Microsoft has tightened several Microsoft 365 settings over the past few years. Newer tenants get more protection out of the box than tenants set up before 2022 or so. The catch is that those changes don’t apply retroactively — a Microsoft 365 setting changed for new tenants in 2024 doesn’t automatically update in yours, and historical configurations around file sharing, email forwarding, third-party app consent, and MFA enforcement stay exactly where they were when your tenant was first set up.
For Southeast Texas businesses whose Microsoft 365 tenant — and its Microsoft 365 settings — is more than two or three years old, was configured by a previous IT provider, or simply hasn’t been audited in a while, the following five Microsoft 365 settings are worth checking — and in several cases, worth correcting. Some carry direct security risk. Others affect your compliance posture or could surface as an insurance concern. None of the Microsoft 365 settings below require a major project to fix.
A quick note before diving into these Microsoft 365 settings: some of these Microsoft 365 settings changes require Microsoft 365 Business Premium, E3, or E5 licensing. If a setting is grayed out in your admin center, your license tier is most likely the reason. And none of these need to be changed all at once — the final section covers a sensible order.
Microsoft 365 Settings Worth Reviewing: The Full List
1. The Default Sharing Link — One of the Most Exposed Microsoft 365 Settings
When someone in your organization shares a file from SharePoint or OneDrive, the link they generate has a default scope. In older Microsoft 365 tenants, that scope is often set to “Anyone with the link” — meaning anyone who receives the URL can open the file without signing in. No authentication required. No expiration. No record of who the link was forwarded to after it left your organization.
Newer Teams-created sites now default to “Only people in your organization.” But older sites and the tenant-level setting frequently still allow Anyone links. A departing employee who shared a proposal to their personal email six months ago still has a working link — unless someone manually revoked it.
The default sharing link type lives in the SharePoint admin center under Policies → Sharing. Switching the tenant default to “Specific people” forces every new link to require authentication. You can also set a maximum expiration on any remaining Anyone links so they time out automatically. Rough time to change: 15 minutes. No impact on existing links until they’re regenerated.
2. External Email Forwarding Rules
Microsoft now blocks automatic email forwarding to external addresses at the tenant level by default, through the outbound spam policy. This is part of Microsoft’s secure-by-default initiative and applies to new tenants.
The problem: forwarding rules created before that change can still be active. A user who set up a rule years ago to forward every email to a personal Gmail address may still be exporting your business data — depending on how the rule was constructed and whether it predates the policy change. Tenants with custom outbound spam policies configured before the new default may also not reflect the current behavior.
Two things to verify on this Microsoft 365 settings check. In the Microsoft Defender portal under Email & Collaboration → Policies & Rules → Anti-spam policies → outbound policy, confirm the automatic forwarding setting is set to “Off” or “Automatic – System-controlled.” Then audit existing inbox rules across your users for any forward-to-external configurations. The Microsoft Purview audit log lets you search for inbox rule creation events across the entire tenant. Rough time: 10 minutes to verify the tenant setting, longer if you need to review rules across all mailboxes.
3. Historical Third-Party App Consents
A Microsoft-managed user consent policy was enabled by default in July 2025, preventing users from consenting to most third-party applications that request access to their files and sites. New consent requests now route to an admin for review.
The change applies going forward. Apps granted user consent before the policy took effect still have whatever permissions they were given — including the ability to read mail, calendars, and files on behalf of the user. Some of those apps may be tools an employee installed years ago and no longer uses, or applications approved during a one-off project that nobody remembers.
To review this Microsoft 365 settings exposure, go to Microsoft Entra ID → Enterprise Applications → All applications. Sort by user consent and look at what currently has access to mail, files, or calendars. Anything unrecognized or no longer needed can be revoked from the same screen. Rough time: 30 to 60 minutes depending on how many historical apps are in the list.
4. Mailbox and Tenant Audit Log Retention
The default audit log retention period in Microsoft 365 changed in October 2023. Audit (Standard) logs are now retained for 180 days, up from the previous 90 days. Customers with E5 licensing or the Microsoft Purview Audit Premium add-on get one year of retention for Exchange, SharePoint, OneDrive, and Entra ID records.
