How to Secure Microsoft 365 Against Modern Cyber Attacks

If a threat actor logged into one of your employees’ Microsoft 365 accounts right now, how long would it take you to notice?

Microsoft 365 runs the modern business. Email, calendars, files, collaboration, identity: this is where work happens and where your most sensitive information lives. Microsoft pours billions into securing that infrastructure every year, and it shows: the platform is secure.

The biggest risks facing businesses today rarely come from a failure in Microsoft’s technology. They come from how identities are configured, protected, and monitored once they are inside your environment. And this is where you come in.

Microsoft 365 is secure. But secure does not mean automatically protected

As the platform has become central to business operations, it has also become one of the most attractive targets for cybercriminals.

In the State of Business Email Compromise 2026 report published earlier this year, Eye Security identified that 99% + of BEC incidents occurred in Microsoft 365 environments.

 

BEC report

This does not mean that Microsoft 365 is more vulnerable; in fact, it is quite the opposite. It simply reflects the reality of corporate environments, a high percentage of which use the platform.

This concentration highlights a wider industry shift. Threat actors are following identities. Where businesses store their most valuable information and conduct their daily operations is where criminals increasingly focus their efforts. 

Modern attackers are no longer focused solely on exploiting software vulnerabilities. They steal credentials, compromise identities, and use legitimate accounts to move through businesses unnoticed. 

Securing Microsoft 365, therefore, requires more than simply having the platform in place. You need the right security controls, ongoing monitoring, and the ability to respond quickly when suspicious activity occurs.

 

“Identity attacks thrive not on technical complexity but on credibility and timing. Eye Security’s data reinforces that defending against such incidents calls for email authentication controls, continuous user awareness, and vigilant financial process validation to counter manipulation at its human core.”

– Lodi Hensen, VP Security Alliances

Business email compromise (BEC): why Microsoft 365 has become a target

Our research shows that business email compromise (BEC) has become one of the dominant threats affecting Microsoft 365 environments. 

Of 343 incidents investigated in 2025, BEC represented 81% of cases

Instead of deploying malware, threat actors use compromised accounts to impersonate trusted individuals, manipulate conversations, and convince employees or suppliers to take fraudulent actions.

These actions take the form of activities such as requesting fake payments, changing supplier bank details, and accessing sensitive information. The communication often ‘originates’ from a genuine account, making these attacks extremely difficult to identify.

“Across dozens of investigations this year, we’ve seen that threat actors rarely succeed because environments lack tools; they succeed because organisations don’t truly operate from the assume-breach posture. In many cases, the breach was already well underway before anyone realised what was happening.”

– Lodi Hensen, VP Security Alliances

 

cyber incidents report

Read The State of Cyber Incidents 2026

 

For many, Microsoft 365 is where their most sensitive business information lives.

A single account provides access to:

  • emails and customer communications
  • financial documents
  • employee information
  • supplier details
  • intellectual property

Rather than launching a traditional attack against a company’s network, criminals now use stolen credentials to access a legitimate account and operate as a trusted employee.

The challenge is that Microsoft 365 sits at the centre of business trust. Employees use it every day to communicate, share documents, and approve decisions. 

When an attacker gains access to a legitimate account, they inherit that trust. 

What threat actors do once they are inside

Gaining access is only the beginning. Once a threat actor is inside a Microsoft 365 account, they do not need malware. They do not need to escalate through your network. And often, they do not need to move fast. 

They read, they wait, and they use the trust that comes with a legitimate account. Real Eye Security investigations show how this plays out.

Case Study 1: The BEC case that nearly cost a million

In one Eye Security incident response case, attackers compromised email communication between the finance controllers of an international headquarters and its national organisations. Payment requests, complete with real invoices, were followed up with emails carrying fraudulent bank account details. Money kept moving, just not to the intended recipients. 

By the time the finance team retraced the payment trail, the fraud amounted to roughly a million in misdirected payments. And the cost did not stop there. Incident response, legal and cross-border compliance work, PR and reputational management, and internal IT overtime all followed.

This is the endgame of the same pattern: patient abuse of a trusted communication channel and a familiar business process, payment approval, until real money leaves the business.

Case Study 2: Two attackers, one inbox

In a second case, a single Microsoft 365 account was compromised twice in the same week by two unrelated threat actors, neither of whom appeared to be working with the other. They simply found and abused the same weak point.

What each of them did after logging in is the instructive part:

  • Reconnaissance first. One actor started by reading files, looking for company context, financial information, and anything useful for fraud or extortion. The other later worked through emails. In many BEC cases, there’s a deliberate gap between initial access and activity, which creates a dangerous false sense of security while the account stays quietly compromised.
  • Hiding in plain sight with an inbox rule. One actor created a mailbox rule that applied to any message containing an “@” symbol, effectively every incoming email, and moved those messages to another folder and marked them as read. So when colleagues replied asking “did you actually send this?”, the real user never saw the warnings.
  • Abusing trust to spread. One actor used the compromised mailbox to send phishing emails internally and successfully compromised a second account. The messages weren’t coming from a lookalike domain; they were coming from a real colleague’s account.
  • Surviving partial remediation. Even after remediation began, one actor was still able to send phishing emails again, because password resets alone do not remove active sessions, malicious inbox rules, or other persistence.

