5 Microsoft 365 Settings Older Tenants Should Check Now

Microsoft has quietly tightened a number of default settings in Microsoft 365 over the past few years. If you set up a new tenant today, you’d get meaningful protections that didn’t exist or weren’t turned on by default back in 2021 or 2022. That’s genuinely good news.

The catch is that none of those improvements reach back and update your existing setup. A setting Microsoft changed for new customers in 2024 stays exactly where it was in your tenant, which might mean it was never changed at all. And any sharing links, inbox forwarding rules, or app permissions granted before the change? Still active.

If your Microsoft 365 environment is more than two or three years old, was configured by a previous IT provider, or simply hasn’t been reviewed in a while, these five settings are worth checking. Many Greater New Orleans businesses in professional services inherited a Microsoft 365 setup that nobody has looked at since the initial install.

A few housekeeping notes before we dig in. Some of these settings require Microsoft 365 Business Premium, E3, or E5 licensing to change. If a toggle is grayed out, your license tier is likely the reason. A couple of these changes will generate questions from your staff because they affect things people do every day. None of them need to be changed all at once.

1. The Default Sharing Link in SharePoint and OneDrive

When someone in your organization shares a file from SharePoint or OneDrive, the link they create has a default scope. In older tenants, that scope is often “Anyone with the link,” which means anyone who receives that URL can open the file without signing in. No login required. No expiration date. No record of who else the link was forwarded to.

Newer sites created through Microsoft Teams now default to “Only people in your organization.” But the older tenant-level setting frequently still allows anyone-can-open links. Think about what that means practically: an employee who quit six months ago and emailed a proposal to their personal account still has a working link to your files, unless someone went in and manually revoked it.

The default sharing setting lives in the SharePoint admin center under Policies > Sharing. Switching the tenant default to “Specific people” means every new link will require the recipient to authenticate. You can also set a maximum expiration on any remaining open links so they time out automatically instead of living forever.

Rough time to change: about 15 minutes. This does not affect existing links until they’re regenerated.

2. External Email Forwarding Rules

Microsoft now blocks automatic email forwarding to outside addresses at the tenant level by default, through what’s called the outbound spam policy. This was part of a broader push toward more secure defaults.

The problem is that forwarding rules created before that change can still be running quietly in the background. A user who set up a rule years ago to copy every incoming email to a personal Gmail account may still be doing exactly that, depending on when the rule was created and how your tenant’s outbound policy was originally configured.

You want to verify two things. In the Microsoft Defender portal, under Email and Collaboration > Policies and Rules > Anti-spam policies > Anti-spam outbound policy, confirm that “Automatic forwarding rules” is set to “Off” or “Automatic – System-controlled.” Then run an audit of existing inbox rules across your users, looking for anything that forwards to an external address. The Microsoft Purview audit log lets you search specifically for inbox rule creation events.

Rough time: about 10 minutes to check the tenant setting, longer if you have many mailboxes to review.

3. Third-Party App Permissions Granted in the Past

Microsoft rolled out a user consent policy in mid-2025 that prevents most employees from independently approving third-party applications that request access to their files, email, or calendar. New consent requests now get routed to an administrator for review. That’s the right approach.

But again, the change only applies going forward. Any application a user approved before the policy took effect still has whatever permissions they granted, including the ability to read email or access files on that person’s behalf. Some of those apps may be tools someone installed years ago for a one-off project that everyone has long since forgotten about.

To see what’s already there, go to Microsoft Entra ID > Enterprise Applications > All applications. Sort by user consent and look at what currently has access to mail, files, or calendars. Anything you don’t recognize or no longer need can be revoked from the same screen.

Rough time: 30 to 60 minutes, depending on how many applications have accumulated over the years.

4. Audit Log Retention

The default audit log retention period in Microsoft 365 changed in October 2023. Audit (Standard) logs are now kept for 180 days, up from the previous 90. If you have E5 licensing or the Microsoft Purview Audit (Premium) add-on, you get one year of retention for Exchange, SharePoint, OneDrive, and Entra ID activity, with most other event types staying at 180 days.

