The Microsoft 365 attack surface is wide and unpredictable. Risks can come from any direction, whether it’s the complexity of managing multiple tenants, the explosion of Entra apps with broad permissions, or inconsistent enforcement of security controls like MFA.
These issues are often worsened by limited visibility, manual oversight, and a lack of cohesive governance. Even small missteps, like an unmonitored configuration change or an overlooked admin role, can introduce serious vulnerabilities.
49% of IT leaders mistakenly believe that Microsoft backs up their configurations automatically, leaving them vulnerable in the event of a disaster.
78% of organisations manage multiple Microsoft 365 tenants, creating significant complexity for IT teams. Many valid reasons exist for maintaining multi-tenant architectures. It’s often a strategic choice, not a technical limitation.
Organisational, geographic, and security factors frequently drive the separation, such as:
Regardless of alignment, multi-tenant management brings complexity and risk, often beyond what organisations are prepared for.
Organisations with 10 or more tenants are 2.3 times more likely to report significant operational overhead than those with just 2–4. Each tenant adds its own configurations, licensing costs, admin burden, cross-tenant access risks, and contributes to identity and privilege sprawl.
The good news is that organisations are getting global admin proliferation under control. Only 20% report having more than 10 global admins, while 61% maintain five or fewer, which is close to Microsoft’s best-practice recommendation of fewer than five.
While global admin counts are down, a new risk is rising: 51% of organisations have 250+ Entra apps with read-write permissions, and 18% report over 1,000. Even among those limiting global admins to five or fewer, 43% still allow 250+ apps with these powerful permissions.
Yet most organisations lack strong oversight: 16% have no process at all, 33% rely on manual reviews, and only a minority use built-in (29%) or third-party (22%) tools to manage app permissions.
While 96% of organisations sa their data is backed up or will be soon, many overlook configuration backups entirely. 47% rely on Microsoft’s built-in tools, which back up data but not configurations. Another 25% use third-party backup vendors, 18% manually back up configurations or rely on documentation, and 10% have no strategy at all.
Organisations with formal disaster recovery plans are 58% less likely to experience significant operational disruptions from misconfigurations. And with formal change control processes in place, they see 72% fewer security incidents tied to misconfigurations.
68% of organisations report that attackers attempt to access Microsoft 365 weekly, daily, or constantly.
Despite the fact that 99.9% of account compromises occur in accounts lacking MFA, only 41% of organisations have implemented MFA effectively. Organisations with automated MFA detection and enforcement experience 53% fewer account compromise incidents compared to those with only partial implementation.
“In a landscape where 49% of IT leaders mistakenly believe their configurations are backed up by Microsoft, and 68% of organisations are facing constant cyber threats, it’s crucial for businesses to reevaluate their security strategies,” says Simon Azzopardi, an expert in cloud security.
"*" indicates required fields
Software Asset Management is a business practice that involves managing and optimising the life cycle of software within an organisation.
Software asset management is relevant to many facets of a business - take a look at some of the roles that it can form part of the focus of.
Software vendors come in all shape and sizes - all with their own set of licensing models and rules. We take a look at just a few of them.
As a constantly evolving subject, SAM is not without its challenges. We take a look at some of the most common ones.
Wondering what an investment in SAM could do for your business? Fill out a few details and find out what return you could get!
Answer a few questions about your SAM infrastructure & experience, and we'll put together a personalised recommendation for the future.
A simple health check of what's being used across your Office 365 estate in this FREE, Microsoft backed and easy to setup review.
Just like you would with your vehicle each year, get an annual check up of your software asset management programme.
Overwhelmed by the task of documenting the steps for a successful SAM programme? Get the experts in to help!
Concerned your SAM tools aren't covering your whole estate? Or on the look out for an entirely new tool? Get us in to assist.
Not content with covering all things SAM related, we've teamed up with Capital to provide a comprehensive hardware asset management review.
A simple, one-time reconciliation of the software you have deployed versus the licence entitlement you own.
A regularly scheduled analysis of your organisation's estate, specifically adapted to your needs and budget.
A full appraisal of your Microsoft 365 setup and how best to optimise it through automated recommendations.
An add-on to our SAMplicity One, MOT and Plus offerings, quickly diagnose your ability to migrate your resources to the cloud.
In collaboration with law firm Addleshaw Goddard, ensure the legality of your SAM programme and get assistance with any contract disputes.
Available as standard with SAMplicity Plus, ensure you're compliant if you're unexpectedly audited by a vendor.
We've teamed up with some of the forefront experts in licensing knowledge so you can teach yourself to be an expert too.
Stumped by the continually evolving complexities of SAM? Join us for one of our comprehensive courses, either in-person or online.
It’s chock full of useful advice, exclusive events and interesting articles. Don’t miss out!