The takeaway: once identity is compromised, a single inbox can become a shared opportunity for multiple cybercriminals. The question then becomes: “How many times, by whom, and what did each of them do?”

How do attackers exploit Microsoft 365?

While the platform provides powerful security capabilities, attackers continue to exploit the same weaknesses repeatedly: compromised identities, poor configuration, trusted communication channels, and a lack of visibility. 

1. Stolen credentials and compromised accounts

“Threat actors did not rely on novel exploits or advanced malware. They operated within trusted environments, using legitimate access, familiar workflows, and increasingly, AI-enhanced social engineering.”

– The State of Business Email Compromise 2026

Threat actors frequently use phishing emails, fake login pages, and malware to steal usernames, passwords, and authentication information, as explored in our recent article on identity attacks across Europe.

Once they gain access to a legitimate account, they can bypass many traditional security controls because their activity appears to come from a genuine user.

2. AI-enhanced phishing and social engineering

In Eye Security’s State of Business Email Compromise 2026, phishing via link was the single dominant entry vector, accounting for 63% of BEC incidents. 

Technology has improved significantly, but attackers continue to rely on one of the oldest techniques in the book: convincing people to trust something they should not.

What has changed is not the tactic but its quality and speed, and that change is driven by AI.

Modern phishing attacks are convincing, using personal information, realistic branding, and AI-generated content to appear legitimate. The emails themselves are no longer the giveaway. Increasingly, it is what happens after a user clicks that determines whether an attack succeeds.

“The consequence for defenders is that the email itself is no longer the giveaway. The old advice, look for spelling mistakes, hover over the link, distrust anything generic, was built for an era of low-effort phishing that AI has effectively ended. Increasingly, it is not whether someone spots a suspicious email that decides the outcome.” 

And what happens after the click is often invisible to the user. 

Modern commercialised phishing kits do not just harvest a password. They proxy the real Microsoft 365 login, capture the authenticated session, and step straight past multi-factor authentication. The user completes a genuine login; the attacker walks in with them. This is why awareness training, though still valuable, cannot be the last line of defence. 

When AI makes lures faster to write, easier to personalise and harder to recognise, and when a single click can hand over an authenticated session, teams need controls that assume some phishing will succeed. This means detection of unusual behaviour after sign-in, and the ability to contain, at AI speed, a compromised account before it causes damage.

3. Misconfigured security settings

Microsoft 365 includes a wide range of security features, but these tools are only effective when they are correctly configured and maintained.

The mistakes we see most often include

  • MFA that is not enforced everywhere, or relies on weak methods;
  • legacy authentication left enabled;
  • no Conditional Access, or Conditional Access with holes in it;
  • external auto-forwarding and unmonitored inbox rules;
  • too many administrators, and admin accounts used for daily work;
  • and no log retention, with no one watching.

Below, we look at what this means for SMEs and our recommendations on tightening up your security features, 

For many teams, the challenge is not a lack of available security technology, but ensuring those controls are correctly implemented.

Unlike traditional network attacks, configuration weaknesses can remain invisible for months. An organisation may have Microsoft 365 deployed correctly from a technical perspective, but still leave unnecessary access or permissions available to attackers. 

What this means for small and medium-sized companies

For smaller businesses, the biggest mistake is the assumption that Microsoft 365 is secure out of the box. The recurring pattern looks like this:

  • treating the default configuration as “good enough” and never hardening it
  • turning MFA on and considering identity “done”
  • granting broad permissions and standing admin rights for convenience
  • leaving external sharing, forwarding, and legacy auth open because tightening them feels like friction
  • having no continuous monitoring, so a compromise is discovered only when money goes missing or a customer flags a strange email

The common thread is visibility. These environments are usually deployed correctly from a technical standpoint, but left unmonitored and unreviewed, so misconfigurations and attacker activity can sit undetected for weeks.

Eye Security recommends: how teams can strengthen Microsoft 365 security

Eye Security’s incident responders see the same pattern across investigations. Threat actors rarely break Microsoft’s technology. They exploit weak identity controls, gaps in configuration, and a lack of monitoring. The recommendations below reflect what Eye Security applies and advises across affected customer environments.

1. Enforce MFA, but treat it as a layer, not a finish line

Eye Security found that MFA was bypassed in 79% of investigated BEC cases, commonly through adversary-in-the-middle phishing and session theft. In one investigation, two unrelated threat actors compromised the same Microsoft 365 account within a week using AitM techniques. MFA therefore remains essential, but it must be supported by stronger authentication methods,

This does not mean MFA is ineffective. It still makes attacks significantly harder and should be enforced on every account. The point is, however, that MFA alone is not enough.

  • Enforce MFA across all users, including administrators, shared mailboxes, and break-glass accounts.
  • Use phishing-resistant methods (FIDO2 security keys or passkeys) for privileged and high-risk users.
  • Avoid relying on SMS or email-based codes for sensitive accounts.

