Growing numbers of organizations are making the move to Microsoft 365, a very popular suite of productivity solutions including Outlook, OneDrive, and SharePoint. Enabling collaboration for home, business, and enterprise environments, Microsoft 365 is one of the most widely used suites housed in the public cloud today.While Microsoft has taken measures to protect their cloud services, users should still be aware of its vulnerable areas and work to secure them. Read on to learn the top four security concerns and how you can secure each one.
Guest blog courtesy of by Blackpoint Cyber. Read more Blackpoint Cyber posts here.
1 - Compromised of Global administrator accounts
Microsoft 365’s centralized administration model is designed to give Global administrators the highest level of administrator privileges at the tenant level. These Global accounts are the first ones created in a new environment and used to configure the tenant and migrate and grant access to future users. Often, threat actors target these administrator accounts to gain the same level of high privileges.After compromising a Global admin account, they are free to:- Alter critical settings,
- Remove safeguard settings,
- Leave backdoors open, and
- Access valuable data.
Action: Enable MFA for administrator accounts immediately
These admin accounts are based in the cloud and, therefore, exposed to internet access. Multi-factor authentication (MFA) is the best method to mitigate account compromise. In Microsoft 365, the Global admin must manually enable MFA to ensure that threat actors cannot exploit their administrator privileges. If not secured immediately, cloud-based accounts can become a quick avenue for attack.2 - Abuse of user privileges
Through it is convenient to give blanket access to all your account users, it is very poor cybersecurity hygiene and makes way for security concerns abound. Giving users more permissions than they need to perform their role increases the risk of data breaches. Users may expose sensitive data whether on accident by falling for phishing and social engineering tactics or deliberately.Further, enabling over-privileged users means you are creating more opportunities for threat actors. Let’s say that a Global admin account is out of reach or protected via MFA. Coming across a regular user account with no MFA enabled and more permissions than needed would be just as good to the attacker.Action: Assign permissions using role-based access control (RBAC)
Minimizing privileges and implementing a principle of least privilege is a significant way to thwart threat actors from exploiting your regular user accounts. Using Microsoft’s built-in administrator roles can also help you identify and organize who needs what permissions. Always assign users the minimum level of permissions they need to complete their tasks and review your roster of accounts often to revoke excessive permissions or deactivate accounts or roles no longer in use.3 - Disabled mailbox auditing
Prior to January 2019, Microsoft did not enable mailbox auditing by default in their 365 environment. So, accounts who procured their 365 account before January 2019 are required to manually enable this auditing capability. Keep in mind that after it is enabled, you will only see events going forward. There is no visibility available for past events. Where there is email communication, there is room for vulnerability.Threat actors who have infiltrated your system can hideout for months while extracting valuable intel from emails, including:- Financial data/invoices,
- Credentials,
- Names and contact information of prominent staff and executives,
- Work plans/schedules, and more.




