Cloud Computing Services: Fix These 5 Microsoft 365 Settings Before You Move to the Cloud
20 July, 2026
Businesses moving to cloud computing services typically focus on the migration itself — moving servers, applications, and data from on-premises infrastructure to cloud hosting. What most migration projects skip is the configuration layer that travels with you.
Microsoft 365 tenant settings configured years ago, or before Microsoft updated its defaults, do not change automatically when you move to the cloud. Legacy configurations migrate alongside your workloads. Cloud computing services engagements that do not include an M365 configuration audit leave security gaps that persist in the new environment and compound over time.
Here are five settings worth verifying before your cloud migration begins.
1. SharePoint and OneDrive Default Sharing Links
In Microsoft 365 tenants set up before 2022 — particularly those configured by a previous provider and not audited since — the default file sharing scope is often "Anyone with the link." This means any recipient can open a shared file without authentication and can forward the link indefinitely with no expiration.
When you move to cloud computing services, your file storage inherits this default. Every file shared with a vendor, contractor, or client generates a permanently accessible link. The fix — switching the tenant default to "Specific people" and setting a maximum link expiration — takes 15 minutes and is the most common configuration issue found during cloud migrations.
2. External Email Forwarding
Microsoft 365 allows users to create inbox rules that automatically forward all incoming email to an external address. This has no legitimate use case for most businesses — but it is exactly the mechanism attackers use after compromising a business email account to monitor financial conversations before a wire fraud attempt.
The energy and construction sectors in Texas see regular business email compromise attacks that involve compromised accounts with active forwarding rules, routing copies of all incoming email to attacker-controlled addresses for weeks before detection. Disabling external forwarding at the tenant level takes one policy change and eliminates this attack vector entirely.
3. Third-Party Application Consent
By default, Microsoft 365 allows any user to grant third-party applications access to their account — including email, files, and calendar — without administrator review. Cloud computing services migrations are particularly high-risk for this because employees experiment with new tools as workflows change. Disabling user consent and routing all app authorization through administrator review is a standard configuration that cloud service providers should include in the migration scope.
4. Audit Log Retention
Microsoft 365 audit logs record sign-in events, administrative actions, file access, and configuration changes. The default retention is 180 days after October 2023 changes. Texas businesses with regulatory compliance requirements — healthcare, energy, financial services — may need longer retention for incident investigation and compliance reporting.
Audit logging must be manually verified in some tenant configurations. Before migrating to cloud computing services, confirm that logging is active and that the retention period matches your compliance requirements. This is significantly easier to establish before migration than to retrofit after workloads are in production.
5. MFA Enforcement on All Accounts
Multifactor authentication enforced across all accounts — including service accounts, admin accounts, and shared mailboxes — is the single most effective control against credential-based account compromise. Many Microsoft 365 tenants have MFA configured as available but not required, which means users can bypass it.
Cloud server and cloud services migrations are the right moment to move to Conditional Access-based MFA enforcement: blocking legacy authentication protocols, requiring MFA from all users, and applying additional requirements for access from unmanaged devices. Legacy protocols that bypass MFA are often still active in tenants that have not been audited recently.
Making Cloud Migration Secure
Cloud computing services engagements should include M365 tenant configuration review as a standard deliverable. The five settings above are easier to fix before migration than after. Elevate Technology delivers cloud services for Texas businesses that include tenant configuration audit, security baseline implementation, and ongoing managed IT services to maintain the environment after migration is complete.
Frequently Asked Questions
What is the SharePoint default sharing scope and how does it affect cloud server storage?
Many existing tenants still default to "Anyone with the link" sharing. When workloads move to cloud servers, this default follows. Any file shared externally generates a permanently accessible link until the default is changed and existing links are audited. Switching to "Specific people" is a 15-minute fix that prevents new open links from being created.
How does external email forwarding become a security risk in cloud computing services?
Inbox forwarding rules created by users — or by attackers after compromising an account — route copies of all incoming email to an external address. In a cloud computing environment, this is one of the primary post-compromise reconnaissance techniques attackers use to gather business intelligence before wire fraud or ransomware deployment. Blocking external forwarding at the tenant level closes this gap.
→ Starting a cloud migration? Visit Managed IT Services — Elevate Technology for a tenant review.