logo

Office 365 security best practices: five things to do right now to keep attackers out

ID: 80d969ad-261b-5cee-90c7-be915ad2f689

STIX ID: report--80d969ad-261b-5cee-90c7-be915ad2f689

Feed Name: Expel Blog

Date Published: 2019-01-15

Date Updated: 2026-04-27

Author: Dan Whalen

...
...

This blog post outlines five concise Office 365 security best practices to protect SaaS data and prepare for account compromises: enable audit logging, require multi-factor authentication, deploy controls for phishing/malware/DLP and user behavior analytics, tighten policy configurations (conditional access, disable public sharing, disable mailbox forwarding), and plan incident response around cloud-centric audit logs. The guidance emphasizes that while cloud providers secure infrastructure, organizations remain responsible for data protection and must adapt investigation approaches to rely on user-centric audit logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.