Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Publication · State of Microsoft 365 security in Brainport SMEs · version 2026.1

State of Microsoft 365 security in Brainport SMEs 2026: what 24 tenants showed at intake.

How secure is the average Microsoft 365 environment of an SME in the Eindhoven region at the moment an IT partner takes it over? Qteco measured 24 tenants of organisations with 25 to 500 employees between January 2025 and September 2026, each time before its own security measures were configured. The average Secure Score was 41 percent, two out of three tenants still had legacy authentication enabled, and on average 312 files per user were shared with the entire organisation.

Version 2026.1 — September 2026 Author — Qteco B.V., data Trung Nguyêñ Dúc Dataset — 24 tenants, 25 to 500 employees Period — January 2025 to September 2026
Method

How the figures were collected.

The benchmark is based on anonymised Microsoft 365 tenants of organisations from the Brainport Eindhoven ecosystem. All measurements were taken at the moment of intake, before the implementation of security measures by Qteco. Results are published exclusively as aggregated statistics.

01

Dataset

24 tenants of SMEs with 25 to 500 employees in the Brainport Eindhoven region, taken over between January 2025 and September 2026.

02

Measurement moment and sources

One measurement per tenant at intake, from Microsoft Secure Score, the Entra ID sign-in logs and role overview, the Conditional Access policies, the backup situation and the SharePoint sharing report. The Secure Score was measured again after 90 days of management.

03

Anonymisation and review

Only percentages, averages and medians across the whole dataset; no names, sectors or individual values, except for one outlier that cannot be traced. Annual review with a new version number.

Key findings

Seven figures on the starting position.

Per topic the value at intake. The percentages are the share of the 24 tenants for which the finding applied.

Finding at intake Value
Secure ScoreAverage Microsoft Secure Score at intake; median 38 percent. After 90 days of management an average of 73 percent.41 %
Legacy authenticationShare of tenants where legacy authentication (POP, IMAP, SMTP basic auth) was still active, so MFA could be bypassed.67 %
MFA administratorsShare of tenants without phishing-resistant MFA (passkeys or FIDO2) on administrator accounts.58 %
MFA usersShare of tenants without any form of MFA for standard users.29 %
Conditional AccessShare of tenants without an active Conditional Access policy.46 %
BackupShare of tenants without an independent Microsoft 365 backup outside the tenant.71 %
Global admin daily useShare of tenants with one or more global administrators who also used the same account daily for e-mail, Teams and office work.54 %
OversharingAverage number of files per user shared with "Everyone in the organisation"; median 184, highest tenant 1,924.312 per user

Comparison figure: after 90 days of management the average Secure Score was 73 percent. That figure is a measurement after the measures of the Microsoft 365 Security Baseline 2026 were configured and says something about feasibility, not about the starting position.

Conclusions

What the figures say about regional SMEs.

Seven conclusions, in the order of the findings. The last two, daily use of global admin accounts and oversharing, hardly ever appear in Microsoft or NCSC reports, while they directly determine whether an organisation is ready for zero trust and Copilot.

01

Maturity at intake is well below the recommended level

An average Secure Score of 41 percent and a median of 38 percent are considerably below what Microsoft recommends for modern cloud environments. The fact that the average stands at 73 percent after 90 days shows the gap can be closed with existing licences.

02

Legacy authentication remains a common risk factor

Two out of three tenants still had old protocols enabled. That makes every MFA effort bypassable; it is the first setting Qteco switches off at takeover.

03

MFA is widely present, phishing-resistant MFA for administrators is not

More than seven out of ten tenants had MFA for users, but at 58 percent administrators could still sign in with a method that a fake sign-in page can relay live.

04

Conditional Access is not yet configured at almost half

Without Conditional Access, MFA does not apply everywhere and an unmanaged device cannot be blocked. 46 percent of the tenants lacked this policy entirely.

05

Independent backup is the exception rather than the rule

71 percent relied on the recycle bin and Microsoft's retention periods. With ransomware through a stolen account or a deleted mailbox there is then no restore point.

