<img src="https://ws.zoominfo.com/pixel/PMY3ZvbpZt27ywWwZSBB" width="1" height="1" style="display: none;">

You are now leaving locknetmanagedit.com

Please check the privacy policy of the site you are visiting.

Continue to Site

Microsoft

What Minnesota Banking IT Leaders Told Us About Their M365 Security Posture

Professional corporate photography of an IT director reviewing cybersecurity metrics on modern monitors in a high-end bank office, warm natural light, soft bokeh background with modern architectural details, navy blue aesthetic, sophisticated tone

At this year's Minnesota Bankers Association Operations and Technology Conference, we asked financial leaders a straightforward question: How secure is your Microsoft 365 environment, really? Not in theory, but in terms of what you actually know, what you've routinely tested, and where your M365 security gaps honestly lie.

We surveyed 14 IT directors, CISOs, and operations leaders following a session on Microsoft 365 security roadmaps. While the sample is focused, the candor of the responses offers a valuable snapshot of where peer institutions across Minnesota banking and the broader Midwest currently stand.

What came back was refreshingly honest—and highlighted several areas that should prompt an immediate conversation within your own institution.

Regional Industry Benchmarks

M365 Security Posture Gaps in Banking

M365 Conditional Access Moderate Risk

50% have implemented conditional access policies; 43% still rely solely on basic MFA.

M365 Legacy Authentication High Risk

Only 36% have fully disabled legacy authentication protocols (e.g., POP, IMAP).

Incident Response Testing High Risk

43% have never tested their incident response process for an M365 account compromise.

Microsoft Copilot & AI Security High Risk

93% are concerned about employees using AI tools without understanding data risks.

What we learned about M365 security posture in Minnesota banking

In short: most Midwest financial institutions have a solid foundation in place, but significant blind spots remain in their overall M365 security posture.

While half of surveyed institutions have adopted M365 conditional access, nearly as many rely on standard multi-factor authentication (MFA) alone. A alarming number still leave M365 legacy authentication unblocked. Furthermore, while most leaders feel confident they could contain a compromised mailbox within an hour, nearly half have never conducted M365 incident response testing. Finally, widespread adoption of generative AI has introduced fresh anxiety regarding data exposure.

These findings point to three urgent priority areas for banking IT security: legacy authentication removal, tabletop incident response testing, and AI governance.

The authentication picture is mixed

Authentication serves as the front door to your tenant. The survey responses indicate that peer institutions are standing at very different stages of the maturity curve—and knowing where you fall is the first step in conducting a practical M365 security assessment.

M365 Conditional Access vs. MFA-Only

Half of respondents have deployed M365 conditional access policies. This risk-based approach controls access dynamically based on physical location, device compliance, and sign-in risk scores.

However, 43% of respondents still rely solely on static MFA, and one institution was still in the process of rolling out MFA across the board.

While standard MFA remains a vital baseline control, M365 conditional access is the modern standard of care for regulated financial institutions. If your bank is relying on MFA alone, upgrading to conditional access is one of the highest-impact steps you can take to strengthen your M365 security posture.

M365 Legacy Authentication Remains a Major Gap

The findings around M365 legacy authentication are more concerning:

    • 36% have fully disabled legacy authentication protocols across their tenant.
    • 29% confirmed they have not disabled legacy protocols.
    • 36% were either unsure or answered "probably."

Legacy authentication refers to older protocols—such as POP, IMAP, and SMTP AUTH—that rely on basic credentials and cannot enforce modern MFA workflows. Cybercriminals routinely exploit this vector through automated password spraying and credential stuffing attacks. If legacy authentication is enabled, attackers can bypass your MFA protections entirely.

Because legacy protocols are one of the first things bank examiners look for, uncertainty here is itself a signal to take action. Disabling legacy protocols is a quick configuration change that immediately closes one of the most dangerous M365 security gaps.

SME Insight: Why Legacy Auth & Conditional Access Matter for Examiners

"When regulators evaluate FFIEC M365 compliance, they aren't just checking whether you bought security licensing—they are verifying whether old bypass doors are locked. Leaving legacy authentication enabled while deploying MFA is like putting a high-tech lock on your front door while leaving the back door unlatched."

Pete Stauffer, Account Executive & Cybersecurity Lead, Locknet Managed IT

Containment Confidence vs. Incident Response Preparedness

When asked how quickly they could contain a compromised mailbox, respondents expressed reasonable confidence. Roughly half estimated containment within an hour, citing vendor management support or SIEM log monitoring.

