Ordered by what each gap costs you if it is the one that is exploited. Most of these are settings you already own rather than anything to buy.
highAdmin accounts
Administrator rights sit on an account that reads email
The account that opens attachments all day is also the account that can reset anyone’s password, read any mailbox, and turn off logging. One bad click stops being a problem on one machine and becomes control of the whole tenant.
Try this: Ask whoever administers Microsoft 365 which account they were signed in as the last time they changed a setting. If it is the one with their name on the business cards, it is the same account.
What changing it involves: A separate admin account per administrator, used only for admin work, with the everyday account holding no privileges. It is free, it takes an afternoon, and it is the single highest-value change in this whole check.
moderateAdmin accounts
Unclear how administrator access is being used
In practice this nearly always means one account does both, because separating them is a deliberate act nobody does by accident.
Try this: In the admin centre, look at the list of users with admin roles. If the names match the people who also appear in your everyday email, they are the same accounts.
What changing it involves: Check first, then separate if needed. Checking takes minutes.
moderateAdmin accounts
More global administrators than the business needs
Every global admin is a full copy of the keys. The count usually grows because it was easier than working out which lesser role someone actually needed, and it never shrinks on its own.
Try this: List them, then ask what each one has actually done in the last six months. Most will not have used the privilege at all.
What changing it involves: Cut to two, with a documented emergency account kept aside. Everyone else moves to the narrower role that matches what they really do.
highAdmin accounts
Administrator access has spread, or nobody is counting
Once the list is long enough that nobody can recite it, it usually includes a former employee, a supplier who set something up years ago, or an account nobody recognises. Each is a full set of keys held by someone outside your control.
Try this: Pull the list of admin role holders and read it out loud. The test is whether anyone in the room can explain every name on it.
What changing it involves: An access review, then a cut. Expect to find at least one account that surprises you, because there almost always is one.
criticalSign-in
A sign-in path that ignores multi-factor is still open
This is the finding that quietly undoes the control everyone is proudest of. If legacy authentication is permitted, an attacker with a valid password can sign in through it and is never asked for the second step. Your multi-factor rollout protects the front door while this leaves a window open.
Try this: Ask whether anything still needs it: an old scanner that emails documents, a copier, a line-of-business app. Whatever comes back is the list to fix, and it is usually shorter than feared.
What changing it involves: Block it tenant-wide, having first moved whatever genuinely needs it onto a modern method or a tightly scoped exception. Usually a short piece of work with a very large effect.
highSign-in
Nobody knows whether the multi-factor bypass is open
Tenants created some years ago allowed it by default, and it stays allowed unless somebody deliberately turned it off. Not knowing usually means nobody did.
Try this: The sign-in logs will show whether anything is still connecting this way, and from where. That report answers the question in about five minutes.
What changing it involves: Check the logs, block what is not needed, and handle the exceptions individually. This is worth doing before anything else on the list.
highSign-in
Shared mailboxes have live logins with shared passwords
A password several people know is a password nobody will change when one of them leaves, and these accounts are usually the ones left out of any multi-factor rollout. They are also the mailboxes suppliers send invoices to, which is exactly where payment fraud starts.
Try this: Ask how many people know the password to your main info@ or accounts@ mailbox, and when it was last changed. Then ask whether any of them have left.
What changing it involves: Convert them to shared mailboxes with sign-in blocked, and give access through named accounts instead. Everyone keeps the access they had, but every action now has a name against it.
moderateSign-in
Unclear whether generic mailboxes can be signed into
Worth resolving, because these accounts are consistently the weakest logins in a tenant and the least likely to be covered by anything.
Try this: Look at the user list for entries that are not people. Anything with a licence and a job title of "reception" or "accounts" is worth a closer look.
What changing it involves: Identify them, then decide which genuinely need a login. In my experience the answer is usually none of them.
criticalMail flow
A compromised mailbox could forward mail out unnoticed
This is what an attacker does after getting in and before doing anything visible. A rule quietly copies mail to an outside address, often into a folder the owner never opens, and they read your invoices and payment conversations for weeks. Everything still works, which is the point. It is the single most common persistence trick on a small business tenant.
Try this: Ask for a report of every mailbox rule that forwards or redirects outside the organisation. If nobody can produce one, nobody has ever looked.
What changing it involves: Block automatic external forwarding at the tenant level and alert on any attempt to create one. Both are built in, and neither costs anything beyond the time to switch them on.
highMail flow
No visibility over mailbox forwarding rules
Not knowing and not being alerted amount to the same thing here, because this attack is specifically designed to be invisible to the mailbox owner.
Try this: Run the report anyway. It takes minutes, and the rules it finds are usually either years old and forgotten, or the answer to a question you did not know you had.
What changing it involves: Check what exists now, then block and alert going forward.
highMail flow
Nothing is watching for mail that impersonates your own people
The default filtering is built for bulk spam. The message that costs money is written for your business, sent to one person, and appears to come from the owner or the finance manager. It is not spam by any measure the default filter uses, and it arrives looking entirely ordinary.
Try this: Look at the actual sender address, not the display name, on the last odd request anyone received. Display names are free to set to anything at all.
What changing it involves: Turn on impersonation protection for your named directors and your own domain, and mark external mail visibly as external. Included in the business plans, and the external banner alone catches a surprising share.
moderateMail flow
Unclear what mail protection is configured
Much of this is included in the licences you already pay for and switched off by default, so the answer is often that you own it and are not using it.
