Posts

Auditing - Ensure The Report Of Users Who Have Had Their Email Privileges Restricted Due To Spamming Is Reviewed

Image
  Summary Microsoft 365 Defender reviews of Restricted Entities will offer a list of users accounts restricted from sending e-mail. If one of the outbound sending limits is exceeded, then, the user will be restricted from sending email, however, they can still receive email. Reason Users on the restricted users list have a high possibility of being compromised. Reviewing this list will help in remediating these user accounts, and then unblock them. How to? To review the report, use the Microsoft 365 Admin center: Go to  Security to open the Security portal. Under Email & collaboration navigate to Review. Click Restricted Entities. Review alerts and take appropriate action (unblocking) after account has been remediated. Monitor: To verify the report is being reviewed at least weekly, confirm that the necessary procedures are in place and being followed.

Auditing - Ensure Microsoft Defender For Cloud Apps Is Enabled

Image
  Summary Enabling it allows you to know about any suspicious activity going on in Microsoft 365, so you can investigate situations that are potentially problematic and, if needed, take action to address the security issues. Reason Notifications of triggered alert are received for atypical or suspicious activities, know how an organization's data in Microsoft 365 is accessed and used, suspend user accounts exhibiting suspicious activity, and require users to log back in to Microsoft 365 apps after an alert has been triggered. How to? To enable the Microsoft Defender for Cloud Apps, use the Microsoft 365 Admin center: Go to  Security. Select More Resources. Select Open under Microsoft Defender for Cloud App Security. Ensure the dashboard opens and the feature is enabled. Monitor: To verify Microsoft Defender for Cloud Apps is enabled, use the Microsoft 365 Admin center: Select  Security. Select  More Resources. Select  Open  under  Microsoft Defender fo...

Auditing - Ensure The Spoofed Domains Report Is Reviewed Weekly

Image
  Summary Spoof intelligence present in the Security Center should be used on the Anti-spam settings page in order to review all senders, who are spoofing either domains that are part of an organization, or spoofing external domains. Spoof intelligence is available as a part of Office 365 Enterprise E5 or separately as part of Defender for Office 365 and as of October, 2018 Exchange Online Protection (EOP). Reason Malicious actors generally spoof domains to trick users into conducting actions they normally would not or should not, via phishing emails. Running this report will inform the message administrators of current activities, and the phishing techniques used by bad actors . This information can also be used to inform end users and plan against future campaigns.  How to? To review the report, use the Microsoft 365 Admin center: Go to  Security. Under Email & collaboration click on Policies & rules then select Threat policies. Under Rules click on Tenant Allow...

Auditing - Ensure Non-Global Administrator Role Group Assignments Are Reviewed At Least Weekly

Image
  Summary Non-global Administrator Role Group assignments should be reviewed at least every week. Reason Although these roles are less powerful than a global admin, they do grant special privileges that can be used illicitly. If anything unusual is seen, then, the user must be contacted in order to confirm it is a legitimate need.  How to? To review non-global administrator role group assignments, use the Microsoft 365 Admin center: Go to  Security. Click on  Audit  then select  Search. Set  Added member to Role  and Remove a u ser from a directory role for Activities. Now, set  Start date  and  End date. Click  Search. Review. Monitor: To verify non-global administrator role group assignments are being reviewed at least weekly, confirm that the necessary procedures are in place and being followed.

Auditing - Ensure The Account Provisioning Activity Report Is Reviewed At Least Weekly

Image
  Summary This report consists of the details of any account provisioning that was attempted by an external application. Reason If a third party provider is not used to manage accounts, any entry on the list is likely illicit; otherwise, it is a great way to monitor transaction volumes and look for new or unusual third party applications that are managing users. If anything unusual is seen, then, the provider must be informed in order to determine the authenticity of the action.                                                                                                                                                How to? T...

Auditing - Ensure All Security Threats In The Threat Protection Status Report Are Reviewed At Least Weekly

Image
  Summary All the security threats should be reviewed at least weekly, in the Threat Protection status report which shows specific instances of Microsoft blocking malware attachment from reaching your users, phishing being blocked, impersonation attempts, etc. Reason This report is not strictly actionable, however, reviewing it will offer you a sense of the overall volume of various security threats targeting your users, which may prompt you to adopt more aggressive threat mitigations.                                                                                                                                                Ho...

Auditing - Ensure Mail Forwarding Rules Are Reviewed At Least Weekly

Image
  Summary E-mail can be forwarded automatically after configuring the Exchange Online environment with the help of Transport Rules in Admin Center, Auto Forwarding per mailbox, and client-based rules in Outlook. Administrators and users both are provided with many methods to automatically and quickly e-mails outside of an organization. Reason By reviewing the rules weekly, the Messaging Administrator can gain insight into possible attempts to exfiltrate data from an organization; it can also help in creating a recognition of baseline, legitimate activity of users which in turn can aide in identifying the more malicious activity of bad actors when/if they chose to use this side-channel. What If? There is no impacting to reviewing these reports. How to? To review mail forwarding rule,  use the Microsoft 365 Admin Center: Go to Exchange admin center. Expand Reports then pick Mail flow. Now, click on Auto forwarded messages report. Review. Note: Mail flow reports cannot be viewed ...