10 Microsoft 365 Security Settings Dubai Businesses Leave Open
Most Microsoft 365 tenants in Dubai run with defaults that were never designed to be final. These are the ten settings we find open again and again in tenant audits, what each one exposes, and the order in which to close them without disrupting your team.

Almost every Microsoft 365 tenant we audit in Dubai has the same profile: licensed properly, working smoothly, and configured with defaults that were never meant to be the final state. Microsoft ships M365 permissive so that nothing breaks on day one. Attackers know this better than most tenant owners do. These are the ten settings we find open again and again, what each one exposes, and the order to close them in.
1. Multi-factor authentication not enforced for everyone
Not "available." Not "enabled for admins." Enforced, for every account, through Conditional Access or security defaults. The overwhelming majority of account compromises we respond to began with a password-only sign-in. If only one item on this list gets fixed, make it this one, and pair it with number two so the enforcement has teeth.
2. Legacy authentication still allowed
Older protocols like IMAP, POP3, and SMTP AUTH ignore MFA entirely. Leaving them enabled while enforcing MFA is locking the front door with the side gate open. Attackers deliberately target legacy endpoints for password spraying because MFA never enters the conversation. Block legacy auth tenant-wide, with a scoped exception only where a genuinely unavoidable device needs one, and an expiry date on that exception.
3. No Conditional Access policies at all
Conditional Access is the policy engine that decides who gets in, from where, on what device. Most Business Premium and E3 tenants already own it and have zero policies configured. The baseline set (MFA for all, block legacy auth, require compliant devices for sensitive apps, protect admin roles hardest) is documented on our Conditional Access page, including how to stage policies in report-only mode so nobody gets locked out.
4. Anyone can consent to third-party apps
By default, any user can grant OAuth applications access to their mail and files. Modern phishing increasingly skips the password entirely: the victim approves a malicious app once, and the attacker keeps access even after a password reset. Restrict user consent to verified publishers with admin approval for everything else, then review the grants that already exist. Some of the worst findings in our audits are apps granted years ago by people who left.
5. External sharing wide open in SharePoint and OneDrive
"Anyone with the link" is a convenient default and a data-loss mechanism. Links get forwarded, indexed, and outlive the deal they were created for. Set sharing to specific people by default, require sign-in for external recipients where the business allows, and put expiry on anonymous links if you must keep them. Then audit what has already been shared: the history does not clean itself up.
6. Mailbox auditing and alerting never reviewed
M365 records a rich audit trail, but a trail nobody reads is not a control. The pattern we see after business email compromise is always the same: the evidence was in the logs for weeks. At minimum, alert on suspicious inbox rules, impossible travel sign-ins, and mass file downloads. If nobody in-house will watch the alerts, that is a solvable staffing question, not a reason to go without.
7. Malicious inbox rules and forwarding unmonitored
The first thing an attacker does inside a compromised mailbox is create rules: forward copies of invoices externally, delete replies from the real vendor, hide warnings. Block automatic external forwarding at the tenant level and alert on new rule creation. This single control has caught live intrusions in tenants we manage.
8. Admin roles over-assigned and permanent
Tenants routinely run with five, eight, a dozen permanent Global Admins, including ex-employees and the previous IT provider. Every one is a full-tenant compromise waiting on one phished credential. Two to four named Global Admins, everything else on least-privilege roles, break-glass accounts documented, and where licensing allows, just-in-time elevation instead of standing power.
9. Safe Links and Safe Attachments unconfigured
Exchange Online Protection catches commodity spam. The targeted phishing that actually costs Dubai businesses money (fake invoices, CEO impersonation, payment redirection) is what Defender for Office 365 exists for, and many tenants that already own it through their licensing have never turned the policies on. Check what your plan includes before assuming you need to buy anything.
10. No DLP, labels, or data governance
Emirates ID scans, salary files, and client contracts move through mail and Teams unlabelled and unmonitored in most tenants, which is precisely what the UAE Personal Data Protection Law expects you to be able to control. Start small: identify the data types that matter, label them, and add DLP policies in audit mode before enforcing. Perfection is not required on day one; visibility is.
Closing them in the right order
Do not flip everything in one weekend; that is how you lock out your own finance team. The sequence that works: identity first (items 1 to 3), then app and sharing hygiene (4 and 5), then detection (6 and 7), then privilege cleanup (8), then mail protection and data governance (9 and 10), each staged in report-only or audit mode before enforcement.
Find out which of the ten are open in your tenant
Every setting above is checked, scored, and prioritised in our Microsoft 365 security audit: a read-only assessment of your tenant with a findings report and a remediation roadmap in priority order. It requires no changes to your environment and no disruption to your team. If you would rather see the whole security picture first, start at the Microsoft security services hub.
Related Articles
Top 10 Cybersecurity Threats Facing UAE Companies in 2024
Discover the most critical cybersecurity threats targeting businesses in the UAE and how to protect your organization.
Microsoft Defender: Complete Security Solution for SMEs
Comprehensive guide to implementing Microsoft Defender for small and medium enterprises in the UAE.
Implementing Zero Trust Security in Your Organization
Learn how to implement Zero Trust security model to protect your organization from modern cyber threats.