Lab 04 — Microsoft 365 Security
Microsoft 365 is much more than:
EmailA typical Microsoft 365 environment may contain:
Exchange Online
Microsoft Teams
SharePoint Online
OneDrive
Microsoft Entra ID
Microsoft Defender
Compliance and Data Protection
Audit and Security MonitoringThese services hold some of the most sensitive information in an organization.
Examples include:
Business Email
Contracts
Customer Information
Internal Documents
Credentials
Financial Data
Chat Messages
Shared FilesFor a security professional, the key question is:
Is the Microsoft 365 TenantConfigured and Monitoredto Protect Identity,Communication,Collaboration,and Data?Mission Information
Section titled “Mission Information”Lab: Microsoft 365 Security
Level: Beginner → Intermediate
Estimated Time: 180–240 minutes
Environment: Authorized Microsoft 365 training tenant
Primary Role: Microsoft 365 Security Engineer
Supporting Roles: SOC Analyst, Identity Engineer, Cloud Security Engineer, Security Consultant, Compliance Analyst
Mission Scenario
Section titled “Mission Scenario”Your organization has adopted Microsoft 365 for:
Email
Collaboration
File Storage
Remote Work
External SharingThe security team wants a structured tenant review.
You have been asked to assess:
Administrative Access
Identity Integration
Exchange Online
Email Security
Mailbox Configuration
Teams
SharePoint
OneDrive
External Sharing
Applications
Data Protection
Audit
Security Alerts
Security MonitoringYour goal is to identify:
Excessive Privilege
Weak Email Protection
Unsafe External Sharing
Uncontrolled Data Access
Suspicious Mailbox Configuration
Logging Gaps
Unreviewed Applications
Security Monitoring GapsLearning Objectives
Section titled “Learning Objectives”By completing this lab, you should be able to:
- Understand the Microsoft 365 security model
- Establish a tenant-security baseline
- Review administrative access
- Review privileged identities
- Review Exchange Online security
- Understand phishing and email protection
- Review mailbox forwarding
- Review mailbox permissions
- Review Teams security
- Review SharePoint security
- Review OneDrive security
- Assess external sharing
- Understand data-protection controls
- Review application access
- Review tenant audit capabilities
- Review security alerts
- Build Microsoft 365 security findings
- Prioritize remediation
- Produce a Microsoft 365 security assessment report
Microsoft 365 Security Mental Model
Section titled “Microsoft 365 Security Mental Model”Think:
IDENTITY ↓ADMINISTRATION ↓EMAIL ↓COLLABORATION ↓FILES ↓APPLICATIONS ↓DATA PROTECTION ↓AUDIT ↓DETECTION ↓RESPONSELab Architecture
Section titled “Lab Architecture” USERS | v Microsoft Entra ID | v Microsoft 365 | +-------------+-------------+ | | | v v v Exchange Teams SharePoint Online | | v | OneDrive | +-------------+-------------+ | v Corporate Data | v Security / Compliance | v Audit + AlertsPart 01 — Define the Assessment Scope
Section titled “Part 01 — Define the Assessment Scope”Before reviewing the tenant, document:
Tenant Name
Assessment Date
Business Owner
Technical Owner
Services in Scope
User Population
Guest Population
Critical Data Types
Critical ApplicationsExample scope:
Microsoft Entra ID
Exchange Online
Teams
SharePoint Online
OneDrive
Microsoft 365 Security Controls
Audit and MonitoringPart 02 — Understand Shared Responsibility
Section titled “Part 02 — Understand Shared Responsibility”Microsoft operates the cloud platform.
The organization remains responsible for areas such as:
Identity
Access
Configuration
Data
Sharing
Applications
Monitoring
User BehaviorA simplified model is:
Microsoft ↓Cloud InfrastructureCustomer ↓Identity + Configuration + Data + AccessPart 03 — Establish the Tenant Baseline
Section titled “Part 03 — Establish the Tenant Baseline”Before changing anything, record the existing environment.
