Explainer
What Microsoft 365 protects, and what it leaves to you
Microsoft protects the platform - the data centres, the service, the spam filtering. Everything about how your business uses it stays yours: who can sign in, what they do, your devices and your data.
By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read
The short version
- Microsoft secures the platform; you secure the way your business uses it
- Security defaults are switched on for new tenants, but older ones may have nothing
- Microsoft says MFA blocks over 99.2% of identity-based attacks
- Filtering catches most phishing, and the ones it misses are the convincing ones
- Offboarding, quarantine and alerts are the jobs that usually have no owner
The line, and why it matters
Microsoft runs the data centres, keeps the service up, patches the platform and filters an enormous quantity of spam and malware before it reaches anybody. That part is genuinely well done, and you can largely stop thinking about it.
What Microsoft does not do is decide how careful your business is. Who has an account, whether they use a second factor, whether a leaver still has access, whether anybody reads the alerts – all of that sits with you, and it sits with you whether or not somebody has actually picked it up.
Almost every Microsoft 365 breach we see is on that second list. Not a failure of Microsoft’s product: a setting nobody turned on, or a job nobody owned.
Data centres and hardware
Microsoft looks after
Entirely theirs
You look after
Nothing to do
Running and patching the service
Microsoft looks after
Entirely theirs
You look after
Nothing to do
Spam and malware filtering
Microsoft looks after
Provided as standard
You look after
Tuning it, and checking quarantine
Who can sign in, and from where
Microsoft looks after
Tools provided
You look after
Configuring and enforcing the rules
Whether MFA is actually on
Microsoft looks after
Default for new tenants only
You look after
Checking it, and covering everyone
Your files and email
Microsoft looks after
Stored and replicated
You look after
Backing them up beyond the retention window
Staff spotting a convincing phish
Microsoft looks after
Filters stop most of them
You look after
Training, and somewhere to report it
Laptops and phones
Microsoft looks after
Only if you licence and set it up
You look after
Enrolling and managing the devices
Someone leaving the business
Microsoft looks after
Nothing happens automatically
You look after
Removing access, on the day
| Microsoft looks after | You look after | |
|---|---|---|
| Data centres and hardware | Entirely theirs | Nothing to do |
| Running and patching the service | Entirely theirs | Nothing to do |
| Spam and malware filtering | Provided as standard | Tuning it, and checking quarantine |
| Who can sign in, and from where | Tools provided | Configuring and enforcing the rules |
| Whether MFA is actually on | Default for new tenants only | Checking it, and covering everyone |
| Your files and email | Stored and replicated | Backing them up beyond the retention window |
| Staff spotting a convincing phish | Filters stop most of them | Training, and somewhere to report it |
| Laptops and phones | Only if you licence and set it up | Enrolling and managing the devices |
| Someone leaving the business | Nothing happens automatically | Removing access, on the day |
Which should you choose?
Microsoft's half is well run and mostly invisible. Everything in the right-hand column is yours whether or not anyone has picked it up - and in a lot of small businesses several of those rows have no owner at all. That gap, rather than any weakness in Microsoft's product, is where the incidents come from.
The protection you may already own and not have switched on
A good deal of what businesses go out and buy is already sitting in the tenant, switched off.
Microsoft turns on security defaults for every new tenant, which requires everyone to register for multi-factor authentication. Microsoft’s own research puts MFA as blocking more than 99.2% of identity-based attacks, and it reports that organisations running security defaults see around 80% less compromise than the overall population of tenants.
The catch is the word “new”. A tenant created years ago may never have had security defaults applied, and plenty have had them switched off during some past migration and never switched back. Nobody is emailed about this. It simply stays off.
If your licences include the more advanced tier, conditional access, device management and sensitive-document labelling are sitting there too. Owning them and using them are different things.
Worth checking in your tenant this week
- Is multi-factor authentication enforced for every account, including the admins?
- Are there any accounts belonging to people who have left?
- Does anybody actually look in the quarantine, and how often?
- Are there shared or generic mailboxes signed into by several people?
- Who receives the security alerts, and did they read the last one?
- Is anybody signing in from a personal machine nobody manages?
The three jobs that never have an owner
Offboarding. Accounts of former staff are a standing invitation, and they linger because removing them is nobody’s named job. It should be part of leaving, alongside the laptop and the keys.
Quarantine. Filtering is not free of error in either direction. Genuine mail gets held and something needs to release it, while some malicious mail arrives anyway. A quarantine nobody reviews is a filter running unsupervised.
Alerts. Microsoft will tell you about an impossible-travel sign-in or a suspicious forwarding rule. If those go to an address nobody monitors, the detection worked and the response never happened. Decide who reads them, and what they do next.
None of these needs a product. They need a name against them.
Common questions
Does Microsoft scan for viruses in email and files?
Yes, across all the business plans, and it catches a great deal. What it cannot reliably catch is a well-written message with no attachment and no dodgy link - a supplier asking you to update their bank details. That is a people-and-process problem rather than a filtering one.
If we pay for the more expensive licence, are we covered?
Not automatically. The dearer plans add real tools - device management, conditional access, better threat protection - but they arrive largely unconfigured. An unconfigured Premium tenant is not much safer than a Standard one.
Whose fault is it if our account gets compromised?
Commercially and practically, it is yours to deal with. Microsoft responsibility covers the platform; accounts, passwords and access rules sit on your side of the line, which is why the settings above matter so much.
Is Microsoft 365 less secure than keeping a server in the office?
Generally the opposite, and by some distance - the platform is patched and monitored at a scale almost no small business could match. The risk simply moves: instead of somebody getting into your building, they get into an account.
We are only five people. Is this over the top?
The list gets shorter, not different. Enforce MFA, remove leavers, and make sure alerts reach a real person. Those three cover most of what actually goes wrong, and none of them costs anything.
Written by Claire Donnelly
Do you know whether MFA is on for everyone?
Most businesses think it is, and in a good number it covers some people and not others. We'll look at your tenant and tell you plainly what is on, what is off, and what we would change first.
Ask for a tenant check