Why M365 first
Business email compromise consistently tops ACSC reported financial losses for Australian businesses. Nearly every case starts with a stolen session or password on a tenant that never had conditional access configured.
These controls cost nothing beyond licensing you likely already hold — the gap is configuration, not budget.
Order of operations
Do identity before mail flow, and mail flow before data protection. Fixing DLP on a tenant with unrestricted legacy auth is decorative.
The checklist
Identity
- Security defaults replaced by explicit Conditional Access policies
- MFA required for all users, including break-glass exclusions documented
- Legacy authentication blocked tenant-wide
- Sign-in risk and user risk policies enabled
- Admin roles assigned just-in-time via PIM
- Guest access restricted and reviewed quarterly
- SPF, DKIM and DMARC published with a reject or quarantine policy
- External sender warning banner enabled
- Auto-forwarding to external domains blocked
- Anti-phishing impersonation protection covers executives and finance
- Safe Links and Safe Attachments enabled for all users
- Mailbox auditing on and retained for at least 12 months
Data and devices
- Anonymous sharing links disabled or expiry-limited in SharePoint and OneDrive
- Sensitivity labels applied to financial and customer data
- Device compliance required for access to corporate data
- Retention policies configured for mail, Teams and OneDrive
Monitoring
- Audit logs forwarded to a SIEM or managed SOC
- Alerts configured for inbox rule creation and impossible travel
- Monthly review of Secure Score movement with named owner