2. Conditional Access and post-login monitoring 

Conditional Access lets you require trusted or compliant devices, restrict risky sign-ins, and apply tighter rules to your most sensitive accounts, which directly limits the value of a stolen session or password.

3. Disable legacy authentication

Legacy authentication protocols do not support MFA challenges, which makes them a common route for identity abuse. Disabling legacy authentication at the tenant level removes one of the most reliable ways attackers bypass modern controls.

4. Apply least privilege

Not every employee needs access to every system or mailbox. Limiting permissions reduces the impact if an account is compromised. The more access an account holds, the more damage its compromise can cause.

5. Protect and monitor administrator accounts

Administrator accounts unlock critical systems and settings. They need additional protection.

  • Use dedicated administrator accounts, separate from day-to-day user accounts.
  • Limit the number of privileged accounts and apply just-in-time, time-bound elevation where possible.
  • Monitor privileged activity

6. Watch for the signs of a compromised mailbox

Because threat actors operate as legitimate users, the clearest signals are behavioural. Eye Security recommends watching for and alerting on:

  • suspicious inbox rules, especially rules that auto-forward or hide messages
  • external auto-forwarding
  • sign-ins from unexpected locations or impossible-travel patterns
  • unusual MFA prompts and new authentication methods being registered

Disabling external auto-forwarding and alerting on new inbox rules are among the highest-value quick wins.

7. Retain logs

Retaining logs matters for two reasons. It supports faster detection, and it preserves the evidence needed for forensic investigation if an incident occurs.

8. Prepare an incident response process before you need it

Eye Security’s investigations repeatedly show that the breach was often well underway before anyone realised. Businesses should have a defined process to contain a compromised account quickly, before one inbox becomes a wider business incident. This means knowing in advance how to reset credentials, revoke active sessions, remove attacker-added MFA methods and forwarding rules, and determine what the attacker accessed.

Microsoft 365 security is an ongoing process, not a one-time setup

One of the biggest misconceptions about cloud security is that once security settings are configured, the job is complete. In reality, Microsoft 365 environments are constantly changing. New users join, applications are connected, permissions evolve, and business requirements change.  All the while, attackers continue developing new techniques.

1. Turn alerts into actions

Monitoring is what turns Microsoft 365’s raw telemetry into early warning. Done well, it surfaces the signals that precede a business-impacting incident: unusual login attempts, suspicious inbox and forwarding rules, unexpected data access, MFA prompts from unfamiliar locations, and account behaviour that only looks wrong when placed in context.

But telemetry alone does not stop anything. Microsoft 365 generates alerts, yet someone still has to investigate whether unusual behaviour is malicious, then act, revoking sessions, resetting credentials and containing the account, before an attack can escalate. The gap between an alert firing and someone acting on it is exactly where BEC unfolds.

2. Every minute counts

Eye Security’s incident response data shows how much that gap matters. In environments without continuous monitoring, threat actors remained undetected inside BEC-affected networks for a median of 18 days. In environments with Managed Detection and Response (MDR), the median dwell time was 19 minutes.

In 19 minutes, a threat actor has barely begun. In 18 days, they can read emails, learn how the business approves payments, create inbox rules to hide their activity, compromise additional accounts, and step into a live supplier or invoice conversation, all from a trusted internal identity.

In BEC, detection speed is the single most important variable in limiting financial and operational impact.

The reason non-monitored environments run to weeks is that they rely on human discovery: a finance team noticing an anomalous payment, or a supplier calling to ask why the bank details changed. By then, the damage is often done. Continuous monitoring, automated detection and 24/7 human analysis replace that accidental discovery with deliberate detection, which is why Eye Security’s data shows BEC being surfaced and contained in a fraction of the time.

“In the BEC cases we investigated, MDR-enabled environments detected and contained incidents up to 99.9% faster.”

The State of Cyber Incidents 2026

In modern identity-based attacks, the time between compromise and detection can determine whether an incident remains contained or escalates into a major business disruption. 

One size does not fit all

Microsoft 365 remains one of the most secure productivity platforms available, but security is a shared responsibility.

In conjunction with the platform’s strong foundation, senior leadership must ensure identities are protected, configurations are regularly reviewed, and suspicious activity is detected quickly.

As threat actors now target people rather than infrastructure, effective security is no longer defined solely by prevention. It depends on how quickly a business can identify, investigate, and respond when something does not look right. And know who to rely on when they need to. 

Blog Categories

Threats and Vulnerabilities

Recent Blogs

Cyber Insurance Renewal Checklist for 2027 

  A lot can change in 12-months. Your business may have added new systems, suppliers, or employees. The amount of data you hold may have increased. Your security controls may have changed. And your current insurance policy may no longer offer the protection you think it does. 

2027 Cybersecurity priorities: are you spending in the right places? 

Cyber budgets have climbed every year for a decade. Attacks keep succeeding anyway. This gap tells us that the size of the budget was rarely the issue. September is when European leadership teams set the budget allocation for 2027. Every department competes for the same investment, and cybersecurity has to earn its place alongside the […]