Company
Services
Industries
Resources
Expert perspectives on IT strategy, cybersecurity, compliance, and technology trends for modern businesses.
The Microsoft 365 settings that cause audit problems are rarely the ones anyone decided on. They are defaults nobody changed, and the most expensive of them is a retention window that quietly deletes your evidence before an auditor asks for it.
Three weeks before fieldwork, the team is not implementing better security. They are reconstructing proof that controls were operating. That work is avoidable, and avoiding it is mostly a question of when it gets done rather than how hard.
Microsoft 365 Backup improves recovery speed and expands restore options inside the tenant. What it does not do is create separation from the tenant, and separation is the part auditors examine.
Most companies treat the help desk like a cost center. That's fine if all you care about is getting people back to work. It's a problem if you care about security or compliance, because the help desk is where access decisions actually get made.
Security doesn't start when an employee signs into their laptop. It starts at the purchase order and it isn't finished until the drive has been destroyed and the certificate is on file. Most endpoint security problems are operational problems first.
Weak passwords are still one of the easiest ways into an environment. What has changed is the expectation around how you control it. Auditors look at how credentials are actually handled, not what your handbook says.
A compliance platform reports what is true right now. An auditor asks what happened in March, in which system, and who approved it. Those are different questions, and the gap between them is where a lot of first-year SOC 2 programs get into trouble.