IT Teams Fall Short in Microsoft 365 Security Protections


IT Teams Fall Short in Microsoft 365 Security Protections

By Greg Tavarez

Remote and hybrid work environments prompted many enterprises to leverage solutions like Microsoft 365, perhaps sooner than they otherwise may have made the transition to the cloud. Across the board, digital transformation was accelerated as businesses moved to quickly adapt to new, though now familiar, work environments. The complexity of M365, with its 25 different apps and more than a dozen admin panels, paired with the skyrocketing usage made it difficult for IT teams to keep up with security monitoring and compliance.

CoreView, looking to understand what companies are doing well with M365, found that not all is as good as companies might want to think. An overwhelming majority ( 90%) of organizations have gaps in essential security protections falling into four areas: MFA, email security, password policies and failed logins.

The cause of the gaps? Common security procedures are not always followed. Even though most enterprises have strong documented security policies, CoreView’s research uncovered that most aren’t being implemented consistently due to difficulties in reporting and limited IT resources.

For example, 87% of companies have MFA disabled for some or all their admins. These are critical accounts that need protection. The research also found that most companies, a little more than 80% in fact, don’t have strong password requirements. Strong passwords, of course, are cornerstone of good security practices

The danger, of course, is these shortcomings leave the door open for cybersecurity threats.

“The role of the IT professional is more important and complex than ever. They need to stay in perfect compliance 100% of the time,” said Shawn Lankton, CEO of CoreView.

Additionally, companies face other challenges that make security and license management difficult, ultimately leading to unnecessary risks and costs. Around 22% of companies have unassigned M365 licenses – 17% have more than 10,000 licenses unassigned or inactive. These cases represent big opportunities to optimize license spend with better tools.

Inactive licenses pose a potential security risk that many IT teams may not think about. Users who left the organization might have access or may have poor password security and be easily hacked. They may also be a reflection of overpurchased licenses, where users don’t need the capabilities that were purchased.

This adds to the overall complexity for IT teams that struggle to keep up with best practices without a cohesive strategy for enforcing internal and external policies and continually ensuring compliance with these policies.

“To overcome this challenge, IT professionals require solutions that help automate compliance and delegate responsibilities to ensure security and efficiency across the business,” said Lankton.

Automating and delegating critical security, license optimization and other management tasks enable IT professionals to focus on important tasks instead of repetitive manual work.

Edited by Erik Linask

MSPToday Editor

Related Articles

GFI Software Named a Platinum Sponsor for MSP Expo 2023, Part of the #TECHSUPERSHOW

By: TMCnet News    1/31/2023

MSP Expo is the premier conference and networking summit for MSPs. This is where MSP business owners and technology specialists share strategies to gr…

Read More

Pioneering Technologist Klaus Dimmler Named Pax8 Chief Science Officer

By: Arti Loftus    1/30/2023

Pax8 announced a newly created position, Chief Science Officer (CSO) - as part of the company's mission to bring transformational cloud solutions to t…

Read More

Advanced MSPs Are Helping Law Firms Embrace Cloud

By: Reece Loftus    1/30/2023

This is the perfect time for law firms to embrace digital transformation and to take full advantage of automation for operational optimization.

Read More

Iron Bow Ramparts Cybersecurity Portfolio with GuardSight

By: Greg Tavarez    1/30/2023

Iron Bow is set to deliver holistic zero trust cybersecurity solutions with its acquisition of GuardSight.

Read More

Grain Expands Activity in Managed Services Sector with Spectrotel Acquisition

By: Greg Tavarez    1/27/2023

Grain acquired Spectrotel, a next-generation aggregator and integrated technology services provider.

Read More