Microsoft 365 is now the standard productivity platform for the majority of British businesses. Teams, Outlook, Word, Excel, SharePoint, OneDrive. A significant proportion of those businesses believe that having Microsoft 365 means their IT is being looked after.
It is not.
What Microsoft is responsible for
Microsoft runs the 365 platform. They maintain the servers, keep the applications available, issue software updates, and provide a service level agreement for platform uptime.
That is what the licence covers.
Microsoft is not responsible for how your organisation has configured the platform. They are not responsible for whether your data is backed up in a form that allows granular recovery if files are accidentally deleted. They are not responsible for whether your security settings are correct. They are not responsible for whether the devices accessing the platform are managed and secure. And they are not responsible for what happens to your data if an account is compromised.
The backup problem that surprises most businesses
OneDrive and SharePoint hold files. But they are not backups in the traditional sense.
If a file is deleted in OneDrive, it goes to the recycle bin. The recycle bin retention period is 93 days. After 93 days, it is gone. Permanently.
If a ransomware attack encrypts files in OneDrive through a compromised user account, the encrypted versions may sync across the estate before anyone notices. Recovering clean versions requires the attack to be detected quickly and the correct version history to be intact.
The expectation is that businesses will implement a third-party backup solution for Microsoft 365 data. Many do not. They discover this at the point at which they need to recover something.
The security configuration gap
A Microsoft 365 tenant can be configured to be reasonably secure or profoundly insecure depending on how it has been set up.
Multi-factor authentication can be enforced across all accounts or left as optional. Legacy authentication protocols, which do not support MFA and are a primary vector for account compromise, can be blocked or left enabled. Conditional access policies can restrict access to approved locations and devices, or be absent entirely.
The default configuration of a new Microsoft 365 tenant is not a secure configuration. It is a starting point that requires active management to harden.
A business that bought a Microsoft 365 licence, set up email, and has not revisited the configuration since is almost certainly running with a significant number of security gaps.
What managed Microsoft 365 actually involves
Proper 365 management covers: MFA enforcement across all accounts, legacy authentication blocked, conditional access configured, Defender for Business or equivalent endpoint protection deployed and monitored, SharePoint and Teams permissions reviewed, Exchange Online configured with anti-phishing policies, audit logging enabled and reviewed, and backup implemented for email, OneDrive, and SharePoint data.
IT-Works manages Microsoft 365 environments for businesses across the UK, covering security configuration, device management, backup, and ongoing administration. If your Microsoft 365 tenant has not been formally reviewed since it was set up, it is worth having someone look at it.
IT-Works Microsoft 365 managed service: enquiries@it-works.co.uk | 0121 270 0808 | https://it-works.co.uk/microsoft-365/
