logo

BEC-ware the Phish (part 3): Detect and Prevent Incidents in M365

ID: 58e61303-1644-50cb-9b5e-09b40b754f0b

STIX ID: report--58e61303-1644-50cb-9b5e-09b40b754f0b

Feed Name: Pen Test Partners Blog

Date Published: 2024-11-27

Date Updated: 2026-03-26

Author: Rachel Rabin

...
...

This guide outlines practical steps to harden Microsoft 365 against Business Email Compromise by configuring and tuning Exchange Online Protection and Defender for Office 365 threat and alert policies, using custom mail flow rules, and calibrating Defender for Cloud Apps anomaly detections (e.g., inbox manipulation, forwarding, impossible travel). It advises prioritizing technical controls over user training alone, applying KQL to identify and reduce noisy alerts, and leveraging Sentinel for centralized correlation and incident management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.