Microsoft 365 Security
Hardening the Microsoft 365 environment most businesses already run, email, files, and Teams, against the defaults it shipped with.
Who this is for: Businesses running Microsoft 365 who set it up once, years ago, and haven’t revisited the security settings since.
The Problem
Microsoft 365 ships secure-enough to work, not secure by default, conditional access, mailbox forwarding rules, and sharing settings are usually left exactly as they came out of the box.
Our Solution
We harden the settings that actually matter, conditional access, MFA enforcement, mail flow rules, and external sharing, against Microsoft’s own security baseline.
What's included
- Conditional access policy setup and review
- MFA enforcement across all accounts, not just admins
- Mail flow rule audit (a common place attackers hide forwarding rules after a compromise)
- SharePoint and OneDrive external sharing review
- Admin role and privileged access review
- Microsoft Secure Score baseline and improvement plan
Microsoft 365 ships secure-enough to work, not secure by default. Conditional access, mailbox forwarding rules, and external sharing settings are usually left exactly as they came out of the box, which is precisely where we find business email compromise incidents start.
We hardened this environment for a client after a near-miss wire-fraud attempt, see the full case study, and it’s consistently one of the highest-value, lowest-disruption engagements we run.
Benefits
- Closed the mailbox-forwarding-rule trick attackers use after a compromise
- Consistent MFA enforcement instead of partial coverage
- A documented Secure Score baseline to track improvement against
Our Process
Audit
Review current tenant configuration and Secure Score.
Harden
Configure conditional access, MFA, and mail flow rules.
Review Sharing
Lock down over-permissive external sharing.
Document
Leave a baseline configuration for future reference.
Monitor
Ongoing review as Microsoft changes defaults over time.
Proven results: See how a compromised mailbox almost redirected a $40,000 wire transfer. See the write-up →
Frequently asked questions
Will this disrupt how our team currently uses Microsoft 365?
Changes are planned around your team’s actual workflow, most hardening (like conditional access and mail flow rules) is invisible to end users day-to-day.
Do you also cover Google Workspace?
Our primary focus is Microsoft 365, but the same underlying principles, MFA enforcement, mail flow review, sharing audits, apply to Google Workspace; contact us to discuss your specific environment.
Especially relevant for
Related services
Network Security
Protecting your network infrastructure, from the firewall edge to individual devices, from unauthorized access and lateral spread.
cloud_lockCloud Security
Securing your cloud environment against breaches, threats, and misconfigurations.
vpn_lockRemote Access Security
Getting remote access to your systems right, reachable when you need it, closed to everyone else.
Not sure if this is the right fit?
Tell us what's worrying you. We'll tell you what actually needs fixing first.