Your baseline should cover:
Users
Administrators
Guests
Domains
Exchange
Teams
SharePoint
OneDrive
Security Policies
Audit
ApplicationsBaseline Principle
Section titled “Baseline Principle”Always know:
CURRENT STATEbefore deciding:
DESIRED STATEPart 04 — Review Tenant Domains
Section titled “Part 04 — Review Tenant Domains”Identify the organization’s accepted and verified domains.
Document:
| Domain | Purpose | Verified | Owner |
|---|---|---|---|
| example.com | Primary business | Yes | IT |
| subsidiary.example | Subsidiary | Yes | IT |
| Legacy domain | Review | Review | Review |
Ask:
Is Every Domain Still Required?
Who Owns It?
Is DNS Properly Managed?
Are Old Domains Still Trusted?Part 05 — Review Tenant Administrative Access
Section titled “Part 05 — Review Tenant Administrative Access”Microsoft 365 administrators can make high-impact changes.
Review:
Administrative Roles
Role Membership
Permanent Privilege
Emergency Access
Authentication Strength
Access Review StatusAdministrative Access Model
Section titled “Administrative Access Model”ADMINISTRATOR ↓ROLE ↓TENANT CAPABILITYThe more powerful the role:
The Strongerthe Security RequirementsShould BePart 06 — Review Privileged Accounts
Section titled “Part 06 — Review Privileged Accounts”Create:
| Administrator | Role | Required | MFA | Permanent |
|---|---|---|---|---|
| Admin-A | High Privilege | Yes | Yes | Review |
| Admin-B | Service Admin | Yes | Yes | Review |
| User-C | High Privilege | No | Review | Yes |
Ask:
Does This Identity Need This Role?
Could a Smaller Role Work?
Does Access Need to Be Permanent?Finding Example — Excessive Tenant Privilege
Section titled “Finding Example — Excessive Tenant Privilege”Finding:Excessive Microsoft 365 Administrative Access
Observation:A user retains a broad tenant administrativerole beyond the permissions required fortheir documented job responsibilities.
Risk:Compromise or misuse of the identity couldaffect multiple Microsoft 365 services andenterprise data.
Recommendation:Replace broad administrative access withthe minimum role required and periodicallyreview privileged assignments.Part 07 — Review Administrator Authentication
Section titled “Part 07 — Review Administrator Authentication”Privileged identities should use strong authentication.
Review:
MFA
Authentication Method
Conditional Access
Device Requirements
Emergency AccessHigh-Risk Combination
Section titled “High-Risk Combination”Administrative Role +Password-Only Authentication =High RiskPart 08 — Review Exchange Online
Section titled “Part 08 — Review Exchange Online”Exchange Online is a critical Microsoft 365 service.
It handles:
Email
Calendars
Contacts
Mailbox Data
Mail FlowEmail is a major security target because it is frequently used for:
Phishing
Credential Theft
Malware Delivery
Business Email Compromise
Social EngineeringPart 09 — Exchange Security Mental Model
Section titled “Part 09 — Exchange Security Mental Model”INTERNET ↓EMAIL ↓MAIL SECURITY CONTROLS ↓MAILBOX ↓USERProtect across:
Sender
Message
Attachment
Link
Mailbox
UserPart 10 — Review Accepted Domains
Section titled “Part 10 — Review Accepted Domains”Review:
Accepted Domains
Mail Domains
Legacy Domains
Unused DomainsAsk:
Is Every Mail Domain Expected?
Is Ownership Clear?
Are Old Domains Still Active?Part 11 — Review Mail Flow Rules
Section titled “Part 11 — Review Mail Flow Rules”Mail-flow rules can influence:
Routing
Message Handling
Headers
Filtering
External CommunicationReview all important rules.
