Want an easy way to see if you’ve had an M365 compromise? 𝗟𝗼𝗼𝗸 𝗮𝘁 𝗜𝗻𝗯𝗼𝘅 𝗥𝘂𝗹𝗲𝘀! Inbox rules are used by attackers to hide ongoing conversations they have jumped into. If you hunt through all rules, you can find indicators of a compromise. First, pull all rules with this PS code: 𝘊𝘰𝘯𝘯𝘦𝘤𝘵-𝘌𝘹𝘤𝘩𝘢𝘯𝘨𝘦𝘖𝘯𝘭𝘪𝘯𝘦 $𝘶𝘴𝘦𝘳𝘴 = (𝘎𝘦𝘵-𝘌𝘹𝘰𝘔𝘢𝘪𝘭𝘣𝘰𝘹 -𝘳𝘦𝘴𝘶𝘭𝘵𝘴𝘪𝘻𝘦 𝘶𝘯𝘭𝘪𝘮𝘪𝘵𝘦𝘥).𝘜𝘴𝘦𝘳𝘗𝘳𝘪𝘯𝘤𝘪𝘱𝘢𝘭𝘕𝘢𝘮𝘦 𝘧𝘰𝘳𝘦𝘢𝘤𝘩 ($𝘶𝘴𝘦𝘳 𝘪𝘯 $𝘶𝘴𝘦𝘳𝘴) { 𝘎𝘦𝘵-𝘐𝘯𝘣𝘰𝘹𝘙𝘶𝘭𝘦 -𝘔𝘢𝘪𝘭𝘣𝘰𝘹 $𝘶𝘴𝘦𝘳 | 𝘚𝘦𝘭𝘦𝘤𝘵-𝘖𝘣𝘫𝘦𝘤𝘵 𝘔𝘢𝘪𝘭𝘣𝘰𝘹𝘖𝘸𝘯𝘦𝘳𝘐𝘋,𝘕𝘢𝘮𝘦,𝘋𝘦𝘴𝘤𝘳𝘪𝘱𝘵𝘪𝘰𝘯,𝘌𝘯𝘢𝘣𝘭𝘦𝘥,𝘙𝘦𝘥𝘪𝘳𝘦𝘤𝘵𝘛𝘰,𝘔𝘰𝘷𝘦𝘛𝘰𝘍𝘰𝘭𝘥𝘦𝘳,𝘍𝘰𝘳𝘸𝘢𝘳𝘥𝘛𝘰 | 𝘌𝘹𝘱𝘰𝘳𝘵-𝘊𝘚𝘝 𝘛𝘦𝘯𝘢𝘯𝘵𝘙𝘶𝘭𝘦𝘴𝘖𝘶𝘵𝘱𝘶𝘵.𝘤𝘴𝘷 -𝘕𝘰𝘛𝘺𝘱𝘦𝘐𝘯𝘧𝘰𝘳𝘮𝘢𝘵𝘪𝘰𝘯 -𝘈𝘱𝘱𝘦𝘯𝘥 } Look through the output for the following signs: • Emails being put into the RSS Feeds, Conversation History, Archive, Junk, or Deleted Items folders • Rule names that are only composed of periods (., .., …, etc.), single letters, odd repeating characters, or names meant to enforce not to delete the rule (e.g. “Don’t Disable”) • Rules acting on emails containing keywords such as payment, payroll, direct deposit, paystub, invoice, password, etc. If you find any, reach out to the users and ask if they enabled them…they may have. If not, start an investigation because you may have just found a compromised account! What malicious inbox rules have you seen? #dfir #incidentresponse #forensics #inversion6
Email security audit for M365 users
Explore top LinkedIn content from expert professionals.
Summary
An email security audit for M365 users involves reviewing and strengthening security settings in Microsoft 365 to prevent unauthorized access, phishing, and other threats. This process helps businesses ensure their email accounts and data are protected against common attack methods.
- Analyze mailbox rules: Regularly check mailbox rules for signs of suspicious activity, such as strange folder redirects or rule names, to spot possible compromises.
- Review privilege settings: Audit user and app permissions to ensure no accounts or applications have more access than necessary, and promptly remove any risky or unnecessary privileges.
- Enable audit logging: Make sure Unified Audit Log is switched on so you can track actions in mailboxes and have a record available in case of a security incident.
