Northwind Traders
Northwind Traders' Microsoft 365 has a critical security gap that should be fixed now.
At a glance
We ran 54 security checks and 39 need attention (1 critical, 13 high, 13 medium and 12 low priority). The most urgent: 1 admin without MFA, and 1 whose registration isn't known.
On the positive side, 15 checks passed, including “Between 2 and 4 Global Administrators”, “Automatic forwarding to outside addresses is off” and “Shared mailboxes can't be signed in to”.
Since 13 September, Microsoft Secure Score rose from 40% to 47.5%, users with MFA rose from 58.7% to 62.2%, 1 issue was fixed and 7 new items came up.
About £123.30 a month (£1,479.60 a year) goes on licences that are unused or assigned to disabled or inactive accounts.
7 checks couldn't run because the data or a licence they need is missing.
Key figures
This month
7 found and 1 fixed since September 2026. Found counts new findings and ones that came back.
What we did
- Fixed Every active user has MFA registered · 1 item: megan.lee@northwindtraders.example
What we recommend next
-
Have each listed admin register a strong method
1 admin without MFA, and 1 whose registration isn't known. See the detail
-
Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group
1 admin not covered by MFA. See the detail
-
Remove admin roles from guest accounts
1 guest with admin roles. See the detail
The detail
Everything behind the summary: what changed, each finding with the accounts or settings it affects, and licences line by line. The XLSX export has every row.
What changed since 13 September
Findings
1 fixed and 7 new or returning. New ones are also marked New in the checks below.
- Fixed megan.lee@northwindtraders.example: No MFA method registered
- New grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
- New Campaign video.mp4 (Marketing / Documents): Anyone can edit
- New Year end/Draft accounts FY26.xlsx (Clients / Documents): Can be edited by partner@mason-legal.example
- New hannah.robinson@northwindtraders.example: 47.2 GB of 49.5 GB (95%), no archive
- New olivia.smith@northwindtraders.example: 45.6 GB of 49.5 GB (92%), no archive
- New DESK-EDWARDS33 (imogen.edwards@northwindtraders.example): Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.
- New LAPTOP-WATSON32 (aaron.watson@northwindtraders.example): Windows 11 24H2: updates for Home and Pro end 13 Oct 2026.
In Microsoft 365
- New Accounts: aaron.watson@northwindtraders.example: New member account
- New Accounts: imogen.edwards@northwindtraders.example: New member account
- New Licences: aaron.watson@northwindtraders.example: Given Microsoft 365 Business Premium
- New Licences: imogen.edwards@northwindtraders.example: Given Microsoft 365 Business Premium
- New Mail: grace.taylor@northwindtraders.example: Now forwards to grace.taylor@homemail.example
- New Devices: LAPTOP-WATSON32 (aaron.watson@northwindtraders.example): Enrolled Windows
- New Devices: DESK-EDWARDS33 (imogen.edwards@northwindtraders.example): Enrolled Windows
- Changed Admin activity: Payroll Sync: Update application – Certificates and secrets management by admin@northwindtraders.example on 2026-09-29: Added certificate
- Changed Admin activity: Block risky countries: Delete conditional access policy by admin@northwindtraders.example on 2026-10-05
- Changed Admin activity: Require MFA for all users: Update conditional access policy by admin@northwindtraders.example on 2026-10-06: On → Off
- Changed Admin activity: ann.patel@northwindtraders.example: Add eligible member to role in PIM completed (permanent) by admin@northwindtraders.example on 2026-10-08: Exchange Administrator
- Changed Admin activity: northwindtraders.example: Set domain authentication by mallory.price@northwindtraders.example on 2026-10-09
- Changed Admin activity: robert.hughes@northwindtraders.example: Add member to role by admin@northwindtraders.example on 2026-10-09: Global Administrator
- Changed Admin activity: Payroll Sync: Update application – Certificates and secrets management by admin@northwindtraders.example on 2026-10-10: Added certificate
- Changed Admin activity: Mail Sync Pro: Add service principal credentials by Contoso Automation on 2026-10-11: Credential added
Microsoft Secure Score
Microsoft's own measure of how many recommended security settings are turned on. Higher is better.
