Microsoft 365 is the backbone of most small and mid-sized businesses in Australia. It is also, for the same reason, the single most attacked thing they own. An attacker who gets into one mailbox gets your contacts, your invoices, your contracts and a trusted place to send email from.
The good news is that the highest-value fixes are configuration, not spend. Here is what we change first, and why.
1. Multi-factor authentication, on everyone
This is not a surprise, but it is worth being precise about two things people get wrong.
It has to cover everyone, including the accounts nobody thinks about. The shared accounts@ mailbox, the director who travels, the contractor from last year. Attackers look for the one account without it.
Not all MFA is equal. SMS codes are far better than nothing, but they can be intercepted and they are phishable. An authenticator app is better. Number matching, which makes the user type a number shown on screen rather than just tapping approve, defeats the “MFA fatigue” trick where an attacker spams prompts until someone taps yes to make it stop.
2. Turn off legacy authentication
Old protocols such as POP, IMAP and SMTP AUTH were designed before MFA existed and cannot enforce it. If they are enabled, an attacker with a valid password can often bypass your MFA entirely by connecting over one of them.
Blocking legacy authentication is one of the highest-value changes available. Check what still uses it first, because occasionally an old scanner or line-of-business app depends on it, and plan those out rather than breaking them on a Friday afternoon.
3. Watch for mailbox rules and forwarding
This is the part most businesses miss, and it is how invoice fraud actually plays out.
Once inside a mailbox, a common move is to create an inbox rule that quietly moves messages containing words such as “invoice”, “payment” or “bank” into an obscure folder, or auto-forwards them outside the organisation. The real user never sees the conversation. The attacker replies from the middle of a genuine email thread, with correct context and history, and asks the client to update payment details.
Two changes help enormously: block automatic external forwarding by default, and alert on new inbox rules that forward or delete. Both are quick.
4. Restrict who can consent to apps
By default, users can often grant third-party applications access to their mailbox and files. Consent phishing abuses this: rather than steal a password, the attacker asks the user to approve an app, and the resulting access survives a password reset.
Require admin approval for app consent, or at minimum restrict it to verified publishers.
5. Know your admin accounts
Global Administrator should be rare, deliberate, and not used for day-to-day email. If your everyday account is also a Global Admin, one successful phish hands over the whole tenant. Separate the roles.
6. Retention and recovery
Deleted items and mailboxes do not last forever by default, and a determined intruder will clear their tracks. Understand your retention settings before you need them, not after. Note that this is about being able to reconstruct what happened as much as it is about recovering data.
7. Actually look at the alerts
Enabling alerts and sending them to a mailbox nobody reads is a common outcome. Decide who reads them, and what they do when one fires. A control nobody monitors is a control you do not have.
The honest summary
None of this requires additional licensing in most cases. It requires an afternoon, a change record, and someone who knows which settings break things if you flip them carelessly. The difference between a default tenant and a hardened one is the difference between a phished password being an incident and being a catastrophe.
Want a review of your Microsoft 365 tenant against these and the rest of the baseline, with a plain-English list of what to fix and in what order? Get in touch.