Microsoft 365 Security
In order to protect your IT systems, we are currently auditing your current 365 setup and implementing many improvements to your tenant. These settings help protect your email, data, and identity — we are ultimately trying to protect you from any financial loss due to scams.
What we implement in the first round
MFA & number matching
Multi-factor authentication with number matching to prevent MFA fatigue attacks.
Authentication methods
Configured authentication methods appropriate for your organisation and security level.
Audit logs
Audit logging enabled so we can track activity and investigate any suspicious events.
Connected applications
Review and restrict which third-party applications have access to your Microsoft 365 data.
Mailbox permissions
Review and tighten mailbox permissions to prevent unauthorised access to email accounts.
Password policy
Password reset every 1 July — ensuring passwords are regularly rotated across all accounts.
OneDrive retention
OneDrive retention policies configured to protect against accidental or malicious deletion.
SharePoint permissions
SharePoint sharing settings reviewed and tightened to prevent oversharing of company documents.
External sender tag
Emails from outside your organisation are tagged with [EXTERNAL] so staff can identify them easily and avoid phishing.
Risky attachment blocking & Security Access Training
Risky attachment blocking
We are seeing .HTM files being sent to your customers that contain QR codes. These QR codes link to a fake Microsoft website where you are prompted to enter your username, password, and MFA code.
The fake website proxies to the real Microsoft servers to satisfy the MFA request. The hacker now has your MFA code and can login to your account.
Security Access Training
Security Access Training is critical for your users and may be a requirement of your insurance policy. If you are yet to accept our free offer of security training, we suggest you do so.
Conditional Access Policies
Conditional Access Policies are a powerful security feature that helps organisations control access to resources based on specific conditions. We are implementing new policies to protect you from overseas hacking attempts and for enrolling users with multi-factor authentication.
Country restrictions
Allowing access only from the countries you operate in — blocking sign-ins from overseas locations.
Requiring MFA for all users
Enforcing MFA via Conditional Access, not just the free version — including support for trusted devices and remember MFA.
Blocking legacy authentication
Blocking legacy authentication protocols that bypass modern security controls and MFA enforcement.
Key features of Azure AD Premium P1
To implement Conditional Access policies, you need Microsoft NCE Azure AD Premium P1 licences. As threats change and evolve it is important to add the corresponding protection to your Office 365 tenant.
Conditional Access
Create policies that enforce access controls based on user, device, location, risk level etc. Helps protect against unauthorised access and identity-based threats.
Multi-Factor Authentication (MFA)
Includes MFA enforcement via Conditional Access, not just the free version. Supports trusted MFA, remember MFA on trusted devices, and more.
Group-Based Access Management
Automate user access to apps and resources using dynamic groups and group-based licensing.
Company Branding
Customise the sign-in pages with your logo, background, and help links.
Security Reports & Alerts
Gain insights into risky sign-ins, leaked credentials, and more.
Microsoft Identity Protection
Detects and responds to suspicious sign-in behaviour automatically.