For each record:
Rule Name
Purpose
Owner
Conditions
Actions
ExceptionsSecurity Concern
Section titled “Security Concern”A powerful mail-flow rule can accidentally:
Bypass Security
Redirect Email
Alter Message HandlingPart 12 — Review Email Forwarding
Section titled “Part 12 — Review Email Forwarding”Automatic forwarding deserves special attention.
Potential scenario:
Mailbox ↓Automatic Forwarding ↓External AddressThis may be legitimate.
It may also indicate:
Misconfiguration
Data Leakage
Mailbox CompromiseForwarding Review Questions
Section titled “Forwarding Review Questions”Ask:
Which Mailboxes Forward?
Where?
Who Approved It?
Why?
Is the Destination External?
Is It Still Required?Finding Example — External Forwarding
Section titled “Finding Example — External Forwarding”Finding:Unapproved External Mail Forwarding
Observation:A user mailbox automatically forwardsmessages to an external address withoutdocumented business approval.
Risk:Corporate email and potentially sensitiveinformation may leave the organization'smanaged environment.
Recommendation:Remove unapproved forwarding and establisha controlled approval process for externalmail forwarding.Part 13 — Review Mailbox Delegation
Section titled “Part 13 — Review Mailbox Delegation”Mailbox access may be delegated to others.
Review:
Full Access
Send As
Send on BehalfAsk:
Who Has Access?
Why?
Was It Approved?
Is the Original Business RequirementStill Valid?Part 14 — Shared Mailboxes
Section titled “Part 14 — Shared Mailboxes”Shared mailboxes may support:
Finance
HR
Support
Sales
OperationsReview:
Owners
Members
Delegation
Business Purpose
External Forwarding
LifecyclePart 15 — Review Email Authentication
Section titled “Part 15 — Review Email Authentication”Modern email security relies on domain-level controls.
Understand:
SPF
DKIM
DMARCEmail Authentication Model
Section titled “Email Authentication Model”SPF ↓Who Is Allowed to Send?DKIM ↓Was the Message Cryptographically Signed?DMARC ↓What Should Receivers DoWhen Authentication Fails?Important
Section titled “Important”These controls reduce domain impersonation risk but do not eliminate phishing.
Part 16 — Review SPF
Section titled “Part 16 — Review SPF”Check whether business domains have an appropriate SPF policy.
Security questions:
Which Systems Are Authorized to Send?
Are Old Providers Still Included?
Is the Record Overly Broad?
Are Multiple Third Parties Included?Part 17 — Review DKIM
Section titled “Part 17 — Review DKIM”Assess whether approved domains use DKIM where required.
Ask:
Is DKIM Enabled?
Which Domains Use It?
Are Signing Configurations Current?Part 18 — Review DMARC
Section titled “Part 18 — Review DMARC”Review the organization’s DMARC strategy.
Understand the progression conceptually:
MONITOR ↓UNDERSTAND MAIL SOURCES ↓ENFORCE APPROPRIATE POLICYAvoid deploying strict email-authentication policy blindly without understanding legitimate mail sources.
Part 19 — Review Anti-Phishing Controls
Section titled “Part 19 — Review Anti-Phishing Controls”Review tenant controls addressing:
Impersonation
Spoofing
Phishing
Malicious URLs
Malicious Attachmentsdepending on the tenant’s available security capabilities.
Security Objective
Section titled “Security Objective”Reduce the chance that:
ATTACKER ↓FAKE EMAIL ↓USER ↓CREDENTIAL THEFTsucceeds.
Part 20 — Safe Links Concept
Section titled “Part 20 — Safe Links Concept”Link-protection technologies may help evaluate potentially malicious URLs.
Think:
EMAIL LINK ↓SECURITY EVALUATION ↓USER ACCESSPart 21 — Safe Attachments Concept
Section titled “Part 21 — Safe Attachments Concept”Attachment-protection capabilities may inspect or analyze suspicious files.
Think:
ATTACHMENT ↓SECURITY ANALYSIS ↓ALLOW / BLOCK / DETONATEdepending on the available configuration.
