financial Services
Retail
Manufacturing
Insights
All Resources
Technology Topics & Trends
About
Our Story
Our People
Accreditations
Corporate Social Responsibility
Careers
Contact
  • Contact
  • Sign In
×
  • Solutions & Services
  • Client Outcomes
  • Partners
  • Industries
  • Insights
  • About
Solutions & Services
  • Data Resilience

    • Managed Backup
    • Disaster and Cyber Recovery
    • CopyAssure®
  • Software

    • Software Licensing Management
    • Managed Licence Compliance
    • Software Asset Management
    • Managed AI
  • Cyber Security

    • Managed Siem
    • MDR & MXDR
    • Exposure Management
    • Incident Response & Consultancy
    • Secrets & Service Management
  • Infrastructure

    • Infrastructure Advisory
    • Infrastructure Transformation
    • Managed Services
    • FinOps as a Service
    • Software Resell
    • Hardware Resell
Industries
  • Healthcare
  • Local Government
  • Financial Services
  • Retail
  • Manufacturing
Insights
  • All Resources
  • Technology Topics & Trends
About
  • Our Story
  • Our People
  • Accreditations
  • Corporate Social Responsibility
  • Careers
  • Contact
Cyber Security

Microsoft 365 is secure. But is your tenant configured securely?

Hannah Boswell
Hannah Boswell

21 July 2026

Time to read

Loading read time...

Share this post

Table of contents

  • A realistic attack path
  • Configuration weaknesses that matter
  • Questions every organisation using Microsoft 365 should be able to answer
  • Find out where your tenant stands
Find out more

 

Blog header (5)

A common misunderstanding about Microsoft 365 security is that using the platform automatically means the environment is secure. That is not how attackers see it.

Most Microsoft 365 incidents do not start with someone hacking Microsoft. They start with someone signing in as a real user, abusing an existing configuration, or using permissions that were never meant to be so broad. That makes identity one of the most important security layers in Microsoft 365, and one of the easiest to get wrong.

 

A realistic attack path

An attacker performs password spraying against Microsoft 365 accounts. Rather than trying thousands of passwords on one account, they try a small number of common passwords across many users, avoiding the lockouts that would otherwise give them away.

If one password works, the obvious question is whether MFA is enabled. The better question is whether every authentication path is protected by MFA.

This is where legacy authentication becomes dangerous. Legacy protocols do not support modern MFA controls, so even when an organisation believes MFA is enabled, an attacker with a valid username and password may still be able to authenticate through an older protocol if it remains allowed. This is not a Microsoft 365 platform problem. It is a tenant configuration problem.

Threat actors such as APT28 (Fancy Bear) have used credential-based attacks and valid accounts as part of their operations. In a Microsoft 365 environment, that becomes especially relevant when older authentication methods, weak Conditional Access policies, or poorly monitored accounts are still in place.

 

Configuration weaknesses that matter

Individually, these can look like small issues. Together, they can create a path from one compromised password to mailbox access, data exposure, business email compromise, or privilege escalation:

  • Legacy authentication still allowed
  • MFA not enforced for all users and administrators
  • Conditional Access policies with too many exclusions
  • Service accounts without proper controls
  • Too many Global Administrators
  • Guest accounts with long-term access
  • OAuth applications with excessive permissions
  • Mailbox forwarding rules that are not monitored
  • Inactive accounts that still have access

 

Questions every organisation using Microsoft 365 should be able to answer

  • Do we know whether legacy authentication is fully blocked?
  • Are all privileged accounts protected with strong MFA?
  • Can risky sign-ins be blocked automatically?
  • Do we review OAuth application permissions?
  • Are external users and guest accounts still required?
  • Do we monitor mailbox rules and forwarding?
  • Do we know how many users have administrative privileges?

If any of these are hard to answer with confidence, that is a sign the tenant configuration hasn't kept pace with how the environment has grown and changed.

Microsoft 365 provides strong security capabilities, but those capabilities only reduce risk when they are correctly configured, actively maintained, and regularly reviewed. Security in Microsoft 365 is not a one-time setting. It is ongoing identity governance, configuration management, monitoring, and verification.

The real question is not whether Microsoft 365 can be secure. It is whether your Microsoft 365 tenant is configured in a way that matches the threats attackers actually use, and this is exactly what Celerity's Managed SIEM and MDR services are designed to monitor and enforce, day to day.

 

Find out where your tenant stands

The only way to answer these questions with certainty is to assess your tenant against a recognised security standard, not assumptions.

Celerity's independent CIS Benchmark assessment reviews your Microsoft 365 configuration against the industry's leading hardening framework, covering identity, authentication, mailbox controls, and administrative access, and shows you exactly where the gaps are.

 

Get your independent CIS benchmark assessment

Latest News

All Resources
We Put AI in the Hands of Public Sector Leaders
We Put AI in the Hands of Public Sector Leaders

Blog

We Put AI in the Hands of Public Sector Leaders

Software
Hannah Boswell
Hannah Boswell

29 June 2026

Read blog article
Five Questions Your Board Will Ask About Cloud Spend
Five Questions Your Board Will Ask About Cloud Spend

Blog

Five Questions Your Board Will Ask About Cloud Spend

Infrastructure
Hannah Boswell
Hannah Boswell

17 June 2026

Read blog article
You Can’t Secure What You Don’t Understand
You Can’t Secure What You Don’t Understand

Blog

You Can’t Secure What You Don’t Understand

Cyber Security
Holly Ellwood
Holly Ellwood

08 June 2026

Read blog article
Logo WHITE-cropped
phone 0845 565 2097
email info@celerity-uk.com
Vector
9001_Certification Badges_RGB_(0421)_4 14001 Certification Badges_RGB_(0421)_4 27001 Certification Badges_RGB_(0421)_4 cyberessentials_certification mark plus_colour

Transforming Technology. Empowering People.

QUICK LINKS
  • Technology Topics & Trends
  • Clients
  • Partners
  • Policies
  • Cyber Security Managed Services
  • Managed Cyber Security
  • Cyber Security Managed Service Provider
  • Managed Cyber Security Services
  • Cyber Security Risk Management
LATEST BLOGS
  • Microsoft 365 is secure. But is your tenant configured securely?
  • We Put AI in the Hands of Public Sector Leaders
  • Five Questions Your Board Will Ask About Cloud Spend

Ⓒ Celerity 2026 All Rights Reserved

Privacy

Terms

 

  • There are no suggestions because the search field is empty.