Blog
We Put AI in the Hands of Public Sector Leaders
Software
Hannah Boswell
29 June 2026
Secure data optimisation & proactive backup
Proactive Licensing, Compliance & Asset Management
Agile, Modular, & Secure Cyber Security & Managed Siem
Manage & Transform Multi-Cloud, Hybrid & On-Premise
A common misunderstanding about Microsoft 365 security is that using the platform automatically means the environment is secure. That is not how attackers see it.
Most Microsoft 365 incidents do not start with someone hacking Microsoft. They start with someone signing in as a real user, abusing an existing configuration, or using permissions that were never meant to be so broad. That makes identity one of the most important security layers in Microsoft 365, and one of the easiest to get wrong.
An attacker performs password spraying against Microsoft 365 accounts. Rather than trying thousands of passwords on one account, they try a small number of common passwords across many users, avoiding the lockouts that would otherwise give them away.
If one password works, the obvious question is whether MFA is enabled. The better question is whether every authentication path is protected by MFA.
This is where legacy authentication becomes dangerous. Legacy protocols do not support modern MFA controls, so even when an organisation believes MFA is enabled, an attacker with a valid username and password may still be able to authenticate through an older protocol if it remains allowed. This is not a Microsoft 365 platform problem. It is a tenant configuration problem.
Threat actors such as APT28 (Fancy Bear) have used credential-based attacks and valid accounts as part of their operations. In a Microsoft 365 environment, that becomes especially relevant when older authentication methods, weak Conditional Access policies, or poorly monitored accounts are still in place.
Individually, these can look like small issues. Together, they can create a path from one compromised password to mailbox access, data exposure, business email compromise, or privilege escalation:
If any of these are hard to answer with confidence, that is a sign the tenant configuration hasn't kept pace with how the environment has grown and changed.
Microsoft 365 provides strong security capabilities, but those capabilities only reduce risk when they are correctly configured, actively maintained, and regularly reviewed. Security in Microsoft 365 is not a one-time setting. It is ongoing identity governance, configuration management, monitoring, and verification.
The real question is not whether Microsoft 365 can be secure. It is whether your Microsoft 365 tenant is configured in a way that matches the threats attackers actually use, and this is exactly what Celerity's Managed SIEM and MDR services are designed to monitor and enforce, day to day.
The only way to answer these questions with certainty is to assess your tenant against a recognised security standard, not assumptions.
Celerity's independent CIS Benchmark assessment reviews your Microsoft 365 configuration against the industry's leading hardening framework, covering identity, authentication, mailbox controls, and administrative access, and shows you exactly where the gaps are.
Blog
29 June 2026
Blog
17 June 2026
Blog
08 June 2026