For law firms, accounting practices, insurance agencies, and healthcare organizations, 180 days may not be enough. HIPAA, the FTC Safeguards Rule, and most state bar guidelines around client data assume you can produce records when asked, and the relevant timeframe is often measured in years rather than months. If you’re in a regulated industry and you’ve never verified your audit retention settings, this one deserves a look.

Audit retention policies live in the Microsoft Purview compliance portal under Audit > Audit retention policies. Extending retention past 180 days requires E5 licensing or the Purview Audit add-on. Once you’ve confirmed your license supports it, the configuration itself takes about 15 minutes.

5. MFA Enforcement and Security Defaults

Multi-factor authentication (MFA) is the single most effective thing most businesses can do to protect their accounts. It’s the second lock on the front door. Microsoft introduced Security Defaults in late 2019 and has been steadily tightening MFA requirements through 2024 and 2025, including mandatory MFA for administrator actions. New tenants get this enforced automatically.

Older tenants often don’t. There’s also a configuration trap that catches a lot of businesses: when an administrator enables Conditional Access policies (available with Business Premium and above), Microsoft expects that admin to take over MFA enforcement through those policies and may turn Security Defaults off in the process. If that transition was done quickly or incompletely, you can end up with Security Defaults off and a Conditional Access policy that doesn’t actually cover every user.

Check three places. In the Entra ID admin center under Properties > Manage Security Defaults, confirm whether Security Defaults is on or off. Under Protection > Conditional Access, confirm that a policy is actively requiring MFA for all users, including administrators. Pay close attention to any emergency backup admin accounts, which are sometimes intentionally excluded from Conditional Access for recovery purposes and left with no MFA protection as a result.

Rough time: about an hour, longer if you have multiple Conditional Access policies to sort through.

A Sensible Order to Roll the Changes

Some of these changes happen invisibly to your staff. Others affect things people do every day and will generate questions.

Start with audit log retention (#4) and the historical app consent review (#3). Neither one has any user-facing impact, so you can address them without any communication prep.

Verifying external forwarding (#2) is also largely invisible unless someone has a legitimate forwarding rule in place, which is uncommon. Do this next.

The sharing link default (#1) will eventually produce user questions, particularly from anyone who’s used to clicking “share” and pasting a link into an email. Give your team a heads-up before you change the tenant setting.

The MFA and Conditional Access review (#5) carries the highest stakes and the greatest risk of locking people out if it’s handled carelessly. Save it for last, and give yourself enough time to do it right. Rushing this one is how businesses in New Orleans and everywhere else end up with angry calls from staff who suddenly can’t get into their own accounts.

Frequently Asked Questions

Are my Microsoft 365 settings still at risk if my tenant was set up recently?

New tenants get stronger default protections than tenants set up a few years ago. That said, certain settings, including sharing scope, app permissions granted by users, and historical inbox rules, should be reviewed in any tenant regardless of how recently it was created.

What is the current Microsoft 365 default for “Anyone with the link” sharing?

At the tenant level, many existing tenants still permit “Anyone with the link” sharing. Newer SharePoint sites created through Microsoft Teams default to “Only people in your organization.” Check both the tenant-level setting and the individual site settings to understand what your users actually see.

Did Microsoft turn off external email forwarding by default?

Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. Inbox forwarding rules created before that change may still be active and should be audited.

How long does Microsoft 365 keep audit logs by default?

180 days under Audit (Standard), as of October 2023. One year for key workloads including Exchange, SharePoint, OneDrive, and Entra ID if you have E5 licensing or the Microsoft Purview Audit (Premium) add-on.

Does Security Defaults cover all my users?

On a new tenant, yes, including MFA enforcement for everyone. On an older tenant where Conditional Access policies have been enabled, Security Defaults may have been turned off, and MFA coverage now depends entirely on how those Conditional Access policies are configured.

If you’re not sure whether your Microsoft 365 tenant has any of these gaps, Bourn Technology can take a look before a small oversight becomes a serious problem. We work with professional services firms across the Greater New Orleans area to keep Microsoft 365 environments configured correctly and reviewed on a regular basis. Reach us at (504) 262-1234 or hello@go.bourntech.com and we’ll start with a straightforward conversation about where things stand.

Let's Talk...

SCHEDULE A GETTING TO
KNOW YOU
CALL TODAY

Give us a call at (504) 262-1234 or complete the form below and we’ll follow up with contact details for your call.