IT Support
Five Microsoft 365 mistakes small businesses make
Microsoft 365 works out of the box, which is exactly the problem. Five defaults that quietly cost small businesses money or data.
Microsoft 365 is easy to start using and easy to get wrong, because the defaults are designed to make the first day frictionless rather than the third year safe.
None of these five are exotic. I find them in most small businesses I'm called into, and each one has a fix that takes under an hour.
1. Admin accounts without multi-factor authentication
The global administrator account is the one that can read anyone's mailbox, reset anyone's password, and export everything. It is also, routinely, the one protected by a password chosen in 2019 and reused on three other services.
Attackers don't guess passwords any more — they buy them from breach dumps and try them. Multi-factor authentication is what makes a stolen password worthless, and Microsoft's own published figure is that it blocks the overwhelming majority of account-compromise attempts.
Turn it on for administrators first, then everyone. In the Microsoft 365 admin centre it's under Users → Active users → Multi-factor authentication, or via Conditional Access if you're on a Business Premium plan.
Two related habits worth adopting at the same time:
- Don't use a global admin account for daily email. Create a separate admin account, use it only when you need it, and do your normal work as a standard user. A phishing link clicked in a normal mailbox is a much smaller event.
- Keep one break-glass admin account with a long random password stored somewhere physical, excluded from Conditional Access policies. It's what gets you back in when MFA itself breaks.
If your business email is on Microsoft 365 and MFA is off, stop reading and go turn it on. Every other item on this list is a slower-moving problem.
2. Paying for licences nobody uses
This one is pure money, and it accumulates silently.
When someone leaves, the usual instinct is to block their sign-in and move on. The licence keeps billing — every month, per seat — and nobody notices because the invoice total only ever creeps upward.
Check Billing → Your products and compare the licences purchased against licences assigned. Then check assigned licences against people who actually still work there.
| Situation | What to do instead of leaving the licence |
|---|---|
| Employee left, mailbox still needed | Convert to a shared mailbox — under 50GB it needs no licence |
| Employee left, mailbox not needed | Export what's required, then delete the account |
| Seasonal or part-time staff | Unassign the licence between engagements rather than deleting the user |
| Role replaced by a new hire | Reassign the existing licence rather than buying another |
Also look at whether everyone needs the plan they're on. A warehouse team that uses only email doesn't need the same licence as the finance team using the desktop Office apps.
Put a recurring calendar reminder to review licences every quarter. Fifteen minutes, four times a year, and it's the only item on this list that pays for itself directly.
3. Assuming Microsoft backs up your data
This is the most expensive misunderstanding in the list, and the most common.
Microsoft guarantees the service is available. It does not guarantee your data is recoverable after you delete it. What actually happens by default:
- A deleted email sits in Deleted Items, then in a recoverable folder, and is then gone — commonly around 30 days in total.
- A deleted file in SharePoint or OneDrive goes through two recycle bins and is gone, typically after 93 days.
- A deleted user account takes their OneDrive with it after the retention window, whether or not anyone looked at the contents.
- Ransomware that encrypts files synced by OneDrive syncs the encrypted versions up. Versioning helps, if you notice inside the window.
The gap is time. If someone deletes a folder in March and you discover it in July, the default retention has already expired.
Two things to put in place:
- Retention policies in the Microsoft Purview compliance centre, so items are held for a defined period regardless of what a user deletes.
- A third-party backup for Exchange, SharePoint, OneDrive and Teams, with a copy outside the tenant. This is what a real restore looks like, and it's a few dollars per user per month.
Then test a restore once. An untested backup is a hypothesis.
4. Shared logins instead of shared mailboxes
Almost every small business has an info@ or accounts@ address, and in
about half of them, three people know the password.
Why it's worth fixing:
- You lose accountability. When something is sent from that address, nobody can say who sent it.
- MFA becomes impractical. A shared account can't easily have a second factor, so it stays the weakest door in the building.
- Offboarding breaks. Someone leaves and the password has to change for everyone, so it doesn't get changed.
- You may be paying for it — a shared login is usually a full licensed user account.
The built-in answer is a shared mailbox. Each person signs in as themselves and the shared mailbox appears alongside their own. Permissions are granted and revoked per person, sending is auditable, MFA applies normally, and under 50GB it needs no licence at all.
Same principle for anything else with a shared password: use a group, a delegated permission, or a proper password manager with per-person access.
5. No offboarding process
Someone resigns. Their manager tells IT — or doesn't. Weeks later the account is still active, still licensed, and still receiving customer email nobody is reading.
Write down the steps once so it isn't improvised each time. Mine looks roughly like this:
- Block sign-in immediately on the last day. This is the security step and it takes ten seconds.
- Reset the password and revoke active sessions — blocking sign-in alone doesn't always kill a token that's already issued.
- Convert the mailbox to a shared mailbox and grant access to whoever is covering the role. Nothing is lost and the licence is freed.
- Set up mail forwarding or an auto-reply so customers writing to that address get a response.
- Move their OneDrive files to a colleague or a team site before the retention window on the deleted account expires.
- Remove the licence, then remove the account after an agreed grace period.
- Revoke access to everything else — the website admin, the CRM, the hosting panel, the shared password manager. This is the step most lists forget, and the one that matters most six months later.
Keep it as a checklist somewhere non-IT staff can find it, and make the last day of employment the trigger.
What to do first
Check MFA on your admin accounts today. It's the item where the gap between "fine" and "someone is reading your email" is a single reused password.
Then do the licence audit, because it takes fifteen minutes and usually pays for whatever you decide to fix next. Backup and offboarding are the ones that need a decision and a small budget, so plan those rather than rushing them.
If you'd rather have someone go through the tenant with you, Microsoft 365 setup and support is part of what I do — including the unglamorous parts like offboarding checklists that stop this list from rebuilding itself.
- #Microsoft 365
- #IT Support
- #Security
Related reading
Your SSL certificate broke: a 5-minute checklist
Browser shouting about your certificate? Work through these five checks in order — it's almost always one of them, and four take under a minute.
Your WordPress site got hacked: what to do first
Deleting the malware is the easy part — and the part that gets redone next week if you skip the rest. Here's the order that makes a cleanup stick.
A technical SEO audit you can run yourself
Before paying anyone for an SEO audit, run these six checks. They take an afternoon, need no paid tools, and usually find the real problem.
Need a hand with something like this?
I work with businesses in Dubai and remotely worldwide on websites, SEO, hosting and IT. Tell me what you're dealing with.
Get in touch