Fix first 14
1 admin without MFA, and 1 whose registration isn't known
AdminsWhat to do: Have each listed admin register a strong method (Authenticator or a FIDO2 key), or remove the role. Break-glass accounts should use FIDO2 keys kept offline.
| Account or item | Detail | Severity |
|---|---|---|
| breakglass@ | Global Administrator with no MFA method registered | critical |
| g#EXT#@ | Exchange Administrator: MFA registration unknown | low |
1 admin not covered by MFA
AdminsWhat to do: Make sure each admin is included in an enabled Conditional Access policy that requires MFA for all apps, and isn't excluded from it directly or through a group. Use a separate policy for break-glass accounts.
| Account or item | Detail | Severity |
|---|---|---|
| breakglass@ | Global Administrator: excluded from Require MFA for all users | high |
1 guest with admin roles
AdminsWhat to do: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA.
| Account or item | Detail | Severity |
|---|---|---|
| g#EXT#@ | Guest holding Exchange Administrator | high |
1 app with access to mail, files or the directory
AppsWhat to do: Review each app with the client. Remove apps nobody recognises (Enterprise applications > Delete), and for the rest confirm the vendor and that it still needs mailbox or file access.
| Account or item | Detail | Severity |
|---|---|---|
| Mail Sync Pro | Mail.Read (application permission; unverified publisher) | high |
4 of 36 computers not encrypted
DevicesWhat to do: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data.
| Account or item | Detail | Severity |
|---|---|---|
| DESK-WRIGHT18 (leo. | Windows disk isn't encrypted | high |
| LAPTOP-HUGHES (robert. | Windows disk isn't encrypted | high |
| LAPTOP-SCOTT29 (olivia. | Windows disk isn't encrypted | high |
| LAPTOP-SMITH07 (olivia. | Windows disk isn't encrypted | high |
5 of 36 Windows computers past end of support
DevicesWhat to do: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap.
| Account or item | Detail | Severity |
|---|---|---|
| LAPTOP-HUGHES (robert. | Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade. | high |
| LAPTOP-MARTIN22 (maya. | Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade. | high |
| LAPTOP-PATEL13 (hannah. | Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade. | high |
| LAPTOP- | Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade. | high |
| LAPTOP-TAYLOR04 (grace. | Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade. | high |
| DESK-BAKER27 (ella. | Windows 11 24H2: updates for Home and Pro end 13 Oct 2026. | low |
| DESK-CLARKE00 (thomas. | Windows 11 24H2: updates for Home and Pro end 13 Oct 2026. | low |
| DESK-EDWARDS33 (imogen. | Windows 11 24H2: updates for Home and Pro end 13 Oct 2026. | low |
| DESK-HILL15 (ruby. | Windows 11 24H2: updates for Home and Pro end 13 Oct 2026. | low |
| DESK-LEE03 (megan. | Windows 11 24H2: updates for Home and Pro end 13 Oct 2026. | low |
| …and 15 more in the XLSX export. | ||
1 suspicious inbox rule
EmailWhat to do: Check each rule with the mailbox owner. Rules that delete or bury messages about payments or security alerts are a sign of a compromised account: reset the password, revoke sessions and review sign-ins.
| Account or item | Detail | Severity |
|---|---|---|
| ann. | ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank | high |
4 external forwards
EmailWhat to do: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset.
| Account or item | Detail | Severity |
|---|---|---|
| ann. | Mailbox forwarding to ann.patel@homemail.example (keeps a copy) | high |
| ann. | Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example | high |
| grace. | Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy) | high |
| olivia. | Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example | high |
14 users without MFA
IdentityWhat to do: Ask these users to register the Microsoft Authenticator app. Until they do, anyone with their password can register MFA in their place.
| Account or item | Detail | Severity |
|---|---|---|
| breakglass@ | No MFA method registered | high |
| alfie. | No MFA method registered | medium |
| alfie. | No MFA method registered | medium |
| carl. | No MFA method registered | medium |
| grace. | No MFA method registered | medium |
| hannah. | No MFA method registered | medium |
| leo. | No MFA method registered | medium |
| leo. | No MFA method registered | medium |
| maya. | No MFA method registered | medium |
| olivia. | No MFA method registered | medium |
| …and 4 more in the XLSX export. | ||
Legacy authentication is allowed
IdentityWhat to do: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target.
