State of Microsoft 365 security in Brainport SMEs 2026: what 24 tenants showed at intake.
How secure is the average Microsoft 365 environment of an SME in the Eindhoven region at the moment an IT partner takes it over? Qteco measured 24 tenants of organisations with 25 to 500 employees between January 2025 and September 2026, each time before its own security measures were configured. The average Secure Score was 41 percent, two out of three tenants still had legacy authentication enabled, and on average 312 files per user were shared with the entire organisation.
How the figures were collected.
The benchmark is based on anonymised Microsoft 365 tenants of organisations from the Brainport Eindhoven ecosystem. All measurements were taken at the moment of intake, before the implementation of security measures by Qteco. Results are published exclusively as aggregated statistics.
Dataset
24 tenants of SMEs with 25 to 500 employees in the Brainport Eindhoven region, taken over between January 2025 and September 2026.
Measurement moment and sources
One measurement per tenant at intake, from Microsoft Secure Score, the Entra ID sign-in logs and role overview, the Conditional Access policies, the backup situation and the SharePoint sharing report. The Secure Score was measured again after 90 days of management.
Anonymisation and review
Only percentages, averages and medians across the whole dataset; no names, sectors or individual values, except for one outlier that cannot be traced. Annual review with a new version number.
Seven figures on the starting position.
Per topic the value at intake. The percentages are the share of the 24 tenants for which the finding applied.
Comparison figure: after 90 days of management the average Secure Score was 73 percent. That figure is a measurement after the measures of the Microsoft 365 Security Baseline 2026 were configured and says something about feasibility, not about the starting position.
What the figures say about regional SMEs.
Seven conclusions, in the order of the findings. The last two, daily use of global admin accounts and oversharing, hardly ever appear in Microsoft or NCSC reports, while they directly determine whether an organisation is ready for zero trust and Copilot.
Maturity at intake is well below the recommended level
An average Secure Score of 41 percent and a median of 38 percent are considerably below what Microsoft recommends for modern cloud environments. The fact that the average stands at 73 percent after 90 days shows the gap can be closed with existing licences.
Legacy authentication remains a common risk factor
Two out of three tenants still had old protocols enabled. That makes every MFA effort bypassable; it is the first setting Qteco switches off at takeover.
MFA is widely present, phishing-resistant MFA for administrators is not
More than seven out of ten tenants had MFA for users, but at 58 percent administrators could still sign in with a method that a fake sign-in page can relay live.
Conditional Access is not yet configured at almost half
Without Conditional Access, MFA does not apply everywhere and an unmanaged device cannot be blocked. 46 percent of the tenants lacked this policy entirely.
Independent backup is the exception rather than the rule
71 percent relied on the recycle bin and Microsoft's retention periods. With ransomware through a stolen account or a deleted mailbox there is then no restore point.
Privileged access management is applied to a limited extent
At 54 percent of the tenants at least one global admin worked daily with that account. One phishing e-mail to that account is then a complete takeover.
Oversharing is the key concern before Copilot
An average of 312 widely shared files per user, with an outlier of 1,924. Copilot makes everything "everyone in the organisation" may see directly searchable; without clean-up and labels, sensitive information surfaces.
Which baseline measure removes each finding.
The seven findings map one to one onto the Microsoft 365 Security Baseline 2026. That makes the benchmark a priority list as well.
The full list with the reason, the setting and the evidence per measure is in the publication Microsoft 365 Security Baseline 2026.
Frequently asked questions about this benchmark.
What is a good Microsoft Secure Score for an SME?
Qteco uses a minimum of 70 percent as the floor for a managed tenant; the 24 tenants in this benchmark averaged 41 percent at intake and 73 percent after 90 days of management. The score is not a goal in itself, but a measure of how many of the recommended measures are actually enabled.
Why is legacy authentication such a big risk when MFA is already enabled?
Old protocols such as POP, IMAP and SMTP basic auth do not support MFA. As long as they are enabled, an attacker can sign in with just a password, however well MFA is configured for the rest. This was the case at 67 percent of the tenants at intake.
What is oversharing and why does it matter before Copilot?
Oversharing means files are visible to more people than necessary, usually through the sharing setting "Everyone in the organisation". Without Copilot that hardly shows; with Copilot everything a user may see becomes searchable and summarisable. An average of 312 such files per user means salary overviews or contracts can surface in an answer.
Are these figures representative for the whole of the Netherlands?
No, the dataset is limited to 24 tenants of organisations with 25 to 500 employees in the Brainport Eindhoven region, taken over between January 2025 and September 2026. It is a regional sample from the practice of one MSP, not a national survey. The figures are consistent with what Microsoft and the Dutch NCSC describe in broader reports.
Can the figures be traced to Qteco's clients?
No. All values are percentages, averages and medians across the whole dataset. No names, sectors, employee counts per tenant or individual scores are published. The only single value, the highest oversharing measurement, cannot be traced without context.
How often is this benchmark repeated?
Annually, with a new version number and a larger dataset as more tenants are taken over. Changes are listed at the bottom of this page. Always cite with the version number and the measurement period.
How to cite this publication.
This benchmark is published under the Creative Commons Attribution 4.0 International licence (CC BY 4.0): you may share, adapt and quote it, including commercially, as long as you credit Qteco and state the version number. Changes per version are listed alongside.
Qteco B.V. (2026). State of Microsoft 365 security in Brainport SMEs 2026, version 2026.1. Eindhoven. https://qteco.nl/en/staat-microsoft-365-beveiliging-brainport-mkb. Licence: CC BY 4.0.
September 2026, first public version
Seven key findings on 24 tenants (January 2025 to September 2026), conclusions, mapping to the Microsoft 365 Security Baseline 2026, FAQ. Data: Trung Nguyêñ Dúc, Head of Technology.
Find out where your organisation stands compared with these 24.
The free Microsoft 365 security check tests the key points from this benchmark in 2 minutes. Or request an intake measurement: the same seven figures, for your own tenant.
