The beauty of Microsoft 365 is that it doesn’t require you to choose between security and collaboration. You can be collaborative and careful.
You know that feeling when you realize you think you may have left your office door unlocked? Yeah, that’s what we’re avoiding today.
Cloud collaboration tools like Microsoft 365 are genuinely fantastic, as they’ve made remote work possible, enabled seamless teamwork across continents, and freed us from the tyranny of forwarding documents as email attachments. But here’s the thing nobody wants to admit: they’ve also made it embarrassingly easy to accidentally share your financial data with the entire internet.
The good news? Most risks are incredibly simple to fix – let’s walk through four settings worth reviewing this week in Microsoft 365. Not looking to add more to your plate – Microsoft 365 Tenant Drift management is one of the reasons many businesses come to work with Adna.

1. External Sharing Permissions (The “Oops, Did I Share This With EVERYONE?” Check)
Here’s a scenario: You create a document, share it with your team, then accidentally select “Anyone with the link” instead of “People I choose.” Suddenly, your Q3 budget spreadsheet is visible to absolutely anyone who stumbles on that link. Bonus fun: they could edit it too.
Check your SharePoint and OneDrive sharing settings. Go to the admin center, find “SharePoint,” and review your external sharing settings. You want to decide: should documents be shareable with anyone outside your organization, or just with specific approved people? Most small businesses should limit external sharing to “existing guests” or require approval before sharing externally.
The key question: Do your team members actually need to share files with people outside your company? If the answer is “rarely,” tighten those settings. If they do, consider requiring a review step before external sharing happens.
2. Inactive or Forgotten User Accounts (The “Who Even Is This Person?” Audit)
Here’s the scenario: Someone left your company six months ago. Their account still exists. They still have access to your shared drive, your customer database, and that sensitive file from the acquisition you’re planning. Nobody disabled their account because, well, someone was supposed to do it, and then it just… didn’t happen.
This is surprisingly common, and it’s a real vulnerability.
Go to the admin center and review your active users. Look for accounts that haven’t been used in 30+ days. Check the “Last activity” column. Deactivate or remove any accounts for people who’ve left. Also review any guest accounts—if you invited contractors or partners months ago, check that you still need them.
Here’s the uncomfortable truth: This isn’t just a security risk, it’s also a compliance issue. Depending on your industry and data, you might have legal obligations to revoke access when someone leaves. Do yourself a favor and create a simple offboarding checklist for future departures. (Email accounts, file access, app licenses… you know the drill.)
3. Connected Apps and Integrations (The “What Is This Even Doing?” Deep Dive)
You’ve probably authorized dozens of apps at this point. That one app to create social media graphics? The scheduling tool? The email tracking software? They all seemed useful when you signed up.
The problem: You might have given them permissions you don’t fully understand. Some apps request access to your entire Microsoft 365 account—not because they need it, but because it’s easier to ask for broad permissions than specific ones.
Check your app permissions by going to Settings > Privacy & Security > Admin consent requests. Review what apps have access to your organization’s data. Delete any integrations you’ve stopped using.
Quick rule of thumb: If you haven’t used an app in three months, disconnect it. If an app is requesting permissions that seem way too broad (“We need access to your entire email archive”?), that’s a red flag.
4. Sharing with External Domains or Groups (The “Accidentally Gave The Whole Company Access” Prevention)
This one’s subtle but important. You might have created a sharing rule that looks totally reasonable: “Share this folder with everyone at [other-company].com.” Seems fine, right? Except now anyone with an email at that domain has access, including new hires you’ve never met and employees in departments you don’t work with.
Similarly, if you’ve set up sharing with a broad internal group (like “Everyone”), you might not realize how many people that actually includes. Contractors? Consultants? People in the wrong department? They might be in that group.
Review your SharePoint and Teams permissions. Check which groups have access to your sensitive folders. Remove access for groups that are broader than they need to be.
The fix here is usually about being more intentional. Instead of “share with a group,” try “share with these three people.” It takes an extra 30 seconds, but it prevents a lot of headaches.
The Real Benefit of 30 Minutes of Checking
Here’s the good news most small business owners discover when they actually do this audit: Nothing catastrophic is usually happening. You’re probably not in immediate danger.
But you almost certainly find a few things worth tightening up. An old account you forgot about. An app integration you no longer use. A folder that’s shared more broadly than it should be. Little gaps that, individually, aren’t huge deals—but collectively, they’re exactly the kind of thing that turns into a real problem down the road.
The beauty of Microsoft 365 is that it doesn’t require you to choose between security and collaboration. You can be collaborative and careful. You just need to occasionally open the door, look around, and make sure you’re comfortable with what you see.
A Quick Note About Tenant Drift
If you’re an Adna customer, you might be thinking: “Wait, don’t you all handle this stuff for us?” And honestly? You’re not wrong. Many of our clients don’t need to worry about this particular audit because we manage Microsoft 365 tenant drift as part of our service.
What’s tenant drift? Think of it as the slow creep of security gaps that happens naturally over time—forgotten accounts, permissions that expand without anyone noticing, Microsoft introducing new feature and options after your initial setup, app integrations that pile up. Our tenant drift management program continuously monitors your Microsoft 365 environment, identifies these gaps before they become problems, and helps to close them. It’s like having a security audit running in the background, all the time.
So if you’re with us, take a breath. We’ve got your back. If you’re not yet, well—here’s your 30-minute starter guide.
So here’s my suggestion for those of you not yet with Adna: Block out 30 minutes this week. Grab a coffee. Put on your favorite podcast. Walk through these four settings. Disable a few accounts. Disconnect some unused apps. Tighten a few sharing permissions.
Your future self—the one who doesn’t get the 2 AM call about suspicious file access—will thank you.
What security settings have you found yourself neglecting? Drop your thoughts in the comments. And if you discover something absolutely bonkers during your audit, well… that’s what we’re here for.
Posted by Nathan R on September 11, 2026