A compromised Microsoft 365 mailbox is rarely just an email problem. It can expose invoices, redirect payment approvals, impersonate executives and provide an attacker with a trusted foothold into the business. For Australian organisations, the operational and reputational cost can be far higher than the apparent value of a single mailbox.
Knowing how to secure Microsoft 365 email means treating identity, email flow, endpoints and monitoring as one security design. Microsoft 365 includes strong security capabilities, but default settings, inconsistent licensing and rushed deployment often leave critical gaps.
Start with identity: the control plane for email security
Most Microsoft 365 email compromises begin with a stolen password, token theft or an attacker convincing a user to approve a fraudulent sign-in. Multi-factor authentication is therefore non-negotiable, but not all MFA provides the same level of protection.
Require MFA for every user, including administrators, service accounts where supported, contractors and executives. Move high-risk accounts towards phishing-resistant methods such as FIDO2 security keys or certificate-based authentication. SMS and voice MFA are better than passwords alone, but remain more vulnerable to social engineering and SIM-swap attacks.
Conditional Access should then determine when and how users can access email. A sensible baseline blocks legacy authentication, requires MFA, restricts high-risk sign-ins and applies tighter controls to administrative roles. Where the licensing supports it, use sign-in risk and user risk signals to force password changes or block access when Microsoft identifies suspicious activity.
Avoid creating broad exclusions simply to get a difficult application working. Every exception should have an owner, a documented reason and a review date. If a legacy device cannot meet modern authentication requirements, replacing or isolating it is generally safer than weakening tenant-wide policy.
Protect privileged accounts separately
Global Administrator accounts should not be used for routine email, browsing or daily administration. Create separate named admin accounts, protect them with phishing-resistant MFA and keep the number of Global Administrators low. Use role-based administration so staff receive only the permissions they need.
For larger organisations, privileged identity management adds time-bound approval and auditing to elevated access. It introduces a little administrative overhead, but significantly reduces the damage from a compromised administrator account.
Secure Microsoft 365 email at the gateway and mailbox
Email security needs multiple checks because phishing techniques do not rely on one weakness. Attackers may spoof a supplier domain, use a legitimate compromised account, send a malicious link after initial delivery, or conduct business email compromise without attaching malware at all.
Configure SPF, DKIM and DMARC for every domain that sends mail on behalf of the organisation. SPF identifies authorised senders, DKIM validates message signing, and DMARC tells receiving systems how to handle messages that fail those checks. Start DMARC in monitoring mode if required, then progress to quarantine or reject once all legitimate mail sources have been identified.
Within Microsoft Defender for Office 365, apply anti-phishing, anti-spam and anti-malware policies consistently. Enable impersonation protection for priority users and domains, with special attention to finance, payroll, procurement and executive staff. Configure Safe Links and Safe Attachments to inspect URLs and attachments, including threats that appear after a message has been delivered.
Mailbox forwarding deserves particular attention. Attackers commonly create hidden inbox rules that forward invoices, customer correspondence or password reset messages to an external address. Restrict automatic forwarding to external domains by default and alert on new forwarding rules, delegated mailbox permissions and suspicious inbox rule creation.
There is a balance to strike. Overly aggressive filtering can delay legitimate customer emails or quarantine business-critical attachments. Start with vendor recommendations, test policies against normal workflows and review false positives with business owners. Security controls should reduce risk without making staff bypass them.
Secure the devices that access the mailbox
Email is only as secure as the devices and browsers used to access it. A managed laptop with supported software, endpoint protection and disk encryption presents a very different risk profile from an unmanaged personal device.
Use device compliance policies to require supported operating systems, encryption, screen locks and endpoint protection before granting access to corporate email. For mobile access, app protection policies can prevent corporate data being copied into personal apps, downloaded to unmanaged storage or accessed on compromised devices.
Endpoint detection and response is also valuable because many credential theft attacks begin with malware on a user device. If an endpoint shows signs of compromise, conditional access can limit access to Microsoft 365 while the security team investigates.
For organisations with branch offices, remote workers and cloud applications, email controls should sit within a wider secure access design. Fortinet security solutions can complement Microsoft 365 by providing endpoint, network, secure access service edge and email protection capabilities under a unified operational model. The right mix depends on existing licences, internal capability and the level of visibility required.
Protect sensitive information without blocking the business
Microsoft 365 email often carries contracts, customer data, financial reports and commercially sensitive designs. Data loss prevention policies help identify when sensitive information is being sent externally, while sensitivity labels can apply encryption, access restrictions and handling requirements to documents and messages.
Begin with the data that would cause the greatest harm if misdirected: payment information, personal information, health records, intellectual property and confidential commercial documents. Map where it is used before applying controls. A blanket rule that blocks every external attachment may look secure on paper, but can quickly disrupt sales, projects and supplier operations.
Use staged enforcement. Start by notifying users and collecting policy matches, then move high-confidence scenarios to blocking or approval workflows. This approach gives security teams evidence to tune controls and helps staff understand why a message requires different handling.
Monitor the signals that reveal compromise
Security settings have little value if no one notices when they are bypassed or challenged. Review Microsoft 365 audit logs, sign-in activity, mailbox changes and security alerts on a defined schedule. Alerts should be routed to people who can act, not simply sent to an unattended shared mailbox.
Prioritise alerts for impossible travel, repeated MFA failures, unfamiliar sign-in locations, risky users, newly created forwarding rules, changes to transport rules and privileged role assignments. Correlate these events with endpoint and network telemetry where possible. A sign-in from an unusual country may be legitimate; that same sign-in followed by an inbox rule and payment-related email activity is far more concerning.
Define an email incident playbook before an incident occurs. It should cover account disablement, session revocation, password reset, removal of malicious rules, message search and purge, affected-recipient notification, evidence retention and escalation to management or legal advisers. For businesses without a dedicated security operations function, managed monitoring can provide the required coverage without building a full internal team.
Back up Microsoft 365, but do not mistake backup for prevention
Retention policies and native Microsoft 365 recovery features are useful, but they are not a complete substitute for an independent backup strategy. A properly designed backup can help recover deleted mail, restore data after ransomware or retain information beyond operational retention settings.
Backup does not stop phishing, account takeover or unauthorised data access. It is a resilience control, not an identity or email security control. Keep backup access separate from normal user credentials, protect it with MFA and test restoration regularly.
Make security an operating practice, not a one-off project
The strongest Microsoft 365 configuration will still be tested by changing staff, new applications, supplier impersonation and evolving attacker methods. Review privileged access, conditional access exclusions, external forwarding, DMARC reporting and high-risk alerts at least quarterly. Reassess after mergers, system changes or a security incident.
Staff training also matters, particularly for finance and executive assistants who handle payment changes. Training should use realistic scenarios and clear escalation paths rather than generic annual tick-box modules. People need confidence to pause a suspicious request, verify it through a separate channel and report it quickly.
Email security becomes commercially effective when it is built around the way your organisation actually operates. Start with strong identity controls, close the common mailbox gaps, monitor the right signals and keep refining the design as risks and business requirements change. That is how Microsoft 365 email becomes a dependable business platform rather than an exposed point of entry.