06

Privileged access management is applied to a limited extent

At 54 percent of the tenants at least one global admin worked daily with that account. One phishing e-mail to that account is then a complete takeover.

07

Oversharing is the key concern before Copilot

An average of 312 widely shared files per user, with an outlier of 1,924. Copilot makes everything "everyone in the organisation" may see directly searchable; without clean-up and labels, sensitive information surfaces.

From figure to measure

Which baseline measure removes each finding.

The seven findings map one to one onto the Microsoft 365 Security Baseline 2026. That makes the benchmark a priority list as well.

Finding Measure in the baseline
Secure Score 41 %No periodic measurement and follow-up11 Secure Score monthly, at least 70 %
Legacy auth 67 %Old protocols bypass MFA02 Legacy authentication blocked
MFA 58 % / 29 %No phishing-resistant MFA for administrators, no MFA for users01 MFA for everyone, passkeys for administrators
Conditional Access 46 %No policy on identity and device04 Only managed and healthy devices
Backup 71 %No restore point outside the tenant08 Independent, immutable backup
Global admin 54 %Administration and daily work on one account03 Separate admin accounts and least privilege
Oversharing 312Files widely shared, no labels09 External sharing restricted and sensitive data labelled

The full list with the reason, the setting and the evidence per measure is in the publication Microsoft 365 Security Baseline 2026.

FAQ

Frequently asked questions about this benchmark.

What is a good Microsoft Secure Score for an SME?

Qteco uses a minimum of 70 percent as the floor for a managed tenant; the 24 tenants in this benchmark averaged 41 percent at intake and 73 percent after 90 days of management. The score is not a goal in itself, but a measure of how many of the recommended measures are actually enabled.

Why is legacy authentication such a big risk when MFA is already enabled?

Old protocols such as POP, IMAP and SMTP basic auth do not support MFA. As long as they are enabled, an attacker can sign in with just a password, however well MFA is configured for the rest. This was the case at 67 percent of the tenants at intake.

What is oversharing and why does it matter before Copilot?

Oversharing means files are visible to more people than necessary, usually through the sharing setting "Everyone in the organisation". Without Copilot that hardly shows; with Copilot everything a user may see becomes searchable and summarisable. An average of 312 such files per user means salary overviews or contracts can surface in an answer.

Are these figures representative for the whole of the Netherlands?

No, the dataset is limited to 24 tenants of organisations with 25 to 500 employees in the Brainport Eindhoven region, taken over between January 2025 and September 2026. It is a regional sample from the practice of one MSP, not a national survey. The figures are consistent with what Microsoft and the Dutch NCSC describe in broader reports.

Can the figures be traced to Qteco's clients?

No. All values are percentages, averages and medians across the whole dataset. No names, sectors, employee counts per tenant or individual scores are published. The only single value, the highest oversharing measurement, cannot be traced without context.

How often is this benchmark repeated?

Annually, with a new version number and a larger dataset as more tenants are taken over. Changes are listed at the bottom of this page. Always cite with the version number and the measurement period.

Citing and reuse

How to cite this publication.

This benchmark is published under the Creative Commons Attribution 4.0 International licence (CC BY 4.0): you may share, adapt and quote it, including commercially, as long as you credit Qteco and state the version number. Changes per version are listed alongside.

Qteco B.V. (2026). State of Microsoft 365 security in Brainport SMEs 2026, version 2026.1. Eindhoven. https://qteco.nl/en/staat-microsoft-365-beveiliging-brainport-mkb. Licence: CC BY 4.0.

2026.1

September 2026, first public version

Seven key findings on 24 tenants (January 2025 to September 2026), conclusions, mapping to the Microsoft 365 Security Baseline 2026, FAQ. Data: Trung Nguyêñ Dúc, Head of Technology.

Your own figures

Find out where your organisation stands compared with these 24.

The free Microsoft 365 security check tests the key points from this benchmark in 2 minutes. Or request an intake measurement: the same seven figures, for your own tenant.