-
-
Want to keep Russian threat actors out of your M365 tenant? Good, me too. Go uncheck this box immediately in your settings. Unfortunately, M365 is not fully secure or hardened out of the box. By default, any user can create app registrations and consent to Graph permissions. Here is some other guidance to level-up your defenses: ☑️ Audit all user and service principal identities in your tenant using Microsoft Graph Data Connect to assess their privilege levels. Scrutinize privileges more closely if they belong to unknown identities, are no longer in use, or exceed necessary levels, especially for apps with app-only permissions that might have over-privileged access. ☑️ Review identities with ApplicationImpersonation privileges in Exchange Online. This feature allows a service principal to perform actions on behalf of a user, like managing a mailbox. Check permissions in the Exchange Online Admin Center or via PowerShell to ensure they are appropriately scoped and not overly broad. ☑️ Utilize anomaly detection policies to identify and address malicious OAuth apps in Exchange Online. Investigate and remediate any risky OAuth apps that perform sensitive administrative activities. ☑️ Implement conditional access app control for users on unmanaged devices. Be vigilant of OAuth application abuse, particularly those with EWS.AccessAsUser.All and EWS.full_access_as_app permissions, and remove any unnecessary permissions. ☑️ For applications requiring mailbox access, use role-based access control in Exchange Online to ensure granular and scalable access. This model allows applications to access only the specific mailboxes they need, enhancing security.
-
Email is still the number one initial access vector. Most organizations have Microsoft Defender for Office 365 licensed — and most use about 30% of what it can do. The features most teams miss: Attack Simulation Training Built-in phishing simulation that sends realistic campaigns to your users, tracks click rates, and enrolls clickers in targeted awareness training automatically. Run simulations monthly. Track improvement quarterly. Threat Explorer Real-time view of every email delivered, quarantined, or blocked. When a user reports phishing, Threat Explorer shows every other recipient who got the same message — and whether they clicked. URL detonation Safe Links detonates URLs in a sandbox, follows redirects, and re-evaluates after the page fully renders. Catches time-of-click attacks that static reputation filters miss. ZAP (Zero-Hour Auto Purge) After a phishing email is delivered and identified as malicious, ZAP retroactively removes it from all recipient mailboxes — even if they have already received it. Priority account protection Designate your executives and high-value targets as priority accounts. MDO applies additional heuristics and gives their alerts higher priority in the queue. Start here: apply the Standard or Strict preset security policy to all users before touching individual settings. This gives you Microsoft's recommended baseline for anti-phishing, anti-spam, safe links, and safe attachments — in one click. KQL to investigate phishing in Sentinel: EmailEvents | where ThreatTypes has "Phish" | where DeliveryAction != "Blocked" | summarize count() by SenderMailFromDomain, RecipientEmailAddress | order by count_ desc When did you last run an attack simulation against your users? #DefenderForOffice365 #EmailSecurity #AntiPhishing #MicrosoftSecurity #SOC #CyberSecurity
-
Last week I completed a network and Microsoft 365 setup for a small business and it reinforced something I see far too often. Small businesses incorrectly assume that Microsoft 365 is secure by default, it is not. On the network side, I installed and configured switches and WiFi access points with proper segmentation, Intrusion Detection and Prevention (IDS/IPS) and cloud based management. This client migrated to Microsoft 365 Business Premium from a very basic e-mail setup with unmanaged workstations. During the setup, I secured the client’s Microsoft 365 environment after explaining the importance of security to the client. Identity controls, email security, and baseline protections were put into place. This matters because misconfigured Microsoft 365 environments are a leading cause of account takeovers, business email compromise, and data exposure in small businesses. Critical Microsoft 365 Business Premium security steps: 🏈 Enforce MFA for all users and block legacy authentication methods 🏈 Harden admin access: no standing global admins; apply least-privilege role assignments 🏈 Lock down email with anti-phishing, spoof protection, and scan links and attachments 🏈 Secure endpoints with Intune: device compliance, disk encryption, and patch enforcement 🏈 Use Conditional Access to restrict sign-ins by risk, device state, and location 🏈 Disable risky defaults such as external forwarding, anonymous sharing, and unused apps 🏈 Implement real backups: Microsoft 365 does not include automatic backups. Use a third-party backup service and test data restoration 🏈 Security Defaults: Microsoft provides preconfigured baseline security settings to protect against common attacks. These are a minimum starting point If your small business relies on Microsoft 365 Business Premium and you’re not confident the security settings reflect today’s threat landscape, I’m happy to review the setup and point out where simple changes can reduce risk. #Cybersecurity #BlacksuitConsulting #Microsoft365
-
Check your M365 Unified Audit Log status today If your organization is hit by a Business Email Compromise (BEC), the Unified Audit Log (UAL) is the most important data source you have. It tracks exactly what an attacker did inside your mailboxes. While Microsoft enables this by default now, we still find tenants where it is disabled. If it is off during an incident, you cannot recover that data later. These logs are not retroactive. And without logs, you can't prove what data was accessed. Check the status via PowerShell as seen in the image below: Get-AdminAuditLogConfig | Select UnifiedAuditLogIngestionEnabled If the value is False, you are not collecting the logs you need. Change it to True immediately.