A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Enable Microsoft Entra ID Identity Protection sign-in risk policies
Enable Microsoft Entra ID Identity Protection user risk policies
Ensure 'External sharing' of calendars is not available
Ensure additional storage providers are restricted in Outlook on the web
Ensure all forms of mail forwarding are blocked and/or disabled
Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains
Ensure MailTips are enabled for end users
Ensure mailbox auditing for all users is Enabled
Ensure Exchange Online Spam Policies are set to notify administrators
Ensure users installing Outlook add-ins is not allowed
Publish M365 sensitivity label data classification policies
Ensure that no sender domains are allowed for anti-spam policies
Ensure multifactor authentication is enabled for all users in administrative roles
Ensure multifactor authentication is enabled for all users
Configure which users are allowed to present in Teams meetings
Ensure the customer lockbox feature is enabled
Restrict anonymous users from joining meetings
Don't add allowed IP addresses in the connection filter policy
Set automatic email forwarding rules to be system controlled
Block users who reached the message limit
Sign out inactive users in SharePoint Online
Ensure modern authentication for SharePoint applications is required
Deploy a log collector to discover shadow IT activity
Ensure 'Self service password reset enabled' is set to 'All'
Enable Conditional Access policies to block legacy authentication
Create Safe Links policies for email messages
Turn on Safe Attachments in block mode
Ensure that mailbox intelligence is enabled
Ensure that intelligence for impersonation protection is enabled
Move messages that are detected as impersonated users by mailbox intelligence
Enable impersonated domain protection
Set the phishing email level threshold at 2 or higher
Enable impersonated user protection
Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
Create zero-hour auto purge policies for malware
Quarantine messages that are detected from impersonated domains
Quarantine messages that are detected from impersonated users
Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams
Turn on Safe Documents for Office Clients
Ensure the Common Attachment Types Filter is enabled
Ensure DLP policies are enabled
Set action to take on high confidence spam detection
Set action to take on phishing detection
Set action to take on high confidence phishing detection
Set action to take on spam detection
Ensure that password hash sync is enabled for hybrid deployments
Ensure Safe Attachments policy is enabled
Ensure third party integrated applications are not allowed
Ensure user consent to apps accessing company data on their behalf is not allowed
Create zero-hour auto purge policies for phishing messages
Set action to take on bulk spam detection
Enable the domain impersonation safety tip
Enable the user impersonation safety tip
Enable the user impersonation unusual characters safety tip
Ensure modern authentication for Exchange Online is enabled
Ensure Microsoft 365 audit log search is Enabled
Ensure Safe Links for Office Applications is Enabled
Ensure that an anti-phishing policy has been created
Only invited users should be automatically admitted to Teams meetings
Create zero-hour auto purge policies for spam messages
Restrict dial-in users from bypassing a meeting lobby
Limit external participants from having control in a Teams meeting
Restrict anonymous users from starting Teams meetings
Retain spam in quarantine for 30 days
Set the email bulk complaint level (BCL) threshold to be 6 or lower
Set maximum number of external recipients that a user can email per hour
Set maximum number of internal recipients that a user can send to within an hour
Set a daily message limit
Designate more than one global admin
Use least privileged administrative roles