Part 22 — Review Anti-Spam Protection
Section titled “Part 22 — Review Anti-Spam Protection”Review controls addressing:
Spam
Bulk Mail
Spoofing
Suspicious SendersDo not evaluate spam policy only by asking:
Is Spam Blocked?Also ask:
How Are False Positives Handled?
Who Can Release Messages?
Are Allow Lists Controlled?Part 23 — Review Allow Lists
Section titled “Part 23 — Review Allow Lists”Security teams should pay special attention to:
Allowed Senders
Allowed Domains
Security Bypasses
Transport Exceptionsbecause excessive allow-listing may weaken filtering.
Finding Example — Broad Allow List
Section titled “Finding Example — Broad Allow List”Finding:Overly Broad Email Security Exception
Observation:A broad sender or domain exception bypassesnormal email-security controls.
Risk:Messages from the exempted source mayreceive reduced inspection, increasing theimpact of source compromise or spoofing.
Recommendation:Remove broad exceptions where possible anduse narrowly scoped, documented exceptionsonly when required.Part 24 — Review Quarantine Governance
Section titled “Part 24 — Review Quarantine Governance”Review:
Who Can Access Quarantine?
Who Can Release Messages?
Are Administrative Releases Audited?
Are Users Allowed to Release High-RiskMessage Types?Part 25 — Business Email Compromise Scenario
Section titled “Part 25 — Business Email Compromise Scenario”Scenario:
Finance Executive ↓Account Compromised ↓Attacker Sends Payment RequestInvestigation should consider:
Sign-In Activity
Inbox Rules
Forwarding
Sent Mail
Authentication Methods
Mailbox Delegation
Session ActivityPart 26 — Review Inbox Rules
Section titled “Part 26 — Review Inbox Rules”Mailbox rules can be abused to:
Hide Messages
Delete Alerts
Move Email
Forward InformationReview suspicious or unexpected rules.
Security questions:
Who Created the Rule?
What Does It Do?
When Was It Created?
Does the User Recognize It?Part 27 — Suspicious Mailbox Rule Finding
Section titled “Part 27 — Suspicious Mailbox Rule Finding”Finding:Unrecognized Mailbox Processing Rule
Observation:A mailbox contains a rule that redirects orhides messages without a documented user orbusiness requirement.
Risk:A malicious or unauthorized rule could hidesecurity notifications or redirect sensitivecommunications.
Recommendation:Validate the rule with the mailbox owner,remove unauthorized rules, and review recentmailbox and sign-in activity.Part 28 — Review Microsoft Teams Security
Section titled “Part 28 — Review Microsoft Teams Security”Microsoft Teams combines:
Chat
Meetings
Files
Applications
External CollaborationThis means Teams security touches:
Identity
Data
Sharing
Applications
GuestsPart 29 — Review Teams External Access
Section titled “Part 29 — Review Teams External Access”Assess:
External Users
Federation
Guest Access
Meeting Access
Anonymous ParticipationAsk:
Is External Collaboration Required?
Who Can Use It?
Which Controls Apply?
Is Access Reviewed?Part 30 — Review Teams Guest Access
Section titled “Part 30 — Review Teams Guest Access”Guest access should have:
Sponsor
Business Need
Defined Scope
Review
ExpirationFinding Example — Unreviewed Guest Access
Section titled “Finding Example — Unreviewed Guest Access”Finding:Unreviewed Microsoft Teams Guest Access
Observation:External guest users retain access to Teamsresources after the associated businessengagement has ended.
Risk:External parties may continue accessingcorporate conversations and shared fileswithout current authorization.
Recommendation:Implement sponsor-based guest reviews andremove external access when the businessneed expires.Part 31 — Review Teams Applications
Section titled “Part 31 — Review Teams Applications”Teams can integrate third-party and custom applications.
Review:
Installed Applications
Allowed Applications
Blocked Applications
Application Owners
Business Need
Data AccessApplication Risk
Section titled “Application Risk”An application may access:
Messages
Files
User Information
External Servicesdepending on permissions.
Part 32 — Review Meeting Policies
Section titled “Part 32 — Review Meeting Policies”Assess relevant meeting controls such as:
Anonymous Access
Recording
External Participants
Screen Sharing
Lobby BehaviorApply based on business need and data sensitivity.
Part 33 — Review SharePoint Online
Section titled “Part 33 — Review SharePoint Online”SharePoint often stores:
Policies
Project Documents
Financial Information
Business Records
Shared Team FilesSharePoint Security Model
Section titled “SharePoint Security Model”SITE ↓OWNERS ↓MEMBERS ↓VISITORS ↓FILESPart 34 — Review SharePoint Sites
Section titled “Part 34 — Review SharePoint Sites”Inventory important sites.
Capture:
| Site | Owner | Sensitivity | External Sharing | Review |
|---|---|---|---|---|
| Finance | Finance | High | Restricted | Current |
| Project-A | Project Team | Medium | Enabled | Review |
| Legacy | Unknown | Unknown | Review | Review |
Part 35 — Review Site Ownership
Section titled “Part 35 — Review Site Ownership”Every business-critical SharePoint site should have:
Known Owner
Business Purpose
Appropriate Membership
Defined Sharing PolicyOrphaned Site Risk
Section titled “Orphaned Site Risk”Site Exists +No Owner =Governance ProblemPart 36 — Review Site Permissions
Section titled “Part 36 — Review Site Permissions”Review:
Owners
Members
Visitors
Guests
Direct Permissions
Sharing LinksAsk:
Who Can Read?
Who Can Edit?
Who Can Manage?
Who Can Share?Part 37 — Review External Sharing
Section titled “Part 37 — Review External Sharing”External sharing is useful but high impact.
Possible scenarios:
Specific People
Authenticated Guests
Broad Sharing Linksdepending on configuration.
Security Principle
Section titled “Security Principle”For sensitive information:
THE MORE SENSITIVE THE DATA ↓THE MORE CONTROLLED THE SHARINGPart 38 — Sharing Link Review
Section titled “Part 38 — Sharing Link Review”Look for links that may be:
Broad
Long-Lived
Unowned
No Longer RequiredFinding Example — Excessive Sharing
Section titled “Finding Example — Excessive Sharing”Finding:Excessive External File Sharing
Observation:Sensitive content is accessible through asharing method broader than required by thedocumented business use case.
Risk:Corporate information may be accessed byunintended recipients or remain accessibleafter the original collaboration ends.
Recommendation:Restrict sharing to explicitly authorizedusers and periodically review activeexternal-sharing links.Part 39 — Review OneDrive
Section titled “Part 39 — Review OneDrive”OneDrive often contains individual user files.
Review:
Sharing
External Links
Sensitive Data
Offboarding
Ownership TransferOneDrive Lifecycle Question
Section titled “OneDrive Lifecycle Question”When an employee leaves:
Who Owns Required Business Data?
How Is It Preserved?
How Is Access Removed?
How Long Is It Retained?Part 40 — OneDrive Sharing Scenario
Section titled “Part 40 — OneDrive Sharing Scenario”Scenario:
Employee Creates External Linkto Confidential SpreadsheetReview:
Data Sensitivity
Recipients
Link Type
Expiration
Business NeedPart 41 — Data Classification
Section titled “Part 41 — Data Classification”Security decisions improve when data is classified.
Example model:
PUBLIC
INTERNAL
CONFIDENTIAL
HIGHLY CONFIDENTIALData Protection Relationship
Section titled “Data Protection Relationship”CLASSIFICATION ↓HANDLING REQUIREMENT ↓ACCESS ↓SHARING ↓PROTECTIONPart 42 — Sensitivity Labels Concept
Section titled “Part 42 — Sensitivity Labels Concept”Sensitivity labels can help classify and protect information.
Depending on configuration, they may influence:
Marking
Encryption
Sharing
Access
Container SettingsImportant
Section titled “Important”Classification is useful only when:
Users Understand It
Policies Support It
Controls Are EnforcedPart 43 — Data Loss Prevention
Section titled “Part 43 — Data Loss Prevention”DLP aims to reduce inappropriate handling of sensitive information.
A simple model:
SENSITIVE DATA ↓USER ACTION ↓DLP EVALUATION ↓ALLOW / WARN / RESTRICTPossible Data Types
Section titled “Possible Data Types”Organizations may protect:
Financial Information
Personal Information
Customer Data
Credentials
Health Information
Intellectual Propertyaccording to business and regulatory needs.
Part 44 — DLP Scenario
Section titled “Part 44 — DLP Scenario”Scenario:
Employee Attemptsto Share Sensitive DataExternallyA DLP policy may:
Detect
Warn
Require Justification
Restrictdepending on policy design.
Part 45 — Retention Concepts
Section titled “Part 45 — Retention Concepts”Retention controls help organizations manage:
How Long Data Is Kept
When Data Can Be Deleted
Regulatory Requirements
Business RecordsSecurity vs Retention
Section titled “Security vs Retention”Do not confuse:
Retentionwith:
BackupThey serve different objectives.
Part 46 — Review Application Access
Section titled “Part 46 — Review Application Access”Microsoft 365 can integrate with:
SaaS Apps
Automation
Add-Ins
Enterprise Applications
Custom ApplicationsReview:
Owner
Permissions
Users
Consent
Business PurposePart 47 — Application Consent
Section titled “Part 47 — Application Consent”Application consent may grant access to:
User Profiles
Mail
Files
Calendars
Directories
Other Datadepending on permissions.
Security Question
Section titled “Security Question”Ask:
Does the ApplicationActually Need This Permission?Finding Example — Excessive Application Access
Section titled “Finding Example — Excessive Application Access”Finding:Third-Party Application Has Excessive Access
Observation:A connected application possessespermissions broader than required for itsdocumented business purpose.
Risk:Compromise or misuse of the applicationcould expose Microsoft 365 data beyond theintended scope.
Recommendation:Review and reduce application permissionsto the minimum required and establishperiodic application-access reviews.Part 48 — Review Audit Capabilities
Section titled “Part 48 — Review Audit Capabilities”Audit records help answer:
Who Did What?
When?
From Where?
To Which Resource?Important activities may include:
Administrative Changes
Mailbox Activity
File Sharing
User Changes
Application Changes
Security EventsPart 49 — Audit Mental Model
Section titled “Part 49 — Audit Mental Model”ACTION ↓USER / ADMIN / APP ↓RESOURCE ↓TIME ↓AUDIT RECORD ↓INVESTIGATIONPart 50 — Review Unified Audit Activity
Section titled “Part 50 — Review Unified Audit Activity”Using the approved Microsoft 365/Purview audit interface available in the training environment, review recent events.
Focus on:
Privileged Changes
Mailbox Actions
Sharing Changes
Application Changes
User AdministrationPart 51 — Build a Simple Timeline
Section titled “Part 51 — Build a Simple Timeline”Example:
09:12 Suspicious Sign-In
09:18 Mailbox Rule Created
09:22 External Forwarding Added
09:30 Sensitive Email AccessedNow you have:
Eventsturned into:
Incident ContextPart 52 — Review Security Alerts
Section titled “Part 52 — Review Security Alerts”Security platforms may generate alerts related to:
Phishing
Malware
Suspicious Identity
Mailbox Activity
Applications
Datadepending on services enabled.
Alert Triage Model
Section titled “Alert Triage Model”ALERT ↓IDENTITY ↓RESOURCE ↓ACTIVITY ↓EVIDENCE ↓SCOPE ↓DECISIONPart 53 — Alert Does Not Equal Incident
Section titled “Part 53 — Alert Does Not Equal Incident”Remember:
Alert≠Confirmed CompromiseYou need:
Context
Evidence
Timeline
ImpactPart 54 — Phishing Investigation Scenario
Section titled “Part 54 — Phishing Investigation Scenario”Scenario:
User Reports Suspicious EmailReview:
Sender
Recipient
Subject
Links
Attachments
Authentication Results
Other Recipients
User InteractionThen determine:
Was It Delivered Elsewhere?