| Account or item | Detail | Severity |
|---|---|---|
| Whole organisation | No enabled policy blocks legacy authentication for all users | high |
1 domain had sign-in settings changed in the last 30 days
IdentityWhat to do: Confirm with the client that each change was planned (for example, setting up AD FS or another identity provider). If it wasn't, an attacker with admin rights may have federated the domain to their own identity provider so they can sign in as any user without a password or MFA: switch the domain back to managed sign-in, remove unknown federation settings, reset admin credentials and review the audit log.
| Account or item | Detail | Severity |
|---|---|---|
| northwindtraders. | Set domain authentication by mallory.price@northwindtraders.example on 9 Oct 2026 | high |
1 site with no owner, 2 sites with one owner
SharingWhat to do: Give each site a second owner (in the Microsoft 365 group, or as a site administrator) so access requests and content questions have someone to go to when one person leaves. The Site access report lists each site's owners.
| Account or item | Detail | Severity |
|---|---|---|
| Marketing | No enabled owner (Microsoft 365 group) | high |
| Operations | One owner (Microsoft 365 group) | low |
| Staff Intranet | One owner (site administrators) | low |
1 guest with full control of 1 site
SharingWhat to do: Take guests out of each site's owners group and away from Full Control; give them Edit or Read through the site's members or visitors group instead. Full Control lets someone outside the organisation change who can open the site and delete anything on it. The Site permissions report lists them.
| Account or item | Detail | Severity |
|---|---|---|
| accounts@ | Full Control, given Full Control directly | high |
3 files and folders shared with anyone
SharingWhat to do: Remove anyone links that are no longer needed, and set the rest to view-only with an expiry date. The Shared files report lists each one.
| Account or item | Detail | Severity |
|---|---|---|
| Campaign video.mp4 (Marketing / Documents)New | Anyone can edit | high |
| Brand assets (Marketing / Documents) | Anyone can view, link never expires | medium |
| holiday.jpg (OneDrive of ann. | Anyone can view | medium |
Also worth fixing 25
Lower-risk items. Each one lists the accounts or settings affected; the XLSX export has the full detail.
4 accounts inactive for 90+ days or never used
AccountsAffects hannah.
Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers.
2 admins without a phishing-resistant method
AdminsAffects ann.
Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't.
1 app with privileged roles
AdminsAffects Some app.
Check each app that holds a privileged directory role still needs it. A compromised app secret with an admin role bypasses MFA entirely.
Users can consent to any app
AppsApplies to the whole organisation.
Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting.
6 of 37 managed devices not compliant
DevicesAffects DESK-ROBINSON12 (george.
Open each non-compliant device in Intune (Devices > Monitor > Noncompliant devices) to see which setting fails, fix it or retire the device, and block non-compliant devices with a Conditional Access policy that requires a compliant device.
1 mail domain without DKIM
EmailAffects northwindtraders.
Turn on DKIM for each domain in the Defender portal (Email authentication settings > DKIM), publishing the two selector CNAME records it shows. This applies to domains behind a mail gateway too when Microsoft 365 still sends for them (their SPF includes spf.protection.outlook.com); a gateway signs only the mail that goes out through it.
2 domains without DMARC enforcement
EmailAffects northwindtraders.
Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. Without enforcement, spoofed mail from the domain is delivered.
4 teams and groups without an owner
GroupsAffects Project Phoenix, Marketing, Marketing, Provisioned.
Make an active person, ideally two, an owner of each listed team or group (Teams admin center or Microsoft 365 admin center > Teams & groups). Owners approve members and guests and renew the group; without one, nobody looks after its files and conversations. The ownerless group policy (Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups) asks members to take over when the last owner leaves.
Enforced by Require MFA for all users, with 1 exclusion to review
IdentityAffects breakglass@
Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts.
1 disabled account still licensed
LicencesAffects robert.
Remove licences from disabled accounts, or convert leavers' mailboxes to shared mailboxes (free up to 50 GB) before removing the licence.
1 file or folder outside people can edit
SharingAffects Year end/Draft accounts FY26.xlsx (Clients / Documents)New.
Change sharing with people outside the organisation to view-only unless they need to edit, and remove sharing that's no longer needed. The File and folder permissions report lists each person outside and what they can edit.
