In this video
- Why "we have MFA, endpoint protection and a next-generation firewall" is not the same thing as being secure
- Microsoft 365 tenants with MFA enabled but legacy authentication still permitted
- Active Directory environments carrying far more privileged accounts than they need
- Firewall management interfaces and unused services still reachable from the internet
- Why vendor defaults are tuned for ease of deployment rather than for security
The gap is between default and secure
Default configurations exist so that a product installs cleanly and works on day one. They are not a security baseline, and no vendor claims they are. The distance between the configuration a product ships with and the configuration a hardened environment needs is where most incidents live.
These three patterns come up repeatedly during assessments. In every case the technology was already purchased, already deployed and already showing green in the admin console.
Why an admin console won't show you this
Configuration drift is invisible from inside the product. MFA reads as enabled whether or not legacy authentication is blocked alongside it. The console reports what is switched on, not whether what is switched on is sufficient. A benchmark comparison is what turns that into a measurable answer.
Frequently asked questions
If MFA is switched on, can an attacker still get in?
Yes, if legacy authentication protocols are still permitted on the tenant. Those older protocols cannot present a second factor, so an attacker holding a valid username and password can connect through them and bypass MFA entirely. Blocking legacy authentication is what makes MFA effective.
How would we know if our tools are misconfigured?
Not from the admin console — everything there looks enabled. A benchmark comparison is what surfaces it: each setting is checked against a published standard and reported as a pass or a fail, with the specific value that needs to change.
Is this a problem with the products themselves?
No. In each of these examples the product works as designed. The gap is between the configuration it shipped with and the configuration a secure environment needs.
Keep reading
Find out how your tools are actually configured
A CIS Assessment checks your Microsoft 365, Active Directory and firewall configuration against published benchmarks and reports the gaps in priority order.
Contact Us




