Microsoft 365 Permission Failures Enabling Email and SharePoint Exfiltration

Most Microsoft 365 breaches stem from preventable misconfigurations, not platform flaws.

Summary

Most Microsoft 365 breaches stem from preventable misconfigurations, not platform flaws.

A breach hits the headlines, the word "Microsoft" sits in the first paragraph, and readers assume the platform cracked. A breach traces to the software doing what it was told, and what it was told came from a setting somebody left alone. The shared responsibility model draws the line clearly. Microsoft handles the datacenters, the network, the hypervisor, the host OS, and the uptime of the service itself, while identity and access management, data classification, tenant configuration, application consent, and user behavior belong to the customer. Microsoft's FY2025 commercial cloud earnings report shows Microsoft 365 is the intersection of identity, communication, and data storage for over 345 million paid seats globally. Gartner's research backs this up at scale: the overwhelming majority of cloud security failures trace back to the customer, mostly through misconfiguration, not some flaw in the underlying tech.

The confidence gap makes this worse before it gets better. CoreView's 2026 State of Microsoft 365 Security Report surveyed 279 enterprise IT and security leaders and found a majority rating their M365 security as "Established" or "Advanced." Yet 54% of that self-assured majority lack at least one of three basic controls: MFA enforced on admin accounts, a privileged access management setup, or any defined way to catch configuration tampering. Confidence and competence are tracking two different variables here. Once an organization decides it has "advanced" security, the budget conversation for actually locking down identity and configuration tends to end, and the label sticks around long after the gap it was supposed to describe has widened.

Four permission failure modes behind email and SharePoint exfiltration

Email and SharePoint exfiltration routes flow predictably through four well-documented permission failure modes that recur constantly across tenant assessments.

The first is anonymous sharing in SharePoint and OneDrive. New communication sites default to "Only people in your organization," with the root communication site as the lone exception that defaults to "Anyone," and that narrow exception is exactly the kind of setting nobody circles back to fix once it's been left in place. SharePoint and OneDrive defaults can allow users to share files with anyone who has a link, including people outside the organisation with no requirement to sign in. CoreView's 2026 data shows SharePoint storage growing across a large majority of organizations over the past year, stacking new files on top of years of ungoverned sharing links. Each "Anyone with the link" file becomes a door with no lock and no camera: it can be forwarded anywhere, by anyone, and the organization has no record of who walked through.

The second failure mode runs through the inbox itself. Some attackers go further and build rules that quietly bury security alerts in hidden folders, so the compromise stays invisible while it runs. Most tenants now block external forwarding by default, but that setting gets flipped for a legitimate reason (routing helpdesk mail to an outside CRM, say) or was never turned on in an older environment, and defaults have a way of drifting back toward exposure the moment operations need a workaround.

The third mode operates through OAuth consent rather than stolen passwords. Phishing campaigns increasingly aim at getting a user to click "Accept" on a malicious app's permission request, and once that click happens, the attacker holds a token that pulls email, OneDrive files, and SharePoint documents through the Microsoft Graph API indefinitely, with no password ever required again. CoreView's 2026 data found 63% of organizations skip access reviews of their Entra apps because the reviews take too long, and a notable minority can't even produce a count of how many apps they have connected. An Application Administrator role can grant these permissions and build token-based persistence that steps around MFA and Conditional Access entirely, which makes the app consent screen one of the least-watched doors in the whole tenant.

The fourth mode is standing privilege sitting where it shouldn't. A Global Admin account can change security settings, read user data, and spin up new accounts, so a single compromised Global Admin can quietly create elevated roles, kill logging, and pull email or SharePoint data long before any ransom note shows up. An Exchange Administrator can exfiltrate or alter executive email without much resistance, and a Privileged Role Administrator can simply assign itself Global Admin rights. CoreView's 2026 findings show full MFA enforcement is more common for standard users than for admin accounts, so the accounts with the most power over a tenant carry the least protection. Building custom Entra roles takes real admin time few teams have spare, so least privilege gets deferred while standing privileged access leaves a lateral movement risk that Conditional Access alone can't shut down.

How real incidents show these failures combining in practice

Named breaches confirm the pattern rather than complicate it. Every major M365 exfiltration incident on record traces to at least one of these four failure modes, and the worst ones stack several at once.

Take Microsoft's own Midnight Blizzard incident, running from late November 2023 into January 2024. The threat actor got in through a password spray attack against a legacy non-production test tenant account, then rode that account's permissions into a slice of Microsoft's corporate email, including members of the senior leadership team and staff in cybersecurity and legal. The threat actor used a legacy test OAuth application to grant themselves the Office 365 Exchange Online full_access_as_app role, part of the Exchange Web Services (EWS) API, which grants an application full access to all mailboxes in the organization. Microsoft later disclosed that material pulled from those exfiltrated emails was used, or attempted, to reach some of the company's source code repositories and internal systems. This maps to failure modes 3, an over-permissioned OAuth app, and 4, a standing legacy account that should have been decommissioned years earlier.

The ExfilSquad campaign against Microsoft Power Pages sites, which surfaced on July 26, 2026, with a leak site on the dark web claiming multiple compromised organizations, points to misconfigured sites that may have exposed data in Microsoft Dataverse to anonymous visitors. That's failure mode one again: data reachable by anyone because the site configuration allowed anonymous access, no exotic exploit required.

September 2026's TeamFiltration campaign shows what happens once an attacker is inside and permissions aren't scoped down. Across most compromised accounts, the actor used its foothold to reach Office, OneDrive, and Teams, consistent with data harvesting. Proofpoint had already flagged a related cluster, UNK_SneakyStrike, in June 2025, targeting tens of thousands of accounts across hundreds of tenants using the same open-source penetration testing framework. Both cases combine failure modes one and four: broad access sitting there for the taking once the door was open.

