August 2026 Volume 8
OPERATIONS & MANAGEMENT QUICK GUIDE TO MICROSOFT 365 SECURITY By Jim Kerr
• Device management • Current and accurate asset reports, including workstations, servers, and other hardware help you control the potential attack surface. • Ensuring that all devices have proper security. • Data retention and backups • This is a biggie – many people mistakenly think that Microsoft automatically provides email, OneDrive, and SharePoint backup. Securing these elements requires knowledgeable professionals who understand both your business and how to configure M365. Without proper configuration, your Microsoft 365 tenant can quickly become a gateway for cyberattacks including phishing attempts, email compromises, data leaks, and more. Plus, cyber threats are evolving fast and becoming more sophisticated with AI-enhanced phishing and impersonation tactics. The Core Components of Microsoft 365 Security To secure your environment effectively, you need to understand the key layers of protection: • Identity and Access Management • Email Security Every attack starts with access, so IAM is the first line of defense. If attackers can log in, they can do significant damage without ever “hacking” anything. In short, IAM creates user identities and initial login processes, and user access management focuses on what happens after the user logs in. Your IT team should help you determine the right strategy for your business, but best practices include: • Enforcing Multi-Factor Authentication (MFA) for all users • Using Conditional Access policies to restrict risky logins and include geo-fencing • Eliminating shared accounts • Strong password policies and passkey use as appropriate. • Applying least-privilege access controls (only allowing access to the information each person needs to do their job, no more and no less) As with most security, this is not a “set it and forget it” approach. Secure IAM requires ongoing and intentional management. • Endpoint and Device Security • Data Protection and Compliance • Backup and Recovery Let’s take a look at each one. 1. Identity & Access Management (IAM)
I t’s estimated that in the United States alone, more than 1,000,000 businesses use Microsoft 365. Using M365 helps organizations be more efficient, but because so much business data lives in one platform across so many companies, M365 is a high-value target for cybercriminals. Microsoft’s Shared Responsibility Model While it may seem (mostly) easy to use, Microsoft 365 is a complex service that requires proper setup and ongoing management to function effectively. The reality is that M365, while powerful, is not fully secure on its own. It may come as a surprise that Microsoft does not handle all M365 security. Instead, Microsoft operates under a shared responsibility model. Here’s what that means for your business: • Microsoft secures the infrastructure, including application software and data centers • UAM involves two main elements – authenticating who every user is, and deciding what they’re allowed to do after they log in. • In practice, this includes adding new employees and removing former employees promptly, determining the minimum level of access required for each user to reduce the damage if an account is compromised, and more. • Email protection • This includes technical tools like anti-phishing applications and impersonation detection. • Reminding users how to identify email risks using cybersecurity awareness training. • You secure your data, users, and configurations So, your IT team is responsible for things like: • User Access Management (UAM)
48 FIA MAGAZINE | AUGUST 2026
Made with FlippingBook Annual report maker