Citation Bureau
Vol. I
No. 353
XII SEPTEMBER MMXXVI
Software

What is Microsoft 365?

Microsoft 365 is a cloud-based productivity and collaboration platform from Microsoft that includes services such as Exchange Online, Teams, SharePoint, OneDrive, Intune, and Entra ID. Discussion in late 2026 centered on tenant security and recovery: the configuration layer, identity trust relationships, and abandoned applications as attack paths.

Release history

  • Sep 2026 - Matt Dircks said a university tenant held 60,000 to 70,000 SharePoint sites created for projects and never shut down, many still externally shared, unadministered, and holding PII.
  • Sep 2026 - Dircks said stale Entra apps with weak permission models are now a main way adversaries enter tenants, often carrying significant read access in and out.
  • Sep 2026 - Dircks said one tenant was found to have roughly 33 global administrators.
  • Sep 2026 - A speaker said attackers create enterprise apps to maintain persistence in tenants after a compromised account’s access is removed.
  • Sep 2026 - A speaker argued the most valuable asset in Microsoft 365 is the trust relationships determining access, since rebuilding compromised identities and controls is harder than recovering data.
  • Sep 2026 - Dircks said Corv takes a daily immutable backup of tenant configurations and settings and provides near real-time drift detection.

In the discourse

Attributed discussion of Microsoft 365.

Contrarian take

Most organizations cannot identify what M365 tenant state they would restore to, because tenant configuration is accumulated over years and mixes deliberate settings, drift, and potential attacker changes.

“Most organizations can't tell you what state they'd be restoring to. So you can back up data like you said data has a shape and you can verify that. But the thing that actually runs your business in Microsoft 365 is the actual configuration right conditional access admin roles. What's that mail flow look like? sharing the retention pieces and that config isn't designed. It is accumulated, right? You've got 10 years, lots of hands, lots of exceptions. Granted, for good reasons at the time, I'm sure. And when you restore it, you're now looking at a tenant that you can't tell which sittings were deliberate, which were the drift, and which the attacker put there.”
<UNKNOWN> · 10 Sep 2026
By the numbers

A university Microsoft 365 tenant accumulated 60,000 to 70,000 never-decommissioned SharePoint sites, all with external sharing enabled or no assigned admin, and all containing PII.

“60 or 70,000 SharePoint sites that were created for projects and never spun back down again. All of which had some level of external share still enabled or at a minimum didn't have an administrator assigned to them anymore. all with PII from the university sitting inside of them.”
Matt Dircks · 11 Sep 2026
Best explained

Why M365 tenant incidents become circular recovery nightmares: you need identity to fix identity, and must log into the system that handles logging in, making a tenant incident effectively a company-wide outage.

“If I have a tenant incident and it's an application outage, it's a company outage. The recovery is going to be circular. You need identity to fix identity and you're trying to log into the thing that does the logging in.”
<UNKNOWN> · 10 Sep 2026
Contrarian take

Abandoned third-party Entra apps with weak permissions are now one of the primary entry vectors into Microsoft 365 tenants, including Microsoft's own tenant in the Midnight Blizzard attack.

“Those apps are actually now one of the main ways that adversaries are getting into tenants is they can scan a Microsoft tenant. They can find these old enter apps that have just been left behind with weak permission models and often those entra apps have significant readr access in and out of the tenant.”
Matt Dircks · 11 Sep 2026
Best explained

Attackers create enterprise apps in Microsoft 365 to maintain persistence after their initially compromised account access is removed, making account remediation alone insufficient for full eviction.

“Attackers will create enterprise apps as a means to maintain persistence within tenants after potentially we remove access to that compromised account.”
<UNKNOWN> · 10 Sep 2026
By the numbers

A large Australian public sector Microsoft 365 tenant was found to have 33 global administrator accounts.

“We discovered that they had something like 33 global administrators in that one tenant for example.”
Matt Dircks · 11 Sep 2026
Contrarian take

In Microsoft 365, trust relationships and access controls are more valuable than data itself for recovery purposes, because rebuilding compromised identity and security controls is vastly harder than recovering data.

“The most valuable asset in Microsoft 365 isn't the data really. It's actually the trust relationships that determine who can access it that are more important in meantime for recovery. Data can usually be recovered. But rebuilding trust after identities and security controls that have been compromised is vastly more difficult.”
<UNKNOWN> · 10 Sep 2026
Contrarian take

The obstacle to infrastructure-as-code for M365 is not tooling but the impossibility of retroactively declaring configuration intent for tenants that have accumulated changes over a decade.

“Now, why does nobody get there? It's not tooling. It's that you had to declare what your config as code was going to look like before you started the build. The problem is you're looking at a 10-year-old tenant and it was never decided and it's accumulated, right? We're constantly making changes to that. So to say that we just need to go to infrastructure as code, I don't think it's going to be that easy.”
<UNKNOWN> · 10 Sep 2026
Best explained

M365 configuration drift is driven by normal software growth independent of attacker activity, meaning offline backup snapshots become unreliable restore baselines as new parameters and changed options accumulate within weeks.

“To be honest, that's not great because the M365 world is dynamic, right? If I were to write down every configuration that I've that I've got in my tenant and exactly how I've got that configured and then in a month's time, I come, you know, I need to go back and restore those configurations. A lot of those configurations will look different, right? There'll be new parameters to those configurations. Some of those options may have changed. A lot of this is just the normal growth of software and it has nothing to do with someone doing something bad or someone attacking you. Sometimes the normal growth of software causes configurations to drift.”
<UNKNOWN> · 10 Sep 2026
Contrarian take

A real-time digital twin of a compromised M365 tenant is still a real-time copy of the compromise and does not solve attacker persistence.

“A real-time twin of a compromised tenant though is still going to be a real-time copy of the compromise.”
<UNKNOWN> · 10 Sep 2026
Citation Bureau · reference note, compiled from attributed expert discussion. Last updated 2026-09-12.