Microsoft 365 Security Posture Mired in Assumed Maturity
A recent report by CoreView sheds light on the state of Microsoft 365 security in modern enterprises. The survey of over 300 IT and security decision-makers reveals a worrying disconnect between confidence in security posture and actual operational control.
The majority of surveyed organisations, 62%, rate their security maturity as established or advanced, yet many lack critical foundational controls. For instance, nearly half of this confident group fail to enforce multifactor authentication (MFA) on admin accounts, a crucial security measure that only protects standard user accounts in 62% of organisations.
The report highlights several areas where enterprises struggle with security: AI triggers data anxiety as 66% of organisations have delayed or cancelled Microsoft Copilot deployments due to fears of sensitive information exposure. Configuration backups are also a blind spot, with only 17% of enterprises actively backing up their tenant configurations themselves.