Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do organisations still create security gaps in…
Cyber Security

Why do organisations still create security gaps in Microsoft 365 even when cloud controls exist?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Cyber Security

Gaps appear when teams assume the provider is responsible for data protection end to end. In practice, the provider secures the service infrastructure, while the customer must govern the data, users, and permissions inside it. Misunderstanding that boundary leads to overexposed files, weak access reviews, and blind spots in sensitive content discovery.

Why This Matters for Security Teams

Microsoft 365 reduces infrastructure burden, but it does not remove customer responsibility for identity, sharing, retention, classification, and permission hygiene. That boundary is where gaps appear. Security teams often inherit a tenant with broad sharing links, stale group membership, unmanaged guests, and no systematic review of sensitive content. The risk is not that Microsoft 365 is insecure by default, but that cloud convenience can hide governance drift until data exposure is already underway.

This is why shared-responsibility misunderstandings persist even in mature environments. The CSA Cloud Controls Matrix makes the control boundary explicit, yet many organisations still treat SaaS as if provider controls cover data access decisions. NHIMG research on the Microsoft Midnight Blizzard breach and the Ultimate Guide to NHIs both point to the same pattern: credentials, permissions, and delegated access remain the customer’s problem, even when the platform is managed. In practice, many security teams discover the gap only after a sensitive file is overshared or an admin path has already been abused.

How It Works in Practice

Closing the gap in Microsoft 365 starts with treating identity as the primary control plane. Security teams need to know who can access what, through which mechanism, and for how long. That means reviewing Entra ID roles, guest access, SharePoint and OneDrive sharing settings, Teams permissions, service principals, and OAuth-consented applications. The most important shift is to move from one-time configuration to continuous review, because access in Microsoft 365 changes through group nesting, app consent, external collaboration, and inherited permissions.

For sensitive data, classification and discovery need to be tied to action. If labels exist but are not enforced in sharing, download, or forwarding flows, they become documentation rather than control. Customer-managed settings should also be paired with logging and alerting so that file access, mailbox delegation, and anomalous consent events can be investigated quickly. NHIMG’s reporting on the State of Non-Human Identity Security shows how often organisations lack confidence in identity governance, and that same weakness shows up inside SaaS when permissions are not continuously scoped. The lesson is reinforced by incidents such as the CoPhish OAuth Token Theft via Copilot Studio, where delegated access and consent become the attack path.

  • Restrict external sharing by default, then allow exceptions by business need.
  • Review privileged roles, guest accounts, and app consents on a scheduled basis.
  • Use sensitivity labels, DLP, and access reviews together, not as isolated controls.
  • Monitor for dormant accounts, stale links, and anomalous mailbox or file delegation.

These controls tend to break down when organisations rely on tenant-wide defaults and never operationalise permission review across fast-changing collaboration spaces.

Common Variations and Edge Cases

Tighter Microsoft 365 controls often increase administrative overhead, so teams have to balance collaboration speed against exposure reduction. That tradeoff is especially sharp in mergers, regulated business units, and global organisations that depend on external sharing.

There is no universal standard for this yet, but current guidance suggests treating high-risk areas differently from general productivity use. Finance, legal, HR, and security data usually need stronger sharing constraints, more aggressive retention rules, and more frequent access reviews than ordinary team sites. The same applies to automation and third-party integrations. A single mis-scoped app registration or service account can reintroduce broad access even when interactive user permissions are well managed.

One common edge case is “shadow collaboration,” where users duplicate sensitive content into unmanaged spaces to avoid friction. Another is inherited access through old Microsoft 365 groups that no longer match the business structure. The practical response is to combine governance, monitoring, and user education rather than expecting any one control to close the gap. The Azure Key Vault privilege escalation exposure is a useful reminder that permission design failures often matter more than platform weakness. Where collaboration is highly decentralised and app consent is uncontrolled, these gaps persist because the tenant changes faster than the review process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Covers weak lifecycle control for identities and secrets in SaaS.
OWASP Agentic AI Top 10A-04Helpful where M365 automation or copilots expand access paths.
CSA MAESTROGOV-02Supports governance for SaaS data access, sharing, and oversight.
NIST CSF 2.0PR.AC-4Directly maps to access control for users, groups, and applications.
NIST AI RMFUseful when AI features and automated workflows alter SaaS access decisions.

Review Microsoft 365 identities, app consents, and secrets on a fixed rotation and removal schedule.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org