We recommend you apply MFA to everything you possibly can. It’s especially important on Office 365 as Microsoft’s data says almost all of their account breaches would have been prevented had MFA been properly enabled (but only if you don’t have MFA fatigue and click when you shouldn’t have). Even with MFA enabled, you need to be very careful you’re not MFA-ing when you shouldn’t be, as there are some really well-done scammer tools out there that make it seem like you’re logging into the right place when you’re not. Check out this video:
We recommend a multi-layered approach to your Office 365 protection, including but not limited to:
- WestonBlock spam/virus filtering to scan emails and look for signs of the scammers at work
- Web content filtering to try to block access to known scammer sites and domains
- Implementation of multifactor authentication to make accessing email accounts much more difficult
- Security Awareness Training for your company’s team to teach them what to look for and when to be suspicious, along with education on avoiding spear phishing
- Following best security practices with conditional access rules to lock down access to 365.
- Setting up an office 365 Managed Detection and Response (MDR) tool that constantly monitors for potential threats and compromises and locks things down if things hacked.
If you’re not a client of ours and want to know more about our CompleteCare managed IT services and how we can help protect your Office 365 environment, contact us today.