Microsoft 365 is the most attacked service in the fleet we monitor, and at the same time the one with the most free hardening headroom. This guide collects the seven controls we review first in any assessment, with the concrete attack each one cuts.
THE SEVEN CONTROLS
- Conditional access with geo and legacy-auth blocking, cuts password spraying from anonymous infrastructure.
- Number matching and context in MFA, cuts MFA fatigue.
- Disable external auto-forwarding, cuts silent exfiltration after a mailbox compromise.
- Restrict OAuth app consent to admins, cuts consent phishing.
- Direct Send restricted or disabled, cuts internal spoofing that skips the filters.
- Unified audit enabled and retained 180+ days, without it there is no investigation.
- Quarterly review of mailbox rules and delegations, the favorite persistence mechanism after stealing an account.
The pattern behind all seven
None of these controls is exotic. The pattern repeating across incidents is always the same: the organization had the license, the feature existed and nobody had turned it on. M365 hardening is not a project, it’s an afternoon of configuration and a quarterly review.
FOR REGULATED ENTITIES
These seven controls map directly to the Dominican financial-sector cybersecurity regulation and to controls A.5 and A.8 of ISO 27001:2022. The configuration evidence works as-is for the auditor’s dossier.
The license already included it. Nobody had turned it on.
If you want to validate where your tenant stands today, a controls assessment starts exactly here: real configuration against these seven points, with evidence and a prioritized closure plan.