Why Microsoft 365 is a top target
Microsoft 365 is the center of email, files, and identity for most small businesses. That makes it one of the first systems attackers probe.
In many incidents, the break-in is not a software vulnerability. It is a valid login with a stolen password, followed by quiet mailbox manipulation and fraudulent payment requests. That is why Microsoft 365 security settings matter so much: a few controls remove the easiest attack paths.
Start with identity controls
1) Require MFA for every user
This is the single highest-value control in Microsoft 365. Prioritize all users, then enforce stronger methods for admins.
- Require MFA for interactive sign-ins.
- Remove per-user exceptions unless there is a documented business case.
- Prefer phishing-resistant methods where practical.
If MFA is not universally enforced yet, fix that before spending time on lower-priority tuning. The MFA guide covers rollout sequencing.
2) Block legacy authentication
Legacy auth protocols can bypass modern controls and conditional access logic. Attackers know this and test it.
- Block legacy authentication tenant-wide.
- Allow exceptions only for approved service accounts.
- Track and retire every exception with an owner and deadline.
3) Protect administrator accounts separately
Admin identities deserve stricter policy than standard users.
- Use dedicated admin accounts (not day-to-day mail accounts).
- Enforce stronger MFA requirements for admin roles.
- Alert on privileged role assignment and sign-in anomalies.
Lock down mailbox abuse paths
4) Restrict external auto-forwarding
Compromised accounts commonly create hidden forwarding rules to exfiltrate mail. This can run for weeks before anyone notices.
- Disable automatic external forwarding by default.
- Alert on newly created forwarding rules.
- Review inbox rules and transport rules regularly.
5) Enable anti-phishing and Safe Links/Safe Attachments
Most payment fraud and credential theft starts with email. Defender policies reduce what reaches users and rewrite risky links at click time.
- Enable anti-phishing protection for all mailboxes.
- Turn on Safe Links for email and Teams where available.
- Turn on Safe Attachments with detonation/scanning.
This control set complements user training from the social engineering guide.
Improve detection and response
6) Turn on unified audit logging and alerts
Without logs, incident response is guesswork. Keep auditing enabled and wire alerts to a monitored destination.
- Verify unified audit logging is enabled.
- Alert on impossible travel, new inbox forwarding, and suspicious OAuth consent.
- Define who receives alerts and expected response times.
If your team cannot monitor this consistently, pair Microsoft 365 with managed detection workflows such as managed SIEM.
7) Review sign-in and risk events weekly
A lightweight weekly review catches issues before they become losses.
- Review failed and risky sign-ins by user and country.
- Investigate impossible-travel and unfamiliar-sign-in events.
- Confirm no unauthorized MFA method changes occurred.
- Validate that disabled accounts are actually blocked from sign-in.
Policy baseline that prevents BEC losses
Business email compromise often follows a repeatable pattern: account takeover, mailbox monitoring, and changed payment instructions near a legitimate transaction.
Your baseline should include:
- MFA for all users and admins.
- Legacy auth blocked.
- External forwarding restricted.
- Anti-phishing and Safe Links enabled.
- Payment verification policy outside email (phone callback to known numbers).
The payment verification step is operational, not technical, but it is one of the most effective controls against BEC fraud.
Common rollout mistakes to avoid
- Enabling MFA for users but not for break-glass/admin workflows.
- Turning on controls without alert routing and ownership.
- Leaving legacy exceptions undocumented.
- Treating configuration as one-time work instead of recurring maintenance.
Microsoft 365 security is not one switch. It is a baseline that needs ownership, documentation, and quarterly review.
If you want a practical implementation plan for your tenant, start with a security assessment or book a 20-minute intro call.