However, forensic capability—proving exactly what data an attacker accessed or exfiltrated—yielded far less certainty. Several leaders noted they would have to rely on a user reporting the issue first or run manual post-incident scans. In a regulatory context, detection capability and containment capability are distinct requirements—and examiners evaluate both.

The Testing Gap

A major disconnect surfaced between containment confidence and actual readiness:

    • 43% of respondents have never run M365 incident response testing for a mailbox compromise scenario.
    • 21% were unsure when their plan was last tested.
    • 21% had conducted an incident response test within the past 12 months.

A plan that hasn't been practiced is just a document on a shelf. For institutions aiming to satisfy FFIEC M365 compliance, tabletop exercises and documented incident testing are mandatory proofs of a functioning security program.

AI Tools Are Arriving Faster Than Governance Frameworks

The most consistent point of anxiety across Midwest financial institutions was the rapid deployment of artificial intelligence. As banks explore tools like Microsoft Copilot, managing Microsoft Copilot security risks has quickly become a top priority.

Microsoft Copilot & Data Exposure Risks

    • 57% of IT leaders do not feel confident that employees are properly trained to use AI tools safely.
    • 21% are only partially confident or actively scrambling to develop training.
    • 93% expressed explicit concern about employees using AI without understanding the underlying security and data risks.

Microsoft Copilot index-scans your entire tenant—including emails, SharePoint repositories, and Teams chats—to surface answers to user prompts. If your access permissions are overly permissive, Copilot can unintentionally expose sensitive customer data, financial records, or HR files to unauthorized staff members.

Addressing permissions cleanup and AI governance is now a core requirement for maintaining a resilient M365 security posture.

Three Immediate Steps to Strengthen Your M365 Security Posture

If you are planning your IT roadmap for the coming quarters, focus on these three high-value areas where peer institutions are most exposed:

    • Disable Legacy Authentication Immediately: Have your IT team or managed provider audit your tenant configuration this week. Disabling legacy protocols is one of the fastest, zero-cost ways to improve your M365 security posture.
    • Schedule an Incident Response Tabletop Exercise: Run a simulated walkthrough of an M365 account compromise with IT, leadership, and compliance stakeholders. Testing your response workflow is how you convert a static policy into defensible operational readiness.
    • Audit M365 Permissions Before Expanding AI: Before rolling out Copilot or similar tools, clean up SharePoint, OneDrive, and Teams access permissions. Restricting overly broad file access now protects your data before AI tools make over-shared files searchable.

FAQs About Microsoft 365 Security Posture

What is an M365 security posture?

Your M365 security posture is the overall strength of your Microsoft 365 environment's security controls, configurations, and practices. It includes authentication policies, access management, threat detection, incident response readiness, data governance, and how well each of those areas is documented and tested. For financial institutions, a strong M365 security posture also means alignment with regulatory expectations such as FFIEC guidance.

How do I assess my M365 security posture?

Start by reviewing three core areas: authentication (are conditional access policies in place and is legacy authentication disabled?), incident response (has your M365 account compromise response been tested recently?), and data governance (are M365 permissions clean enough to safely support AI tools like Copilot?). A security assessment from a Managed Security Service Provider can help identify gaps you may not see internally.

Why is legacy authentication a risk to my M365 security posture?

Legacy authentication protocols like POP, IMAP, and SMTP AUTH do not support modern MFA, which means attackers can bypass multi-factor authentication entirely using password spraying and credential stuffing. Disabling legacy authentication closes one of the most commonly exploited gaps in an M365 environment and is one of the first things auditors and regulators check.

How does Microsoft Copilot affect M365 security posture?

Microsoft Copilot draws on data across your M365 environment — emails, SharePoint files, Teams conversations — to generate responses. If permissions are overly broad or sensitive data is over-shared, Copilot can surface that information to users who shouldn't have access. Before deploying Copilot broadly, institutions should audit M365 permissions and implement governance controls to prevent accidental data exposure.

Benchmark Your Institution’s M365 Security Posture

Knowing where your security posture stands today is the fastest way to prevent a costly breach tomorrow. Whether you need to disable legacy authentication, prepare for an upcoming FFIEC audit, or clean up data permissions ahead of a Copilot deployment, Locknet Managed IT is here to help.