Why M365 Security Requires Active Configuration
Microsoft 365's default security configuration prioritizes usability and broad compatibility — not hardened security. Out of the box, M365 environments frequently lack critical protections that are available but not enabled by default. Organizations that rely on default settings are leaving significant attack surface exposed. CISA and NCSC have both published specific M365 security guidance following high-profile attacks against M365 environments.
1. Multi-Factor Authentication
Enable MFA for all accounts — no exceptions. Use Conditional Access policies (available in Azure AD P1 and above) rather than per-user MFA. Disable legacy authentication protocols (IMAP, POP3, SMTP AUTH, Basic Auth) which bypass MFA entirely and represent a critical exposure in most M365 environments.
2. Conditional Access Policies
- Require MFA for all users for all cloud apps
- Block legacy authentication protocols
- Require compliant or hybrid Azure AD joined devices for sensitive workloads
- Block access from countries where you have no legitimate business presence
- Enable sign-in risk and user risk policies through Azure AD Identity Protection (P2)
3. Email Authentication (SPF, DKIM, DMARC)
Configure SPF, DKIM, and DMARC for all sending domains. A DMARC policy of p=reject prevents your domain from being spoofed in phishing campaigns against your customers and partners. Absence of DMARC is a finding in nearly every external assessment we conduct.
4. Anti-Phishing and Anti-Malware Policies
- Enable Microsoft Defender for Office 365 (Plan 1 minimum) for Safe Links and Safe Attachments
- Configure anti-phishing policies with impersonation protection for executive accounts and key domains
- Enable "First contact safety tips" to warn users receiving email from first-time senders
- Set Safe Attachments to Dynamic Delivery to detonate attachments in a sandbox before delivery
5. Privileged Identity and Access Management
- Reduce the number of Global Administrators to the minimum necessary (2–4 maximum)
- Enable Privileged Identity Management (PIM) for just-in-time elevation of administrative roles
- Create emergency access ("break glass") accounts with strong passwords and hardware MFA, documented and monitored
- Review and remove guest accounts that are no longer active
- Audit application permissions — third-party apps with excessive OAuth permissions are a frequent attack vector
6. Audit Logging and Alerting
- Enable Unified Audit Logging and retain logs for a minimum of 90 days
- Configure alerts for suspicious sign-in activity, bulk mail deletion, unusual forwarding rules, and new admin role assignments
- Review mailbox delegation and mail forwarding rules regularly — attackers frequently establish forwarding rules for persistent access after initial compromise
Is your Microsoft 365 environment properly hardened?
Grid32's external assessments frequently identify M365 misconfigurations that create significant exposure. Find out where you stand.
Get a Quote →