Microsoft 365 needs a security plan of its own
Knowing which platform your organization uses is a starting point. Its protection depends on how it is configured, who administers it, and whether the arrangements match your business.
Microsoft describes a shared responsibility model: the division varies by service, while customers retain responsibility for their data, identities, and the components they control. Buying a subscription does not settle those operational responsibilities. Microsoft’s shared responsibility guidance
Start with account ownership
Ask who authorizes new accounts, changes access when roles change, and removes access when someone leaves. Request a recent completed example with personal details removed. Check how the process covers contractors, administrator accounts, and accounts used by applications.
Automation may perform parts of this work. Someone still needs to own its configuration, exceptions, and verification.
Check the policy and its reach
Ask your administrator to show which authentication and device-access policies apply to which users. Review exclusions and their reasons. Confirm the relevant capabilities and licensing for your environment before agreeing on a change; features and defaults can vary.
The leadership question is whether the intended protection reaches the intended accounts. A screenshot showing that a feature exists does not answer that question by itself.
Review access to information
Choose a sensitive shared location and ask who can access it, including external guests. Then ask who approves that access and when it was last reviewed. A small sample cannot establish that every permission is correct, but it can reveal whether the review process is workable.
Apply the same approach to mailbox delegation and external forwarding: establish what is permitted, how exceptions are approved, and who investigates unexpected changes. Do not assume that a platform alert is being reviewed simply because the capability is available.
Connect alerts to action
For one relevant alert, trace the route from detection to investigation and response. Identify the receiving team, the hours covered, and who can disable an account or revoke access. If several providers are involved, make the handoff explicit.
Choose the next action from the evidence
A confirmed configuration gap may call for an administrative change. An undocumented responsibility may call for an agreement. Unavailable evidence may call for further verification. Those are different actions, and each needs an owner.
Published by Security Reality Check LLC.
Want to apply this to your situation?
Tell us the question this article raised, the providers or processes involved, and what you need to decide next.
You do not need to send confidential documents to start the conversation.
Contact us about a review