We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
Security2026-09-0310 min read

10 Microsoft 365 Security Settings Dubai Businesses Leave Open

Most Microsoft 365 tenants in Dubai run with defaults that were never designed to be final. These are the ten settings we find open again and again in tenant audits, what each one exposes, and the order in which to close them without disrupting your team.

ByMohd Ahsan
Back to Blog
Defender security centre showing endpoint protection status

Almost every Microsoft 365 tenant we audit in Dubai has the same profile: licensed properly, working smoothly, and configured with defaults that were never meant to be the final state. Microsoft ships M365 permissive so that nothing breaks on day one. Attackers know this better than most tenant owners do. These are the ten settings we find open again and again, what each one exposes, and the order to close them in.

1. Multi-factor authentication not enforced for everyone

Not "available." Not "enabled for admins." Enforced, for every account, through Conditional Access or security defaults. The overwhelming majority of account compromises we respond to began with a password-only sign-in. If only one item on this list gets fixed, make it this one, and pair it with number two so the enforcement has teeth.

2. Legacy authentication still allowed

Older protocols like IMAP, POP3, and SMTP AUTH ignore MFA entirely. Leaving them enabled while enforcing MFA is locking the front door with the side gate open. Attackers deliberately target legacy endpoints for password spraying because MFA never enters the conversation. Block legacy auth tenant-wide, with a scoped exception only where a genuinely unavoidable device needs one, and an expiry date on that exception.

3. No Conditional Access policies at all

Conditional Access is the policy engine that decides who gets in, from where, on what device. Most Business Premium and E3 tenants already own it and have zero policies configured. The baseline set (MFA for all, block legacy auth, require compliant devices for sensitive apps, protect admin roles hardest) is documented on our Conditional Access page, including how to stage policies in report-only mode so nobody gets locked out.

4. Anyone can consent to third-party apps

By default, any user can grant OAuth applications access to their mail and files. Modern phishing increasingly skips the password entirely: the victim approves a malicious app once, and the attacker keeps access even after a password reset. Restrict user consent to verified publishers with admin approval for everything else, then review the grants that already exist. Some of the worst findings in our audits are apps granted years ago by people who left.

5. External sharing wide open in SharePoint and OneDrive

"Anyone with the link" is a convenient default and a data-loss mechanism. Links get forwarded, indexed, and outlive the deal they were created for. Set sharing to specific people by default, require sign-in for external recipients where the business allows, and put expiry on anonymous links if you must keep them. Then audit what has already been shared: the history does not clean itself up.

6. Mailbox auditing and alerting never reviewed

M365 records a rich audit trail, but a trail nobody reads is not a control. The pattern we see after business email compromise is always the same: the evidence was in the logs for weeks. At minimum, alert on suspicious inbox rules, impossible travel sign-ins, and mass file downloads. If nobody in-house will watch the alerts, that is a solvable staffing question, not a reason to go without.

7. Malicious inbox rules and forwarding unmonitored

The first thing an attacker does inside a compromised mailbox is create rules: forward copies of invoices externally, delete replies from the real vendor, hide warnings. Block automatic external forwarding at the tenant level and alert on new rule creation. This single control has caught live intrusions in tenants we manage.

8. Admin roles over-assigned and permanent

Tenants routinely run with five, eight, a dozen permanent Global Admins, including ex-employees and the previous IT provider. Every one is a full-tenant compromise waiting on one phished credential. Two to four named Global Admins, everything else on least-privilege roles, break-glass accounts documented, and where licensing allows, just-in-time elevation instead of standing power.

9. Safe Links and Safe Attachments unconfigured

Exchange Online Protection catches commodity spam. The targeted phishing that actually costs Dubai businesses money (fake invoices, CEO impersonation, payment redirection) is what Defender for Office 365 exists for, and many tenants that already own it through their licensing have never turned the policies on. Check what your plan includes before assuming you need to buy anything.

10. No DLP, labels, or data governance

Emirates ID scans, salary files, and client contracts move through mail and Teams unlabelled and unmonitored in most tenants, which is precisely what the UAE Personal Data Protection Law expects you to be able to control. Start small: identify the data types that matter, label them, and add DLP policies in audit mode before enforcing. Perfection is not required on day one; visibility is.

Closing them in the right order

Do not flip everything in one weekend; that is how you lock out your own finance team. The sequence that works: identity first (items 1 to 3), then app and sharing hygiene (4 and 5), then detection (6 and 7), then privilege cleanup (8), then mail protection and data governance (9 and 10), each staged in report-only or audit mode before enforcement.

Find out which of the ten are open in your tenant

Every setting above is checked, scored, and prioritised in our Microsoft 365 security audit: a read-only assessment of your tenant with a findings report and a remediation roadmap in priority order. It requires no changes to your environment and no disruption to your team. If you would rather see the whole security picture first, start at the Microsoft security services hub.

Share this article:

Related Articles

Security

Top 10 Cybersecurity Threats Facing UAE Companies in 2024

Discover the most critical cybersecurity threats targeting businesses in the UAE and how to protect your organization.

2025-10-125 min read
Security

Microsoft Defender: Complete Security Solution for SMEs

Comprehensive guide to implementing Microsoft Defender for small and medium enterprises in the UAE.

2025-10-125 min read
Security

Implementing Zero Trust Security in Your Organization

Learn how to implement Zero Trust security model to protect your organization from modern cyber threats.

2025-10-125 min read
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy