Attackers are not breaking through your firewall. They are walking through the front door of your Microsoft 365 or Google Workspace account – using misconfigured admin settings, unreviewed delegated email permissions, and global admin accounts with nothing protecting them. If you believe your cloud email is secure because it comes from Microsoft or Google, read this before your next board meeting.
Table of Contents
- What Is Happening in 2025
- The Three Attack Vectors Driving This Surge
- Why the Cloud Vendor Cannot Save You
- What a Well-Run IT Environment Looks Like
- The CEO Blind Spot That Makes This Worse
- What This Means for Small Businesses in South Jersey and Beyond
- How to Assess Your Cloud Identity Attack Risk Today
- The Bottom Line
What Is Happening in 2025

The Cybersecurity and Infrastructure Security Agency has issued multiple advisories in 2025 documenting a coordinated wave of campaigns targeting cloud productivity suite configurations. The CISA cyber threat advisory center reflects a clear shift in attacker focus: rather than targeting endpoint devices or on-premises servers, threat actors are going straight for the identity layer of cloud platforms.
This is not accidental. Over the past five years, most small businesses have moved the majority of their critical operations into Microsoft 365 or Google Workspace. Email, calendars, documents, financial workflows, HR records, and AI-assisted tooling all live inside these environments. Attackers go where the data is.
What makes 2025 different is the efficiency of these campaigns. These are not random phishing attempts. They are methodical operations designed to find and exploit specific administrative misconfigurations that are extraordinarily common in small business cloud tenants. Knowing how these attacks work is the first step toward closing the gaps that make them possible.
The Three Attack Vectors Driving This Surge in Cloud Identity Attacks
Three specific abuse patterns appear repeatedly across public incident disclosures and federal advisories. Each one is worth understanding clearly.
1. Delegated Email Access Abuse
Delegated email access is a legitimate feature. It allows one user – often an executive assistant or IT administrator – to read, send, and manage email on behalf of another user. In a properly governed environment, this access is granted selectively, logged, and reviewed regularly.
In most small business tenants, it is granted once and never revisited. Former employees, vendors who no longer work with the company, and accounts that no longer exist as active users can retain delegated access to an executive’s inbox for months or years after the original business reason ended.
An attacker who compromises any one of those delegated accounts gains silent, persistent access to high-value executive communications – without ever touching the executive’s own credentials. They can read emails, send messages that appear to come from the executive, and monitor ongoing business negotiations, financial instructions, or client communications.
2. OAuth Application Permission Abuse
OAuth is the mechanism that allows third-party applications to connect to your Microsoft 365 or Google Workspace environment. When someone on your team clicks “Connect to Google” or “Allow access” inside a business application, they grant that application a set of permissions – sometimes quite broad ones – inside your cloud environment.
Those permissions persist indefinitely unless someone explicitly revokes them. Most small business tenants have dozens of connected applications, many of which are no longer actively used. Some were granted by employees who have since left the company. A small number were granted by employees who clicked through a malicious authorization prompt without understanding what they were approving.
Attackers exploit this in two ways. First, they run phishing campaigns specifically designed to trick employees into granting permissions to malicious applications. Second, once they gain any foothold inside your environment, they register their own application and grant it persistent access – creating a backdoor that survives even a full password reset on the compromised account.
3. Global Admin Accounts With No Secondary Controls
This is the most dangerous misconfiguration – and the most common. The global administrator account in Microsoft 365 or Google Workspace has unrestricted access to every user, every setting, every piece of data, and every security control in your environment.
In a well-governed environment, global admin accounts are used only when absolutely necessary, protected by the strongest available authentication methods, monitored for unusual sign-in activity, and never used as a day-to-day working account. In the typical small business tenant, the global admin account belongs to whoever set the platform up – often a former employee, a departed vendor, or the business owner using their primary email address – with nothing else protecting it.
A threat actor who compromises a global admin account needs nothing else. They can disable security settings, create new accounts, access every user’s mailbox, export your entire directory, and cover their tracks – all from within the platform’s own administrative interface, using tools that look identical to legitimate administrator activity.
Why the Cloud Vendor Cannot Save You From Cloud Identity Attacks
This is the part that surprises most business owners. Microsoft and Google build the platforms. They do not govern how you configure them. When a threat actor abuses a legitimately granted permission, that activity does not look like an attack to the platform – it looks like authorized usage, because from the platform’s perspective, it is.
Microsoft and Google provide the tools needed to secure these environments properly. What they cannot do is apply those tools on your behalf. Configuration and governance are entirely the responsibility of whoever manages your tenant.
Paying for Microsoft 365 Business Premium or Google Workspace Business Plus gives you access to security features. It does not mean those features are turned on, properly configured, or monitored. Most small business tenants are running on default settings established at initial deployment that have not been revisited since.
What a Well-Run IT Environment Actually Looks Like
An environment hardened against cloud identity attacks looks meaningfully different from what most small businesses have in place. The differences are not exotic or expensive – they are disciplined and consistent.
In a properly governed Microsoft 365 or Google Workspace tenant, you would find:
- Multi-factor authentication enforced for every user, without exceptions – including executives who find it inconvenient
- Global admin accounts that are separate from day-to-day working accounts and protected by the strongest available authentication methods
- Delegated email access permissions that are documented, regularly reviewed, and revoked the moment the business reason ends
- A current inventory of all connected third-party applications and the specific permissions each one holds
- Conditional access policies that flag or block sign-in attempts from unexpected locations, devices, or behavioral patterns
- Alerts that notify a human being when a new admin account is created, global admin permissions are granted, or a bulk email export is initiated
- A regular review cycle – at minimum quarterly – of all of the above
None of these controls are new. All of them are available within the platforms most small businesses are already paying for. The gap is not capability – it is governance. And governance is what a disciplined managed IT relationship is built to provide on an ongoing basis.
At Xact IT, cloud identity governance is a standard part of how we manage client environments. Our cybersecurity practice covers the configuration layer, not just the perimeter – because as 2025 has made clear, the perimeter is no longer where the fight is happening.
The CEO Blind Spot That Makes This Worse
There is a specific reasoning trap that makes small business owners particularly vulnerable. It goes like this: “We use Microsoft. Microsoft is a massive company with enormous security resources. Therefore our email is secure.”
That reasoning is understandable. It is also wrong. Microsoft’s security resources protect Microsoft’s infrastructure. Your tenant configuration is your responsibility.
The analogy that holds: a commercial landlord can build the most secure office building in the world – thick walls, reinforced doors, monitored access points. But if the tenant leaves a master key hanging on a hook by the front desk, none of that matters. The threat actor does not breach the building. They take the key.
In 2025’s cloud identity attack campaigns, the “key” is almost always a misconfigured administrative setting, an unreviewed delegated permission, or a global admin account with no secondary controls. These are tenant-level configurations, not platform-level vulnerabilities. The fix lives with whoever governs your environment.
What This Means for Small Businesses in South Jersey and Beyond
Attackers running cloud identity campaigns are not selecting targets by geography. They scan for misconfigured tenants at scale, across every region. A 15-person professional services firm in Marlton, NJ has the same exposure as a comparable firm in Austin or Atlanta – and the same likelihood of appearing in an automated scan for vulnerable permissions or unprotected admin accounts.
The businesses most at risk share a common profile:
- Microsoft 365 or Google Workspace tenants set up by a vendor or generalist who is no longer engaged
- No current IT oversight or regular configuration review
- Executive accounts that hold global admin permissions alongside their normal working email
- Third-party application integrations approved years ago and never audited since
- Multi-factor authentication enabled for some users but not enforced universally
This profile fits a large percentage of small businesses in the South Jersey market and across the Philadelphia metro. The technical barriers to securing these environments are low. The organizational will to make it a priority – before an incident forces the issue – is usually the harder challenge.
We have operated in this market since 2004. In that time, not one client environment under our management has experienced a breach. That record is not luck. It is the difference between a cloud environment that is actively governed and one that is merely subscribed to.
For additional context on how cloud identity security fits into your broader IT posture, our managed IT services page outlines how ongoing configuration oversight works as part of a complete security program for small and mid-size businesses.
How to Assess Your Cloud Identity Attack Risk Today
Most small business owners do not know whether their Microsoft 365 or Google Workspace tenant is properly hardened – because no one has ever walked them through what that actually means. Here is a starting framework for an honest self-assessment.
Start with your global administrator account. Log into your Microsoft 365 admin center or Google Workspace admin console and identify every account that currently holds global or super administrator privileges. If more than two accounts hold that level of access – or if any belong to former employees or vendors – that is an immediate priority item.
Next, pull a list of all connected applications. In Microsoft 365, this is visible under Azure Active Directory > Enterprise Applications. In Google Workspace, it is available under Security > API Controls > App Access Control. Review each application, confirm it is still actively used, and verify the permissions it holds are appropriate for its function. Any application you cannot account for should be revoked immediately.
Then audit delegated email access. In Microsoft 365, mailbox delegation is visible in the Exchange admin center under Mailboxes > Mailbox Delegation. In Google Workspace, delegation is managed at the individual account level under Gmail settings. Any delegation that cannot be tied to a current, active business relationship should be removed.
Finally, verify that multi-factor authentication is not just enabled but enforced through a conditional access policy – one that makes it impossible to bypass. Authentication that is available but optional provides significantly less protection than authentication that is required without exception.
This audit is not a one-time exercise. Cloud identity attacks succeed precisely because small business tenants treat initial configuration as permanent. The environments that stay secure treat governance as an ongoing operational discipline, not a setup task completed at launch. If conducting this audit internally is not feasible, engaging a managed IT provider with direct experience in cloud identity security is the most efficient path to closing the gap.
If you want a second set of eyes on your tenant configuration, Book a Free Cybersecurity Strategy Call with our team. It is a 20-minute conversation – no sales pressure, no obligation – and you will leave with a clear picture of where your environment stands.
The Bottom Line
The 2025 surge in cloud identity attacks is not a story about sophisticated exploits or capabilities beyond the reach of ordinary businesses. It is a story about attackers finding that small business cloud tenants are largely ungoverned below the surface – and that ungoverned environments are easy to walk through quietly.
Microsoft 365 and Google Workspace are not the problem. They are mature platforms with strong security tooling built in. The problem is the gap between what those platforms can do and what most small business tenants have actually configured. That gap is where cloud identity attacks live in 2025 – and closing it is less a technology project than a governance one.
The businesses that get through this period without a damaging incident are the ones with someone actively watching their administrative configuration, reviewing permissions on a regular cadence, and treating cloud identity governance as an ongoing operational responsibility – not a one-time setup task. That is exactly what a well-run managed IT relationship delivers. No drama. No board-level surprises. No breaches.
Frustrated With Your Current IT Provider?
If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.