Skip to main content
SpaceNet Cybersécurité
FR EN
Request a consultation

Cloud 1 min read

Microsoft 365: the eight settings behind most compromises

A well-run configuration review costs far less than an incident response engagement.

By SpaceNet

In most of the Microsoft 365 compromises we analyze, the attacker exploited no vulnerability at all: they took advantage of a setting left at its default.

Settings to check first

  1. Multi-factor authentication enforced on every account, no exceptions
  2. Legacy authentication protocols disabled
  3. Admin accounts separated from mailbox accounts
  4. Unified audit log enabled and retained
  5. Automatic forwarding to external addresses blocked
  6. User consent to third-party apps restricted
  7. Conditional access by country and device state
  8. Alerts on suspicious inbox rule creation

None of these settings requires an extra licence for most organizations. They mostly require someone to take the time to check them.

References: CIS Microsoft 365 Foundations Benchmark; Microsoft Cloud Security Benchmark.