The move to Microsoft 365 is complete. SharePoint is live. Teams is the default communication platform. Exchange Online handles email. Entra ID is the identity provider. Your IT team is breathing easier.
Meanwhile, your cloud identity layer may be your most exposed attack surface — and most of the risk comes from configuration choices made during migration, under time pressure, without enough security scrutiny.
Mistake 1: Legacy Authentication Still Enabled
Legacy authentication protocols — POP3, IMAP, SMTP Auth, Basic Auth — bypass Conditional Access entirely. They don't support MFA. Microsoft disabled them by default in 2022, but many tenants re-enabled them during migration for legacy applications and never turned them back off. If legacy auth is enabled, your Conditional Access policies provide incomplete protection.
Fix: Use Entra ID sign-in logs to identify legacy auth activity. Disable it for all accounts where no legitimate use exists.
Mistake 2: Over-Permissioned Enterprise Applications
Third-party applications with OAuth tokens often request far broader permissions than needed. An app requesting Mail.ReadWrite.All and Files.ReadWrite.All has access to everything in your tenant. Most organisations have dozens of these over-permissioned applications and couldn't tell you what they are.
Fix: Review enterprise application permissions. Remove unused applications. Restrict user OAuth consent. Require admin approval for new consent requests.
Mistake 3: No Conditional Access Policy
Without Conditional Access, any valid credential can access your environment from anywhere on any device. A mature Conditional Access posture includes: MFA required for all users, block access from untrusted locations/devices, require compliant devices for sensitive applications, block legacy authentication, and phishing-resistant MFA for admin accounts.
Fix: Conduct a Conditional Access policy review. Map coverage, exclusions, and fallthrough behaviour.
Mistake 4: Global Administrators Without Protection
Many organisations have multiple users with permanent Global Admin assignment, using their daily-driver email account, protected by standard MFA. Compromise of a Global Admin is effectively complete tenant takeover.
Fix: Reduce permanent Global Admin to two break-glass accounts with hardware MFA. Use Entra PIM for just-in-time admin access. Separate admin accounts from daily-use accounts.
Mistake 5: Incomplete Offboarding in Hybrid Environments
In hybrid environments, disabling the on-premises AD account may not revoke Entra ID tokens. Former employees can retain access to Teams, SharePoint, and third-party SaaS applications that use M365 as an identity provider.
Fix: Verify that AD account disablement triggers Entra ID session revocation. Implement token revocation as part of the offboarding checklist.
Mistake 6: Ignoring the Attack Signals in Your Logs
Entra ID sign-in logs contain evidence of attacks happening right now in most enterprise tenants — impossible travel, credential spray patterns, legacy auth from unusual locations, token replay attacks. Most organisations aren't looking at these logs.
Fix: Connect Entra ID logs to a SIEM. Create detection rules for impossible travel, high-volume failed authentications, and legacy auth from new locations.