The Department of Homeland Security has issued a Microsoft Office 365 cybersecurity statement. The memo essentially states that some IT consulting firms and MSPs (managed IT service providers) involved in Office 365 migrations are not properly securing the cloud productivity suite for customers.Twitter: @DHSgovThe statement, from the US-CERT arm of the DHS, represents both a challenge and an opportunity for MSPs and MSSPs. On the one hand, such statements can give the overall IT consulting and IT services market a black eye. But on the other hand, partners that communicate the warning (and proper Office 365 security settings) to end-customers can likely differentiate themselves from less reputable firms.The DHS statement tactfully calls out some partners for dropping the cybersecurity ball on some Office 365 migrations, stating:
"Since October 2018, the Cybersecurity and Infrastructure Security Agency (CISA) has conducted several engagements with customers who have used third-party partners to migrate their email services to O365.
The organizations that used a third party have had a mix of configurations that lowered their overall security posture (e.g., mailbox auditing disabled, unified audit log disabled, multi-factor authentication disabled on admin accounts). In addition, the majority of these organizations did not have a dedicated IT security team to focus on their security in the cloud. These security oversights have led to user and mailbox compromises and vulnerabilities."
The DHS says IT consulting firms and end-customers can mitigate the Office 365 configuration issues by taking five steps:
Use multi-factor authentication. This is the best mitigation technique to use to protect against credential theft for O365 users, the organization says.
Enable unified audit logging in the Security and Compliance Center.
Enable mailbox auditing for each user.
Ensure Azure AD password sync is planned for and configured correctly, prior to migrating users.
Disable legacy email protocols, if not required, or limit their use to specific users.
Joe Panettieri is co-founder & editorial director of MSSP Alert and ChannelE2E, the two leading news & analysis sites for managed service providers in the cybersecurity market.
Russia's invasion of Ukraine features alleged cyberattacks. Follow this Russia-Ukraine conflict timeline for cyber & kinetic warfare updates, and guidance for MSSPs worldwide.