Protecting the tenant.
WHAT TO ENABLE FIRST
Multi-factor authentication for every account.
WHY
It prevents the large majority of account compromises.
WHAT TO ENABLE FOR ADMINISTRATORS SPECIFICALLY
Stronger requirements, and separate accounts from daily use.
WHY SEPARATE ACCOUNTS
So an administrative account is not exposed to browsing and email.
WHAT TO CONFIGURE
Policies controlling under what conditions sign-in is permitted Restrictions on legacy authentication methods that bypass modern protection Protection against malicious links and attachments Alerting on suspicious activity
WHY LEGACY AUTHENTICATION MATTERS
Older protocols do not support additional factors, and are used precisely for that reason.
WHAT TO REVIEW
Which applications have been granted access to organisational data Administrative role assignments Guest accounts
WHY THAT FIRST ONE
Users can consent to applications accessing data, and malicious applications exploit this.
WHAT TO RESTRICT
User consent, to verified applications or to none.
WHAT TO MONITOR
Sign-in activity Mailbox rule creation Mass file downloads
WHAT TO PREPARE
A response procedure for a compromised account.