3 mailboxes at or over 90% of quota
StorageAffects accounts@
Turn on the online archive for each listed mailbox (Exchange admin center > Mailboxes > Manage mailbox archive) with a retention policy that moves old mail into it, or clear large old items. A mailbox at its quota can't send, and soon after can't receive.
1 account reports to a blocked manager
AccountsAffects ann.
Set a current manager on each listed account (Entra admin center > Users > Properties > Manager, or in on-premises AD for synced accounts). The manager is where approvals, leaver notices and access reviews go; when they've left, those go nowhere, and their blocked account is usually waiting to be deleted too.
1 app registration with expiring or expired credentials
AppsAffects Old connector.
Renew credentials before they expire to avoid an outage, and delete app registrations whose credentials have all expired if nothing uses them any more.
1 of 37 joined computers not in Intune
DevicesAffects DESK-RECEPTION.
Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them.
3 devices haven't checked in for 30+ days
DevicesAffects DESK-ROBINSON12 (george.
Find out whether each device is lost, replaced or broken. Retire devices that are gone; for devices still in use, restart the Intune Management Extension or re-enrol.
1 of 39 device records unused for 90+ days
DevicesAffects OLD-PC.
Disable, then after 30 days delete, device records that haven't signed in for 90 days (Entra admin center > Devices > All devices, filter by activity). Old records can still hold BitLocker keys and count toward device limits.
1 domain with SPF problems
EmailAffects parked.example.
Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all".
1 of 1 mail domain doesn't fully enforce MTA-STS
EmailAffects northwindtraders.
Publish an MTA-STS policy so other mail servers only deliver to the domain over a verified, encrypted connection: a TXT record at _mta-sts.<domain> ("v=STSv1; id=20260101") and a policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt listing the domain's MX hosts (for Microsoft 365, "mx: *.mail.protection.outlook.com"). Start with "mode: testing" and TLS-RPT reports, then switch to "mode: enforce" and change the id.
SMTP AUTH is on for the organisation
EmailApplies to the whole organisation.
Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it, such as scanners. It accepts passwords without MFA.
Anyone, including guests, can invite guests
GuestsApplies to the whole organisation.
Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings.
3 people can only use a text or call as a second factor
IdentityAffects arthur.
Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM.
2 subscriptions with spare licences
LicencesAffects Microsoft 365 Business Basic, Microsoft 365 Business Premium.
Reduce the subscription quantity at the next renewal, or assign the spare licences.
Any user can register an app
Tenant settingsApplies to the whole organisation.
Set "Users can register applications" to No (Entra admin center > Users > User settings) and give the Application Developer role to the people who need it.
Licences
| Licence | Purchased | Assigned | Unassigned | Disabled users | Inactive users | Waste / month |
|---|---|---|---|---|---|---|
| Microsoft 365 Business Premium | 32 | 29 | 3 | 1 | 2 | £108.60 |
| Microsoft 365 Business Basic | 9 | 7 | 2 | 0 | 1 | £14.70 |
| Total | 41 | 36 | 5 | 1 | 3 | £123.30 |
In good shape 15
- Between 2 and 4 Global Administrators
- Automatic forwarding to outside addresses is off
- Shared mailboxes can't be signed in to
- Mailbox auditing is on
- Guests have limited directory access
- Users have a way to get apps approved
- No old, unaccepted guest invitations
- No guest owns a team or group
- Only chosen people can create teams and groups
- Unused groups and teams expire
- Admin accounts are cloud-only
- SharePoint storage isn't nearly full
- Every licence assignment works
- No subscriptions are about to lapse
- No OneDrive is nearly full
Not checked 7
These checks need data or a Microsoft licence that isn't available, so they're neither a pass nor a fail.
- Users can't create new tenants. Microsoft didn't return this setting
- People can't join the tenant just by verifying an email address. Microsoft didn't return this setting
- Encrypted delivery failures are reported (TLS-RPT). TLS-RPT is checked on mail domains that use MTA-STS, and none do yet
- Directory sync is running. Cloud-only tenant: directory sync isn't turned on
- Password hash sync is on. Cloud-only tenant: directory sync isn't turned on
- No risky sign-ins succeeded. Sign-in risk needs Entra ID P2
- No accounts are at risk in Entra ID Protection. Risky users need Entra ID P2