Rejuvenate IT Logo
  1. Home
  2. Guides
  3. Cyber Security

Explainer

What Microsoft 365 protects, and what it leaves to you

Microsoft protects the platform - the data centres, the service, the spam filtering. Everything about how your business uses it stays yours: who can sign in, what they do, your devices and your data.

By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read

The short version

  • Microsoft secures the platform; you secure the way your business uses it
  • Security defaults are switched on for new tenants, but older ones may have nothing
  • Microsoft says MFA blocks over 99.2% of identity-based attacks
  • Filtering catches most phishing, and the ones it misses are the convincing ones
  • Offboarding, quarantine and alerts are the jobs that usually have no owner

The line, and why it matters

Microsoft runs the data centres, keeps the service up, patches the platform and filters an enormous quantity of spam and malware before it reaches anybody. That part is genuinely well done, and you can largely stop thinking about it.

What Microsoft does not do is decide how careful your business is. Who has an account, whether they use a second factor, whether a leaver still has access, whether anybody reads the alerts – all of that sits with you, and it sits with you whether or not somebody has actually picked it up.

Almost every Microsoft 365 breach we see is on that second list. Not a failure of Microsoft’s product: a setting nobody turned on, or a job nobody owned.

Data centres and hardware

Microsoft looks after
Entirely theirs

You look after
Nothing to do

Running and patching the service

Microsoft looks after
Entirely theirs

You look after
Nothing to do

Spam and malware filtering

Microsoft looks after
Provided as standard

You look after
Tuning it, and checking quarantine

Who can sign in, and from where

Microsoft looks after
Tools provided

You look after
Configuring and enforcing the rules

Whether MFA is actually on

Microsoft looks after
Default for new tenants only

You look after
Checking it, and covering everyone

Your files and email

Microsoft looks after
Stored and replicated

You look after
Backing them up beyond the retention window

Staff spotting a convincing phish

Microsoft looks after
Filters stop most of them

You look after
Training, and somewhere to report it

Laptops and phones

Microsoft looks after
Only if you licence and set it up

You look after
Enrolling and managing the devices

Someone leaving the business

Microsoft looks after
Nothing happens automatically

You look after
Removing access, on the day

Which should you choose?

Microsoft's half is well run and mostly invisible. Everything in the right-hand column is yours whether or not anyone has picked it up - and in a lot of small businesses several of those rows have no owner at all. That gap, rather than any weakness in Microsoft's product, is where the incidents come from.

The protection you may already own and not have switched on

A good deal of what businesses go out and buy is already sitting in the tenant, switched off.

Microsoft turns on security defaults for every new tenant, which requires everyone to register for multi-factor authentication. Microsoft’s own research puts MFA as blocking more than 99.2% of identity-based attacks, and it reports that organisations running security defaults see around 80% less compromise than the overall population of tenants.

The catch is the word “new”. A tenant created years ago may never have had security defaults applied, and plenty have had them switched off during some past migration and never switched back. Nobody is emailed about this. It simply stays off.

If your licences include the more advanced tier, conditional access, device management and sensitive-document labelling are sitting there too. Owning them and using them are different things.

Worth checking in your tenant this week

  • Is multi-factor authentication enforced for every account, including the admins?
  • Are there any accounts belonging to people who have left?
  • Does anybody actually look in the quarantine, and how often?
  • Are there shared or generic mailboxes signed into by several people?
  • Who receives the security alerts, and did they read the last one?
  • Is anybody signing in from a personal machine nobody manages?

The three jobs that never have an owner

Offboarding. Accounts of former staff are a standing invitation, and they linger because removing them is nobody’s named job. It should be part of leaving, alongside the laptop and the keys.

Quarantine. Filtering is not free of error in either direction. Genuine mail gets held and something needs to release it, while some malicious mail arrives anyway. A quarantine nobody reviews is a filter running unsupervised.

Alerts. Microsoft will tell you about an impossible-travel sign-in or a suspicious forwarding rule. If those go to an address nobody monitors, the detection worked and the response never happened. Decide who reads them, and what they do next.

None of these needs a product. They need a name against them.

Common questions

Does Microsoft scan for viruses in email and files?

Yes, across all the business plans, and it catches a great deal. What it cannot reliably catch is a well-written message with no attachment and no dodgy link - a supplier asking you to update their bank details. That is a people-and-process problem rather than a filtering one.

If we pay for the more expensive licence, are we covered?

Not automatically. The dearer plans add real tools - device management, conditional access, better threat protection - but they arrive largely unconfigured. An unconfigured Premium tenant is not much safer than a Standard one.

Whose fault is it if our account gets compromised?

Commercially and practically, it is yours to deal with. Microsoft responsibility covers the platform; accounts, passwords and access rules sit on your side of the line, which is why the settings above matter so much.

Is Microsoft 365 less secure than keeping a server in the office?

Generally the opposite, and by some distance - the platform is patched and monitored at a scale almost no small business could match. The risk simply moves: instead of somebody getting into your building, they get into an account.

We are only five people. Is this over the top?

The list gets shorter, not different. Enforce MFA, remove leavers, and make sure alerts reach a real person. Those three cover most of what actually goes wrong, and none of them costs anything.

Written by Claire Donnelly

Do you know whether MFA is on for everyone?

Most businesses think it is, and in a good number it covers some people and not others. We'll look at your tenant and tell you plainly what is on, what is off, and what we would change first.

Ask for a tenant check