Try this: Check whether mail from outside the company is visibly marked as external when it arrives. If it is not, nothing is adding that warning.
What changing it involves: A short review of what your current subscription already includes, then turning on the parts you are paying for.
highSign-in
A blocked account can still be signed in on a phone
This is the gap almost everybody has, and it is genuinely counter-intuitive. Blocking sign-in prevents the next login. A device already holding a valid session keeps working, sometimes for a long time, so a leaver can keep reading mail from a personal phone after their access is officially gone.
Try this: Take the last person who left. Ask whether anyone signed them out of their devices, or only disabled the account. Almost always the second.
What changing it involves: Add "revoke sessions" to the leaver checklist. It is one action in the admin centre and it takes seconds once anyone knows to do it.
highSign-in
No defined process for removing access
Where there is no checklist, offboarding is done from memory by whoever is around, and memory covers email. It rarely covers the phone still in someone’s pocket, or the files synced to their home computer.
Try this: Ask what happened the last time someone left. Not what should happen. What did.
What changing it involves: A written leaver checklist covering block, sign out, mailbox handover and device removal. The checklist matters more than the tooling.
moderateSign-in
Any correct password works from anywhere in the world
Without conditions, the only thing between an attacker and your mail is the credential itself. Stolen credentials are bought in bulk, and the buyer is rarely in Chester County. A rule that simply declines sign-ins from countries you do not trade with removes most of that traffic at no cost to your staff.
Try this: Look at the sign-in logs for the last month and sort by country. Most businesses find at least one attempt from somewhere nobody has ever visited.
What changing it involves: Start with a country restriction, which is the highest value for the least disruption, then add device conditions if the licensing supports it. Check what your plan includes before assuming.
moderateSign-in
Unclear whether any sign-in conditions exist
These are not on by default and nobody adds them by accident, so not knowing usually means there are none.
Try this: The sign-in logs will show it: if you can see successful sign-ins from unusual places, nothing is stopping them.
What changing it involves: Confirm what your licences allow, then apply the conditions that fit how the business actually works.
moderateMonitoring
Sign-in activity is recorded and never read
The evidence of a compromise usually exists in the logs well before anyone notices the consequences. Nobody reading them means the first sign of a problem is a supplier asking why they were sent a strange invoice.
Try this: Open the sign-in report and look at the last thirty days. Successful sign-ins from places nobody has been are the ones worth explaining.
What changing it involves: Alerting rather than reading, so it comes to you instead of you going to look. That is what monitoring on a managed plan actually means in practice.
moderateMonitoring
No named owner for tenant monitoring
Where nobody owns it, everybody assumes somebody else is doing it, and the reports sit unread for years.
Try this: Ask directly who would notice a sign-in from another continent, and how. If there are two different answers in the room, the answer is nobody.
What changing it involves: Name an owner, or route the alerts to someone whose job it is.
moderateData and sharing
External sharing has never been reviewed
Sharing links are created to solve an immediate problem and then live forever. Years later a link created for one supplier is still live, sometimes set to anyone with the link, and the person who made it left long ago.
Try this: Ask for a list of files currently shared with anyone who has the link. The age of the oldest one is usually the surprising part.
What changing it involves: A one-off review to clear out what is stale, then expiry dates on new links so this does not rebuild.
moderateData and sharing
No visibility over what has left the tenant
It can be checked, and it is worth doing once. Businesses are usually more surprised by what is shared than by anything else in this list.
Try this: The sharing reports in the admin centre answer this. Ask whoever has admin access to run one.
What changing it involves: Run the report, clear what is stale, then set link expiry as the default.
moderateMonitoring
Not enough audit history to investigate anything
Compromises are usually discovered long after they start. If the record does not reach back to when it began, you cannot establish what was accessed, which is precisely the question an insurer, a client, or a lawyer will ask.
Try this: Ask how far back the audit log actually goes on your plan. Compare that to how long you think it would take you to notice a quiet compromise.
What changing it involves: Confirm auditing is switched on, then check the retention your licences give you. Longer retention is a licensing question and worth pricing before you need it rather than after.
moderateMonitoring
Unknown audit retention
Auditing is on by default in current tenants but retention varies by licence, and older tenants sometimes have it switched off entirely.
Try this: Try to search the audit log for something ordinary from three months ago. Whether it returns anything is your answer.
What changing it involves: Check it is enabled, then confirm the retention period matches how long you would realistically take to notice a problem.
highRecovery
Cloud data is only as recoverable as the built-in retention
The retention built into Microsoft 365 is short and designed for accidents, not for a compromised account quietly deleting a year of mail or a dispute that surfaces months later. The gap between what people assume and what is actually retained is one of the widest in this whole check.
Try this: Look up the actual retention period for deleted items on your plan, then compare it to four months. The number is usually much smaller than expected.
What changing it involves: Independent cloud-to-cloud backup, priced per mailbox and typically a small monthly cost. One of the cheapest gaps here to close.
moderateRecovery
Unclear how far back Microsoft 365 data could be recovered
Worth resolving, because the answer is usually shorter than assumed and the fix is inexpensive once somebody actually asks the question.
Try this: Ask whoever manages your tenant what happens if a mailbox is deleted and the loss is noticed in four months. Any hesitation is the answer.
What changing it involves: Confirm the retention you have, then decide whether it covers a realistic discovery timeline.