Summary: Microsoft 365 is at the heart of everyday work for many organisations. But identity, email, sharing, permissions and logging need to be configured correctly to provide good protection. Kristensson i Skåne helps companies in Malmö, Lund, Helsingborg and the rest of Skåne with IT consulting and a security-oriented review of Microsoft 365.
For many organisations in Skåne, Microsoft 365 is a natural part of everyday work. Email, Teams, SharePoint, OneDrive, Entra ID, Intune and Defender are used every day by management, employees, consultants and external partners.
That makes Microsoft 365 a central part of the organisation’s IT environment. But it also makes the environment a natural target.
In its Digital Defense Report 2025, Microsoft describes how cyberattacks are largely driven by financial motives such as extortion, ransomware and data theft, and at the same time highlights identity as a central area of attack. For organisations using Microsoft 365, questions such as multi-factor authentication, conditional access, email protection, logging and permission management therefore become much more than technical details.
They are part of the organisation’s basic resilience.
When do you need an IT consultant with a security focus?
Many people look for an IT consultant in Malmö, Lund or Helsingborg when something concrete needs solving: a migration, a new Microsoft 365 environment, a licence change, support, Intune, Teams, email or user management.
That is often a good start. But it is rarely enough for Microsoft 365 to just work.
The environment also needs to be reasonably secure, traceable and possible to follow up.
Common questions we encounter are:
- Do all users have MFA set up correctly?
- Are administrator accounts sufficiently protected?
- Is conditional access in place for the right users, apps and risk levels?
- Are external shares in SharePoint and OneDrive controlled?
- Is email protection, anti-phishing and domain protection correctly configured?
- Is there logging that can be used during incidents?
- Does the organisation have control over which apps and integrations have access?
- Is there a plan for follow-up, improvement and incident handling?
This is where traditional IT consulting and information security need to meet.
Microsoft 365 needs both technology and governance
Microsoft 365 contains many good security features. But their effect depends on how they are configured, how they are followed up and how they fit the organisation’s ways of working.
Microsoft Secure Score, for example, gives a consolidated view of the security posture for identities, apps and devices in Microsoft 365, and provides recommendations for improvements. It is a good tool, but it should not be used mechanically. Every recommendation needs to be assessed based on the business, risk, licences, user experience and actual value.
Likewise, multi-factor authentication and Conditional Access are central parts of modern protection. Microsoft recommends Conditional Access as a way to require MFA when accessing, for example, Microsoft 365, while simpler environments can use security defaults as basic protection.
The point is not to turn on as much as possible. The point is to create protection that works in everyday life.
Examples of areas we review in Microsoft 365
A security-oriented Microsoft 365 review can be adapted to the organisation’s size, licences and maturity. We often look at the following areas.
Identity and sign-in
Identity is often the most important control point. If an account is compromised, the attacker can reach email, files, Teams, internal systems and sometimes even administrative functions.
We review, for example:
- MFA and authentication methods
- administrator roles
- break-glass accounts
- Conditional Access
- legacy authentication methods
- external users and guests
- risky sign-ins and anomalies
The goal is to reduce the risk of account compromise without creating unnecessary friction for users.
Email protection and phishing
Email is still a common way in. That is why the protection in Exchange Online and Microsoft Defender for Office 365 needs to be set up correctly.
Microsoft describes Safe Links as protection against malicious links used in phishing and other attacks, and Safe Attachments as extra protection where attached files can be opened in a virtual environment before they are delivered to the user.
We review, among other things:
- anti-phishing policies
- Safe Links and Safe Attachments
- protection for priority users
- quarantine handling
- reporting of suspicious messages
- SPF, DKIM and DMARC
- handling of forwarding and external rules
Microsoft also recommends that SPF, DKIM and DMARC are used together as part of the organisation’s email authentication.
Sharing and permissions
SharePoint, OneDrive and Teams make collaboration easy. But if sharing and permissions are not governed, information can end up in the wrong place.
We look at, for example:
- external sharing
- guest users
- sensitive teams and SharePoint sites
- access to management and customer information
- ownership of collaboration spaces
- lifecycle for external users
- routines for reviewing permissions
Here, security is not about stopping collaboration. It is about creating control over how the collaboration happens.
