Forum Discussion
Let’s Talk Security
In regards to biggest security concerns or challenges, here are a few thoughts -
Making sure new Office 365 features or changes don't weaken the security posture, see the Microsoft Teams adds third party file integration comments for an example that's been somewhat contentious
Keeping track of best practices and also the user education component, previously discussed here
Having a process and ownership, there has got be enough resources to manage security properly and having the right approach, I mention a few of these https://social.technet.microsoft.com/wiki/contents/articles/37924.microsoft-security-practical-guidance-on-preventing-cyberattacks.aspx like assume breach.
A challenge would be many of the tools now come at extra cost, which puts them out of the hands of some of the people that could most make use of them like Advanced Threat Protection, Azure Active Directory Premium, Office 365 Advanced Security Management etc.
As well, there are the usual concerns about ransomware, device proliferation, data exfiltration, targeted attacks and the like.