Most breaches we investigate start with an email and a credential. The good news is that Microsoft 365 ships with enough built-in controls to make those attacks dramatically harder, if they are turned on.
The baseline
- Phishing-resistant MFA for all administrators.
- Conditional access blocking legacy authentication.
- Defender for Office anti-phishing policies tuned to your domain.
- Safe Links and Safe Attachments enabled organization-wide.
- External email banner.
- Sender Policy Framework, DKIM, and DMARC published and enforced.
- Sensitivity labels on confidential content.
- Audit log retention extended.
- Risk-based sign-in policies via Entra ID Protection.
- Privileged Identity Management for elevated roles.
- Quarterly access reviews on shared mailboxes and group memberships.
- Restricted self-service Teams creation with a governance template.
None of this requires an upgrade beyond Business Premium or E3+E5 add-ons in most cases. The hard part is the operating discipline to keep the baseline current.
About the author. This article was written by the consulting team at Algorithm, Inc, a U.S.-based software development and digital transformation firm headquartered in Dublin, Ohio. To discuss how these ideas apply to your environment, contact us.