Mistake 1: living in the admin account
In nearly every small-business Microsoft 365 setup I review, someone does daily work, meaning email, browsing, and documents, signed into the global administrator account, usually because it was the first account created and switching felt like a hassle.
The global admin can read any mailbox, delete any file, and change any setting. When that account opens a phishing email, the attacker inherits all of that power in one click.
The fix costs one license or none: create a separate admin account used only for administration, strip admin rights from every daily-driver account, and keep at least two admin accounts in total so a lockout is not fatal. Thirty minutes, once.
Mistake 2: MFA off, optional, or only for some people
Multi-factor authentication, the code or phone prompt on top of the password, is the single control that blocks the overwhelming majority of account break-ins, and I still find tenants where it is off entirely, or enabled for the owner but not for the bookkeeper who pays the invoices.
Microsoft 365 includes Security Defaults, a free one-switch setting that requires MFA across the whole tenant. Newer tenants often have it on already. Older ones, and tenants where a past consultant switched it off to silence complaints, frequently do not.
Use the Microsoft Authenticator app rather than text-message codes where you can, and make it universal. Attackers do not target the accounts with MFA. They find the one without it.
Mistake 3: sharing set to anyone with the link
OneDrive and SharePoint default to convenience: files shared with anyone who holds the link, links that never expire. Convenient, and also how a spreadsheet of customer information ends up reachable through a forwarded link two years later, with no way to know who has opened it.
Corrections that keep sharing usable:
- Set the default sharing option to specific people, not anyone with the link.
- Put expiration dates on external links.
- Restrict or disable anonymous sharing for sensitive libraries such as pricing, HR, and client files.
- Twice a year, run the sharing report to see what is exposed externally. The first run is usually an eye-opener.
Staff can still share externally on purpose. It just stops happening by accident.
Mistake 4: assuming Microsoft backs up your data
Microsoft keeps the service running. It does not promise to recover your data from every mistake. Deleted items and version history help within their windows, typically 30 to 93 days depending on the item, but a departed employee's purged mailbox, a ransomware-encrypted OneDrive synced across devices, or a deletion discovered four months later can all fall outside them.
Microsoft's own service agreement recommends third-party backup. Dedicated Microsoft 365 backup services run roughly $3 to $7 per user per month and keep independent copies of mail, OneDrive, SharePoint, and Teams with long retention.
For a ten-person company, that is around $500 a year as protection against losing correspondence and files that cannot be recreated. It is the cheapest insurance in this article.
Mistake 5: paying for licenses nobody uses
License waste hides in two places.
First, ghost licenses: people who left months ago, still licensed at $12 to $26 a month each because offboarding never included the billing step. I routinely find two to five of these in small tenants, which is often more than $1,000 a year in pure waste.
Second, mismatched plans: everyone on a premium tier when half the team only needs email and web apps, or the opposite failure, everyone on the cheapest plan while the business separately pays for security tools that Business Premium already includes. Premium runs roughly $22 to $26 per user monthly and bundles device management and advanced phishing protection, so for many offices it replaces two or three separate subscriptions.
The admin center shows exactly who holds which license. Ten minutes with that page usually funds the backup from mistake four.
The quick corrections, in order
- Turn on Security Defaults, or confirm MFA is genuinely universal, today.
- Create a dedicated admin account and remove admin rights from daily accounts.
- Change default sharing to specific people and put expiry dates on external links.
- Add a third-party backup for mail and files.
- Audit licenses against the actual staff roster and right-size the plans.
Each step is under an hour. If you would rather have it done for you and explained in plain English, this exact five-point cleanup is one of the most common first projects HashWhales does for small businesses around the DMV, and it is usually paid for by the license audit alone.
