Software-as-a-Service has fundamentally changed how businesses consume technology. Instead of buying servers and installing software, organizations subscribe to platforms like Microsoft 365, Salesforce, Slack, and dozens of specialized tools. This shift eliminates infrastructure management, but it also creates a new and complex security surface — one where your data lives on servers you don't control, accessed by identities you may not fully manage, and connected to third-party applications you might not even know exist. For SMBs in the Vancouver and Portland area, SaaS security is no longer optional — it's a core business risk that requires deliberate attention. This post covers the security considerations every organization should evaluate when adopting or expanding SaaS platforms.
Understanding SaaS Data Ownership and Portability
When you put data into a SaaS platform, the first question should be: who owns it, and can you get it out? Most major SaaS providers specify in their terms that you retain ownership of your data, but ownership and control are different things. If you decide to leave a platform, can you export all your data in a usable format? Is there a documented export API or bulk download capability? Some platforms make export difficult by design, locking data in proprietary formats or charging substantial fees for data extraction.
For Microsoft 365, Microsoft provides clear data portability — Exchange mailboxes can be exported as PST files, SharePoint sites can be exported, and OneDrive content downloads directly. But for specialized SaaS tools, the story varies. Before committing to any SaaS platform, evaluate the export capabilities, document the process, and test it. Run a trial export to verify the data is complete and usable. This isn't paranoia — it's business continuity planning. If a vendor raises prices dramatically, changes terms, or experiences a prolonged outage, you need a realistic exit path.
Access Control, SSO, and the Shadow SaaS Problem
Access control in SaaS environments starts with identity. Every SaaS platform should ideally authenticate users through a central identity provider rather than maintaining its own username and password database. Single sign-on (SSO) through Azure Active Directory (now Microsoft Entra ID) or a similar IdP gives you centralized control — when an employee leaves, you disable one account and they lose access to every connected platform simultaneously. Without SSO, you're relying on each individual SaaS admin to remember to deprovision departing users, which is unreliable at best.
Shadow SaaS — SaaS tools adopted without IT knowledge — compounds the access control problem. Employees use their work email to sign up for tools, sometimes connecting them to company data sources, and IT has no visibility. A marketing team connecting a CRM to an unapproved analytics platform, for example, creates a data pipeline that bypasses your security controls. To address this, use Microsoft Defender for Cloud Apps (included in Microsoft 365 E5 or available as an add-on) to discover which SaaS platforms users are accessing with their Entra ID credentials. The discovery logs reveal every application authenticating against your tenant, giving you a complete inventory of sanctioned and unsanctioned tools. From there, you can formally sanction the useful ones, block the risky ones, and establish a review process for new additions.
Data Residency, Compliance, and Third-Party App Permissions
Where your SaaS data physically lives matters for compliance. Microsoft 365 stores data in specific geographic regions based on tenant configuration, and for most US-based SMBs, data stays in North American datacenters. But not all SaaS platforms are equally transparent about data location. Some smaller or international vendors may store or process data in regions that conflict with industry-specific compliance requirements — healthcare (HIPAA), government contracts (CMMC), or financial services. Before adopting any SaaS tool that will store sensitive data, verify the data residency commitments in the vendor's DPA (Data Processing Addendum) and confirm it aligns with your compliance obligations.
Third-party app permissions are a frequently overlooked risk. Many SaaS platforms support an ecosystem of add-on applications — think of the extensions available in SharePoint, the integrations in Slack, or the marketplace apps in Salesforce. When users grant these apps access, they often authorize broad permissions: read access to all files, ability to send emails on behalf of the user, or access to contact lists. Each connected app is a potential data exfiltration path. Audit the connected applications in your Microsoft 365 tenant through the Entra admin center — review which apps have been granted consent, what permissions they hold, and whether those permissions are still justified. Remove apps that are no longer used, and configure admin consent policies so users cannot grant broad permissions to unverified applications without IT approval.
Audit Logging and Microsoft 365 Security Features
Audit logging in SaaS platforms is essential for detecting and investigating security incidents. Without logs, you cannot answer basic questions: who accessed a sensitive document, when was a sharing link created, who changed a permission level, or when did a user download a large volume of data? Microsoft 365 maintains a unified audit log that captures actions across Exchange, SharePoint, OneDrive, Teams, and Entra ID. The audit log is enabled by default in most tenants, but the retention period varies by license — Business Premium retains 180 days, E5 retains one year. For organizations with compliance requirements, consider whether the default retention is sufficient or whether you need extended retention.
Beyond audit logging, Microsoft 365 includes several security features that many organizations leave underconfigured. Conditional Access policies let you restrict access based on device compliance, location, or risk level — for example, blocking logins from unknown locations or requiring compliant devices for access to sensitive SharePoint sites. Safe Links and Safe Attachments (part of Defender for Office 365) scan email links and attachments in real time. Data Loss Prevention (DLP) policies can prevent users from sharing sensitive information like Social Security numbers or credit card data through email or Teams. Multi-factor authentication enforcement through Entra ID is the single most impactful security control — if you haven't enabled MFA for all users and all authentication methods, this should be your first priority.
Conclusion: SaaS Security Is Shared Responsibility
SaaS security operates on a shared responsibility model. The vendor secures the platform infrastructure, but you are responsible for configuring access controls, managing permissions, monitoring for threats, and ensuring compliance. Too many organizations assume that because Microsoft or Google secures the underlying platform, their data is automatically safe — it is not. Misconfigured sharing settings, orphaned user accounts, over-permissioned third-party apps, and absent audit logging create real vulnerabilities that the platform provider cannot fix for you. Take ownership of your SaaS security configuration, review it regularly, and document your controls.
Beawit Consulting provides IT services to SMBs in the Vancouver/Portland metro area, specializing in Azure, M365, hybrid cloud, and network engineering. We help organizations assess and strengthen their SaaS security posture through M365 security baselines, conditional access policy design, and SaaS environment audits.
Looking for reliable internet connectivity for your business? Use our Scout lookup tool to search available options from over 75 providers, including AT&T, Comcast, Cox, Crown Castle, Fidium, Frontier, Lumen, Spectrum, Verizon, and Zayo — with instant pricing proposals and contracts.
Contact us at contactus@beawit.net or (360) 399-6834 to discuss your SaaS security needs.