Microsoft has quietly tightened a lot of Microsoft 365 defaults over the last few years. New tenants get noticeably better protection by default than they did in 2021.
The catch is that the changes don’t apply retroactively. A setting Microsoft changed for new tenants in 2024 doesn’t change in yours. Old sharing links, inbox rules, third-party app consents and MFA configurations sit exactly where they were.
Five settings worth checking, especially if your tenant is more than two or three years old or was set up by a previous IT provider.
A note before you start. Some of these require Microsoft 365 Business Premium, E3 or E5. If a toggle is greyed out, your licence is most likely the reason. A couple of the changes will generate questions from your team, because they alter how something they already do works. None of it needs to be flipped at once.
1. The default sharing link in SharePoint and OneDrive
When someone in your firm shares a file, the link they generate has a default scope. In older tenants, that default is often “Anyone with the link” – meaning anyone who receives the URL can open the file without signing in. No expiry. No record of who else the link was forwarded to.
Newer Teams-created sites default to “Only people in your organisation.” Older sites and the tenant-level setting often still allow Anyone links. A departing employee who emailed a proposal to their personal account six months ago still has a working link, unless someone manually revoked it.
The setting lives in the SharePoint admin centre, under Policies > Sharing. Switching the tenant default to “Specific people” forces every new link to require sign-in. You can also set a maximum expiry on remaining “Anyone” links so they time out.
Rough time: 15 minutes. No effect on existing links until they’re regenerated.
2. External email forwarding rules
Microsoft now blocks automatic forwarding to external addresses by default at the tenant level, through the outbound spam policy.
Forwarding rules created before that change can still be live, though. A user who set up a rule years ago to copy every email to a personal Gmail address may still be exporting your data, depending on how the rule was written.
In the Microsoft Defender portal, under Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy, confirm “Automatic forwarding rules” is set to Off or System-controlled. Then audit existing inbox rules across your users for any forward-to-external configurations. The Purview audit log lets you search for inbox rule creation events.
Rough time: 10 minutes for the tenant setting, longer for the rule review.
3. Historical third-party app consents
A Microsoft-managed user consent policy took effect by default in July 2025, preventing users from granting third-party applications access to their files and sites. New consent requests now route to an administrator.
The change applies going forward. Apps that were given user consent before the policy still have whatever permissions they were granted, including the ability to read mail, calendars and files on the user’s behalf. Some are tools someone installed years ago and forgot about.
To review what’s already in place, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent. Anything you don’t recognise or no longer need can be revoked from the same screen.
Rough time: 30 to 60 minutes for the review.
4. Audit log retention
The Microsoft 365 default audit log retention period changed in October 2023. Standard logs are now retained for 180 days, up from 90. E5 licences (and the Microsoft Purview Audit Premium add-on) provide one year of retention for Exchange, SharePoint, OneDrive and Entra ID logs.
For a professional services firm, 180 days may not match your retention obligations. Law Society of Ireland record-keeping rules, CCAB-I guidance for accountants, and Central Bank requirements for regulated firms typically work in years, not months. GDPR doesn’t fix a specific audit-log period, but it expects you to be able to evidence accountability.
The setting lives in the Microsoft Purview portal under Audit > Audit retention policies. Extending beyond 180 days requires E5 or the Purview Audit add-on. Configuration is about 15 minutes once the licence is in place.
5. MFA enforcement and Security Defaults
This is the area most likely to be inconsistent in older tenants.
Microsoft introduced Security Defaults in late 2019, and the feature now enforces MFA automatically on new tenants. Microsoft has also progressively made MFA mandatory for admin actions in the M365 admin centre and Azure portal through 2024 and 2025.
Tenants set up before Security Defaults rolled out may have no baseline enforcement. There’s also a common configuration trap: when an admin enables a Conditional Access policy, Microsoft expects you to take over MFA enforcement through that policy and may turn Security Defaults off. If the transition was rushed, you can end up with Security Defaults off and a Conditional Access policy that doesn’t cover every user.
Check three places. In the Entra admin centre under Properties > Manage Security Defaults, confirm whether Security Defaults is on. Under Protection > Conditional Access, confirm a policy is actively enforcing MFA for all users, including administrators. Pay particular attention to break-glass admin accounts, which are sometimes excluded for emergency access reasons and end up with no MFA as a result.
Rough time: about an hour. Longer if Conditional Access has been built out over time.
A sensible order
- Audit log retention (4) and the historical app consent review (3) carry no user-facing impact. Start there.
- Verifying external forwarding (2) is silent unless someone has a legitimate forwarding rule, which is rare.
- The sharing default (1) will generate user questions from anyone used to pasting an “Anyone” link into an email. Tell your team before you flip the tenant setting.
- The MFA and Conditional Access review (5) is the highest-stakes change and the one most likely to lock people out if it’s done badly. Save it for last and budget the time to do it properly.
If you’d like us to walk through these in your tenant, we’re happy to help.

