Gaps appear when teams assume the provider is responsible for data protection end to end. In practice, the provider secures the service infrastructure, while the customer must govern the data, users, and permissions inside it. Misunderstanding that boundary leads to overexposed files, weak access reviews, and blind spots in sensitive content discovery.
Why This Matters for Security Teams
Microsoft 365 reduces infrastructure burden, but it does not remove customer responsibility for identity, sharing, retention, classification, and permission hygiene. That boundary is where gaps appear. Security teams often inherit a tenant with broad sharing links, stale group membership, unmanaged guests, and no systematic review of sensitive content. The risk is not that Microsoft 365 is insecure by default, but that cloud convenience can hide governance drift until data exposure is already underway.
This is why shared-responsibility misunderstandings persist even in mature environments. The CSA Cloud Controls Matrix makes the control boundary explicit, yet many organisations still treat SaaS as if provider controls cover data access decisions. NHIMG research on the Microsoft Midnight Blizzard breach and the Ultimate Guide to NHIs both point to the same pattern: credentials, permissions, and delegated access remain the customer’s problem, even when the platform is managed. In practice, many security teams discover the gap only after a sensitive file is overshared or an admin path has already been abused.
How It Works in Practice
Closing the gap in Microsoft 365 starts with treating identity as the primary control plane. Security teams need to know who can access what, through which mechanism, and for how long. That means reviewing Entra ID roles, guest access, SharePoint and OneDrive sharing settings, Teams permissions, service principals, and OAuth-consented applications. The most important shift is to move from one-time configuration to continuous review, because access in Microsoft 365 changes through group nesting, app consent, external collaboration, and inherited permissions.
For sensitive data, classification and discovery need to be tied to action. If labels exist but are not enforced in sharing, download, or forwarding flows, they become documentation rather than control. Customer-managed settings should also be paired with logging and alerting so that file access, mailbox delegation, and anomalous consent events can be investigated quickly. NHIMG’s reporting on the State of Non-Human Identity Security shows how often organisations lack confidence in identity governance, and that same weakness shows up inside SaaS when permissions are not continuously scoped. The lesson is reinforced by incidents such as the CoPhish OAuth Token Theft via Copilot Studio, where delegated access and consent become the attack path.
- Restrict external sharing by default, then allow exceptions by business need.
- Review privileged roles, guest accounts, and app consents on a scheduled basis.
- Use sensitivity labels, DLP, and access reviews together, not as isolated controls.
- Monitor for dormant accounts, stale links, and anomalous mailbox or file delegation.
These controls tend to break down when organisations rely on tenant-wide defaults and never operationalise permission review across fast-changing collaboration spaces.
Common Variations and Edge Cases
Tighter Microsoft 365 controls often increase administrative overhead, so teams have to balance collaboration speed against exposure reduction. That tradeoff is especially sharp in mergers, regulated business units, and global organisations that depend on external sharing.
There is no universal standard for this yet, but current guidance suggests treating high-risk areas differently from general productivity use. Finance, legal, HR, and security data usually need stronger sharing constraints, more aggressive retention rules, and more frequent access reviews than ordinary team sites. The same applies to automation and third-party integrations. A single mis-scoped app registration or service account can reintroduce broad access even when interactive user permissions are well managed.
One common edge case is “shadow collaboration,” where users duplicate sensitive content into unmanaged spaces to avoid friction. Another is inherited access through old Microsoft 365 groups that no longer match the business structure. The practical response is to combine governance, monitoring, and user education rather than expecting any one control to close the gap. The Azure Key Vault privilege escalation exposure is a useful reminder that permission design failures often matter more than platform weakness. Where collaboration is highly decentralised and app consent is uncontrolled, these gaps persist because the tenant changes faster than the review process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Covers weak lifecycle control for identities and secrets in SaaS. |
| OWASP Agentic AI Top 10 | A-04 | Helpful where M365 automation or copilots expand access paths. |
| CSA MAESTRO | GOV-02 | Supports governance for SaaS data access, sharing, and oversight. |
| NIST CSF 2.0 | PR.AC-4 | Directly maps to access control for users, groups, and applications. |
| NIST AI RMF | Useful when AI features and automated workflows alter SaaS access decisions. |
Review Microsoft 365 identities, app consents, and secrets on a fixed rotation and removal schedule.
Related resources from NHI Mgmt Group
- Why do organisations still need dedicated email security controls when they already rely on Microsoft 365?
- Why do AI agents create gaps in existing cloud security controls?
- Why does email still create so much data leakage risk in organisations with mature security controls?
- Why do mobile apps create compliance gaps even when broader security controls look mature?