Marks & Spencer's 2025 breach puts a number on what a single misconfiguration can cost: losses exceeding £30 million in profits, plus weeks of ongoing operational disruption. Microsoft 365 has over 450 million paid commercial subscribers across 3.7 million organizations worldwide, with over 90% of Fortune 500 companies relying on the platform as their primary collaboration and communication infrastructure, making it the single largest attack surface for most enterprises. That bill wasn't a regulatory fine for mishandling data; it was straight revenue and operations damage from a configuration failure, a cost that a compliance checklist won't catch until after it's been paid.

One incident deserves a clear boundary rather than a blanket lesson. The on-premises SharePoint ToolShell exploits from July 2025 let attackers bypass authentication entirely, including MFA and SSO, to gain privileged access, exfiltrate data, plant persistent backdoors, and steal cryptographic keys; Michael Sikorski, former CTO and VP of Engineering at Palo Alto Networks' Unit 42 and now CISO at Coinbase, warned that government, education, healthcare, and large enterprise systems faced immediate risk. These vulnerabilities hit on-premises SharePoint servers, not SharePoint Online inside Microsoft 365. Cloud-only tenants weren't exposed to ToolShell itself, though organizations running hybrid environments face the compounded risk of both an on-prem authentication bypass and the cloud-side permission failures described above.

How Microsoft 365 Copilot turns permission failures into instant data exposure

Copilot doesn't invent a new category of risk. It reaches into whatever permission structure already exists and returns results faster than any human ever could. Copilot pulls from any data a user is permitted to reach, and it applies no judgment about whether that access makes sense, it simply operates inside the boundaries the tenant's existing permissions already set. Over-permissioned SharePoint sites, misconfigured Teams channels, and files sitting behind anonymous sharing links all become instantly queryable the moment someone asks Copilot the right question.

Four oversharing patterns do most of the damage: the "Everyone except external users" group, broken permission inheritance, anonymous or organization-wide sharing links, and legacy "All Employees" security groups that nobody remembered to retire. Concentric AI data cited by MyWorkDrive puts the scale in stark terms: a significant share of business-critical data sits overshared across a typical organization, averaging hundreds of thousands of exposed files. Copilot doesn't create that exposure; it just makes it retrievable in seconds instead of requiring an attacker to go hunting.

Organizations have picked up on this faster than most security vendors expected. CoreView's 2026 report found 66% of organizations delayed or cancelled a Copilot rollout over concerns about what data it might surface through SharePoint. That hesitation reflects something useful: companies discovering their own permission debt before deployment rather than after a breach report. But the cleanup can't be a one-time gate before launch. Sharing drift resumes the moment someone spins up a new team, a new site, a new folder, or a new link, so governance has to run continuously rather than as a pre-launch checklist. Deploying Copilot on top of an ungoverned SharePoint environment doesn't add an AI productivity tool. It adds a high-speed query interface sitting directly on top of every unresolved permission failure the tenant already had, and the fix for one is the fix for the other: the same sharing cleanup that makes Copilot safe to deploy is the same cleanup that closes the exfiltration paths described above.

Why standard compliance tools leave the permission surface unchecked

Plenty of security teams believe they've covered this ground because they run Microsoft Secure Score, check against CIS benchmarks, and pass whatever government-mandated scanner applies to their sector. Each of those tools checks a real but limited slice of the tenant. Secure Score covers a defined set of checks, CIS benchmarks cover a comparable range of controls, and free government scanners cover a narrower automated subset still, against a tenant that has more than 10,000 configurable settings. Running all three tools at once still leaves significant blind spots because the coverage gap is built into how the tools are scoped.

Configuration drift piles on top of that structural gap. CoreView's 2026 data shows a significant share of organizations relying on manual checks to catch configuration tampering, and some run no monitoring for it at all. The mechanism is mundane rather than dramatic: an admin loosens a security setting to unblock a user's access issue, means to revert it, and the ticket queue moves on before that happens; or Microsoft ships a platform update that introduces new settings nobody's existing policy accounts for. IT teams under constant ticket pressure treat security settings the way most people treat smoke detector batteries, in that everyone means to check them and almost nobody schedules it. Backup compounds the exposure further: only a small minority of organizations back up their own M365 configurations, Microsoft doesn't do it for them, and data backup vendors typically cover just a portion of tenant configuration rather than the whole surface.

There's a fair objection buried in all this: Microsoft's defaults favor collaboration over lockdown, and that design choice lets the platform share blame instead of leaving it entirely on the customer. That criticism has some weight, since Microsoft has faced repeated scrutiny for shipping features that prioritize ease of sharing over secure-by-default configuration. But the remediation tools sit right there in the tenant, largely native and mostly free: Conditional Access policies, Entra role restrictions, sharing link expiration settings, app consent governance. An organization that never turns those on hasn't yet done the configuration work the shared responsibility model always said was theirs to do.

Sources

  1. 2026 CoreView State of Microsoft 365 Security Report
  2. 27M records exposed: hackers target Microsoft Power Pages in massive data heist
  3. Email Security for Microsoft 365: Native Gaps & Fixes | Adaptive Security
  4. 2026 State of M365 Security — Full Report (PDF View) | 365 Security
  5. Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog
  6. Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated August 12)
  7. TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
  8. Microsoft 365 mailbox rules abused for exfiltration, persistence | news | SC Media

More in Cloud Permissions