The Exchange Online security controls organizations keep getting wrong
ID: e4a0ed5a-0f95-50e3-acfe-42618c358460
STIX ID: report--e4a0ed5a-0f95-50e3-acfe-42618c358460
Feed Name: Help Net Security
This interview with an Exchange Online expert outlines responsibilities under the cloud Shared Responsibility Model and highlights operational security gaps — notably legacy authentication (SMTP AUTH, POP, IMAP), audit log blind spots (client-side rules, legacy protocol access, token replay), the necessity of identity/access controls (Conditional Access, PIM, MFA with proper configuration), continuous monitoring, and when third-party email gateways may or may not add value.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