Logging, traceability and incident readiness
When something happens, the organisation needs to be able to understand what has occurred. Who signed in? What data was opened? Which settings were changed? Which messages were forwarded?
Microsoft Purview Audit makes it possible to search logs of user and administrator activities, and Microsoft also describes options for longer log retention depending on licence and configuration.
We review, for example:
- whether relevant logging is active
- how long logs are retained
- who can search the logs
- which alerts and notifications exist
- whether there is a practical incident process
- whether roles and responsibilities are clear in case of suspected account compromise or data leakage
Logging is not just a technical question. It is a prerequisite for incident handling, regulatory compliance and learning after an event.
IT consulting in Skåne with a security focus
Kristensson i Skåne helps organisations in Malmö, Lund, Helsingborg and the rest of Skåne with IT consulting where technology, information security and practical implementation fit together.
We can support you in defined engagements, for example a Microsoft 365 review, or on a more ongoing basis as an IT consultant, security advisor, GRC support or CISO support.
Examples of support we can deliver:
- a security review of Microsoft 365
- review of Entra ID, MFA and Conditional Access
- review of administrator roles and permissions
- checking email protection, SPF, DKIM and DMARC
- review of SharePoint, OneDrive and Teams sharing
- a Secure Score review and a prioritised action plan
- support with Intune, device management and client governance
- logging, incident readiness and follow-up
- documentation, routines and allocation of responsibility
- ongoing IT and security support as a service
Our role is not just to point out what is missing. We help prioritise, explain the consequences and carry out improvements in a way that works for the business.
From working IT to a safer IT environment
A Microsoft 365 environment can work well in everyday life yet still have weaknesses that do not show until something happens.
It could be an administrator account without the right protection, an old sharing link, a gap in the email protection, insufficient logging or a Conditional Access policy that was never finished.
That is why we recommend that organisations regularly carry out a practical review of their Microsoft 365 environment.
Start with the most important questions:
- Which accounts are the most worth protecting?
- Which users have administrator rights?
- Which information is shared externally?
- How is email protected against phishing?
- Which security recommendations are most important to address?
- Are there logs and alerts that work during an incident?
- Who owns the follow-up?
It does not have to become a big project. Often it is enough to start with a prioritised review and a clear action list.
Do you need an IT consultant in Malmö, Lund or Helsingborg?
Are you looking for an IT consultant in Malmö, an IT consultant in Lund or an IT consultant in Helsingborg with a focus on Microsoft 365, security and practical implementation?
Kristensson i Skåne helps organisations gain better control of their Microsoft 365 environment, reduce unnecessary risks and build security work that can be followed up.
Would you like to know whether your Microsoft 365 environment is correctly configured and sufficiently protected? Contact us and we will have a first conversation.
Frequently asked questions
Does Kristensson i Skåne offer IT consulting in Malmö?
Yes. Kristensson i Skåne offers IT consulting in Malmö and the rest of Skåne, with a focus on Microsoft 365, information security, GRC, CISO support and practical implementation.
Does Kristensson i Skåne offer IT consulting in Lund?
Yes. We support organisations in Lund with IT consulting, Microsoft 365 security, security reviews, risk work and practical improvements.
Does Kristensson i Skåne offer IT consulting in Helsingborg?
Yes. We work with organisations in Helsingborg and the rest of Skåne within IT consulting, Microsoft 365, information security, cybersecurity and security-oriented advisory.
What is included in a Microsoft 365 security review?
A review can cover identity and MFA, Conditional Access, administrator roles, email protection, SPF/DKIM/DMARC, SharePoint and Teams sharing, Secure Score, logging, incident readiness and a prioritised action plan.
Is this just technical support?
No. We can help technically, but our focus is to combine IT consulting with information security, governance, risk and practical implementation. The goal is for Microsoft 365 to work securely in the everyday business.
Sources and further reading: Microsoft Digital Defense Report 2025. Microsoft Learn: Microsoft Secure Score; Conditional Access and MFA; Safe Links and Safe Attachments in Defender for Office 365; Microsoft 365 email authentication with SPF, DKIM and DMARC; Microsoft Purview Audit.
This is an overview and not legal advice. Every organisation needs to assess its Microsoft 365 environment based on its operations, licences, risk picture, technical conditions and regulatory requirements.