For Southeast Texas businesses in healthcare, financial services, legal, or any regulated industry, 180 days may not satisfy your retention obligations. HIPAA, the FTC Safeguards Rule, and most state bar rules around client data assume you can produce records on request — and the relevant period is often measured in years, not months.
Audit retention policies live in the Microsoft Purview compliance portal under Audit → Audit retention policies. Extending retention beyond 180 days requires E5 or the Purview Audit add-on. The configuration itself takes about 15 minutes once you’ve confirmed your license supports it.
5. MFA Enforcement and Security Defaults — the Microsoft 365 Settings Most Likely to Be Inconsistent
MFA enforcement is the Microsoft 365 setting most likely to be inconsistent in older tenants. Microsoft introduced Security Defaults in late 2019, and the feature now enforces MFA automatically on new tenants. Microsoft has also been progressively making MFA mandatory for admin actions through 2024 and 2025.
Tenants created before Security Defaults rolled out may have no baseline MFA enforcement at all. There’s also a common configuration gap: when an admin enables a Conditional Access policy (available with Business Premium and above), Microsoft expects you to take over MFA enforcement through that policy and may turn Security Defaults off. If the transition was done quickly, you can end up with Security Defaults off and a Conditional Access policy that doesn’t cover every user.
Check three places. In the Entra ID admin center under Properties → Manage Security Defaults, confirm whether Security Defaults is on or off. Under Protection → Conditional Access, confirm a policy is actively enforcing MFA for all users including administrators. Pay particular attention to break-glass admin accounts — these are sometimes excluded from Conditional Access for emergency access reasons and left with no MFA as a result. Rough time: about an hour, longer if Conditional Access has multiple existing policies to map.
A Sensible Order to Make the Changes
Some of these Microsoft 365 settings changes are invisible to your users. Others change how something they do every day works — and will generate support tickets if done without warning.
Start with audit log retention (#4) and the historical app consent review (#3) — both are Microsoft 365 settings changes with no user-facing impact. Both carry no user-facing impact and can be done quietly.
Verifying external forwarding (#2) is also silent unless someone has a legitimate forwarding rule in place, which is uncommon. Do this next.
The sharing default (#1) will eventually generate user questions, particularly from anyone used to sharing files via open links. Communicate the change before flipping the tenant setting.
The MFA and Conditional Access review (#5) touches the Microsoft 365 settings most likely to lock someone out if done without care and the one most likely to lock someone out if done without care. Save it for last and budget the time to do it properly.
If you’d like help working through these Microsoft 365 settings — or want a full tenant audit — our, our managed IT services include tenant security reviews and configuration audits — schedule a free IT checkup to get started.
Frequently Asked Questions: Microsoft 365 Settings
Are my Microsoft 365 settings still at risk if my tenant was set up recently? New tenants get better protection out of the box. Even so, certain settings — including sharing scope, app consents granted by users, and historical inbox rules — need to be reviewed in any tenant regardless of age. The five settings above apply to both new and older tenants to varying degrees.
What is the current Microsoft 365 default for “Anyone with the link” sharing? At the tenant level, many existing tenants still permit “Anyone with the link” sharing. Newer Teams-created SharePoint sites default to “Only people in your organization.” Verify both the tenant-level setting and individual site-level settings to know what your users see in practice.
Did Microsoft turn off external email forwarding by default? Yes. Microsoft’s outbound spam policy now blocks automatic external forwarding by default at the tenant level. Existing inbox rules created before that change may still be active and are worth auditing — particularly in older tenants or tenants with custom outbound policies.
How long are Microsoft 365 audit logs kept by default? 180 days for Audit (Standard), as of October 2023. One year for key workloads — Exchange, SharePoint, OneDrive, and Entra ID — if you have E5 or the Microsoft Purview Audit Premium add-on. Regulated industries often need longer retention than the default provides.
Does Security Defaults cover all my users for MFA? On a new tenant, yes. On an older tenant that has had Conditional Access policies enabled, Security Defaults may have been turned off — and MFA coverage now depends entirely on how Conditional Access has been configured. Gaps in that configuration can leave individual users or admin accounts without MFA enforcement.
Article used with permission from The Technology Press.
