For years, a lot of people have pushed “Put it in the cloud” without discussing the potential data risks and management overhead. This is important insight for everyone using M365, but especially the small businesses (SMBs) who think they can manage it without proper guidance. “If it’s in the cloud, I don’t need IT support.” Wrong. If M365 is left with default settings and you care about risk management, here are two things you should know:
- You have very little control over users syncing OneDrive and SharePoint. Sure, you can turn off syncing, but the experience accessing files is much more cumbersome than using File Explorer. Scenario: a user syncs their OneDrive and all accessible SharePoint sites to their home computer, then changes their sync setting to “Download all files” or right-clicks any folder and clicks “Always keep on this device”. The user eventually quits the company – guess what, you’ll need a subpoena to see what is on their computer without their permission.
- File access management is left up to the end user. With on-prem file storage, the IT staff usually creates the needed folders and sets permissions on those folders, so it was centralized. Now, it’s like the wild west. Without proper licensing, tools, and monitoring, you have little idea what is being created and who is sharing what with whom. By default, M365 users can also create SharePoint sites and grant permissions as needed. Scenario: a user shares their OneDrive folders or SharePoint site documents with a personal, external account (user@yahoo.com). By the way, external sharing is enabled by default. The user eventually quits the company and still has access to all their files through this personal account. Anyone else they shared with still has access.
Out of the box, M365 has glaring data security risks. Maybe that’s a way for Microsoft to sell additional licensing with better security. However, this is a significant problem for SMBs who may not know any better or choose not to effectively manage their environment. The M365 platform has certainly matured over time and having managed it and on-prem file storage, such as servers, I can honestly say it takes significantly more time and effort to manage M365 properly. Yes, these risk scenarios can be mitigated, but to manage it properly, you can’t just purchase it, create a few users, and think you’re done.

Leave a comment