← All insights

Microsoft 365 and identity security

Microsoft 365 Security Starts with Identity, Not Just Email

A Microsoft 365 tenant can be productive and still expose a business through weak identity controls, excessive permissions, or overlooked persistence.

IT coordinator reviewing Microsoft 365 identity access settings on a monitor in a small office

The real Microsoft 365 security question

For many Central Florida offices, Microsoft 365 is the front door to email, files, calendars, collaboration, and business applications. The most important question is not simply whether employees use strong passwords. It is whether the business knows who and what can access its Microsoft cloud environment, how that access is verified, and how suspicious activity is investigated.

Microsoft’s current security guidance describes identity as a pressure point because attackers can gain substantial reach by compromising a user, administrator, service principal, or other non-human identity. Microsoft has also documented campaigns in which social engineering and self-service password-reset abuse were used to obtain access to Microsoft Entra ID and Microsoft 365 data. The specific campaign details do not prove that every business is being targeted, but they demonstrate why identity controls deserve priority.

What is confirmed versus uncertain

Confirmed priorities include MFA, least privilege, sign-in monitoring, secure recovery methods, and prompt removal of departing users. The exact features available depend on the organization’s Microsoft license, configuration, device platform, and integration choices.

MFA is highly valuable, but not every MFA method offers the same resistance to social engineering. A user who approves an unexpected prompt can still help an attacker. Train employees to deny unfamiliar requests and report them.

No Microsoft 365 setting removes the need for business-process controls. A fraudulent invoice, vendor change, or wire request may arrive through a legitimate compromised mailbox.

Secure the tenant administrator layer

Begin with the highest-impact accounts:

  • Identify every Global Administrator and reduce the list to people who genuinely need that role.
  • Use separate administrator accounts rather than performing daily email and web browsing with elevated privileges.
  • Require MFA for administrators and block legacy authentication where supported.
  • Review emergency or break-glass accounts, document their purpose, protect them carefully, and test access without using them for routine work.
  • Review privileged-role assignments and remove stale accounts.
  • Require approval and time limits for elevated access when the licensing and operating model support it.

Do not disable an emergency account without a tested alternative. Security changes should be documented and reviewed so that the business does not lock itself out during an outage.

Review mailbox persistence

After a mailbox is compromised, an attacker may attempt to remain hidden. Review suspicious forwarding rules, inbox rules, delegate access, new devices, unusual sign-ins, OAuth or application consent, and changes to recovery information.

Managers should know that a password reset alone may be incomplete. Active sessions, refresh tokens, delegated access, malicious applications, or forwarding rules may survive unless they are separately revoked or removed. The exact cleanup procedure should be handled by a qualified administrator or incident-response provider.

Protect SharePoint and OneDrive data

Cloud storage is not automatically organized according to least privilege. Review:

  • External sharing links and anonymous access.
  • Broad group membership and inherited permissions.
  • Sensitive folders available to entire departments.
  • Former employees’ shared files and ownership.
  • Synchronization to unmanaged personal devices.
  • Retention, recovery, and legal-hold requirements.

Use sensitivity labels, data-loss prevention, retention, and access reviews where they fit the organization’s needs and licensing. Start with the data that would cause the greatest harm if exposed or altered.

Investigate sign-ins with context

A sign-in from an unfamiliar location is not automatically proof of compromise. Travelers, mobile networks, virtual private networks, cloud services, and inaccurate geolocation can create misleading signals. Conversely, a familiar location does not prove legitimacy.

Look for combinations of evidence:

  • New device registration followed by sensitive file access.
  • Repeated MFA prompts followed by a successful login.
  • Unusual mailbox searches, downloads, forwarding, or application consent.
  • Impossible travel or unfamiliar browser and operating-system details.
  • Access outside an employee’s normal working pattern.

Use Microsoft’s available audit and sign-in logs, but understand retention limits and licensing. Configure alert ownership so notifications reach someone who can act.

Add business verification

Technology should support human controls. Require a second-person review for payment changes, use a known phone number to verify instructions, and separate the person who prepares a payment from the person who approves it. Do not treat a familiar email thread as proof that a request is genuine.

A practical review sequence

  • First, secure administrators and require MFA.
  • Second, review mailbox forwarding, delegates, applications, and external sharing.
  • Third, remove stale users and permissions.
  • Fourth, confirm logging, alert ownership, and retention.
  • Fifth, test account recovery and the response plan.

Microsoft 365 can reduce infrastructure burdens, but the business still owns many configuration and identity decisions. A secure tenant is maintained, reviewed, and adjusted as people, applications, and business processes change.

Human-reviewed draft. Guidance is general information, not legal advice.

Sources