Microsoft 365: the eight settings behind most compromises
A well-run configuration review costs far less than an incident response engagement.
By SpaceNet
In most of the Microsoft 365 compromises we analyze, the attacker exploited no vulnerability at all: they took advantage of a setting left at its default.
Settings to check first
- Multi-factor authentication enforced on every account, no exceptions
- Legacy authentication protocols disabled
- Admin accounts separated from mailbox accounts
- Unified audit log enabled and retained
- Automatic forwarding to external addresses blocked
- User consent to third-party apps restricted
- Conditional access by country and device state
- Alerts on suspicious inbox rule creation
None of these settings requires an extra licence for most organizations. They mostly require someone to take the time to check them.
References: CIS Microsoft 365 Foundations Benchmark; Microsoft Cloud Security Benchmark.