Did Anyone Click?
Was Credential Access Attempted?
Did Sign-In Activity Change?Part 55 — Compromised Mailbox Scenario
Section titled “Part 55 — Compromised Mailbox Scenario”Indicators:
Unusual Sign-In
New Inbox Rule
External Forwarding
Unexpected Sent Mail
Authentication ChangeInvestigation sequence:
IDENTITY ↓SIGN-IN ↓MAILBOX ↓RULES ↓FORWARDING ↓SENT ITEMS ↓SESSIONS ↓IMPACTPart 56 — External Sharing Scenario
Section titled “Part 56 — External Sharing Scenario”Scenario:
Sensitive FileShared Outside OrganizationReview:
File
Owner
Recipient
Sharing Method
Timestamp
Sensitivity
Business ApprovalPart 57 — Administrative Change Scenario
Section titled “Part 57 — Administrative Change Scenario”Scenario:
Security Policy ChangedInvestigate:
Who Changed It?
When?
What Changed?
Was It Approved?
What Was the Security Impact?Part 58 — Build Administrative Access Matrix
Section titled “Part 58 — Build Administrative Access Matrix”| Identity | Role | MFA | Required | Review |
|---|---|---|---|---|
| Admin-A | High Privilege | Yes | Yes | Current |
| Admin-B | Exchange Admin | Yes | Yes | Current |
| User-C | High Privilege | Review | No | Remove/Review |
Part 59 — Build Exchange Security Matrix
Section titled “Part 59 — Build Exchange Security Matrix”| Control | Expected | Actual | Result |
|---|---|---|---|
| External Forwarding | Restricted | Review | |
| Mailbox Delegation | Approved | Review | |
| Email Authentication | Configured | Review | |
| Anti-Phishing | Enabled | Review | |
| Security Exceptions | Minimal | Review |
Part 60 — Build Collaboration Matrix
Section titled “Part 60 — Build Collaboration Matrix”| Service | External Access | Owners | Sensitive Data | Review |
|---|---|---|---|---|
| Teams | Review | Known | Medium | |
| SharePoint | Review | Known | High | |
| OneDrive | Review | User | Variable |
Part 61 — Build Sharing Inventory
Section titled “Part 61 — Build Sharing Inventory”| Resource | Owner | External | Link Type | Expiration | Action |
|---|---|---|---|---|---|
| Finance Site | Finance | No | N/A | N/A | None |
| Project Doc | Project | Yes | Specific | Review | Review |
| Old File | Unknown | Yes | Broad | None | Remove/Review |
Part 62 — Build Application Access Matrix
Section titled “Part 62 — Build Application Access Matrix”| Application | Owner | Permissions | Required | Review |
|---|---|---|---|---|
| App-A | Finance | Limited | Yes | Current |
| App-B | Unknown | Broad | Review | Investigate |
| App-C | IT | Limited | Yes | Current |
Part 63 — Build Data Protection Matrix
Section titled “Part 63 — Build Data Protection Matrix”| Data Type | Classification | External Sharing | DLP | Owner |
|---|---|---|---|---|
| Financial | Confidential | Restricted | Required | Finance |
| HR | Confidential | Restricted | Required | HR |
| Public Content | Public | Allowed | Basic | Marketing |
Part 64 — Establish Microsoft 365 Security Baseline
Section titled “Part 64 — Establish Microsoft 365 Security Baseline”A practical baseline might include:
| Area | Expected State |
|---|---|
| Privileged Accounts | Strongly protected |
| Admin Roles | Least privilege |
| External Forwarding | Controlled |
| Email Authentication | Configured |
| Email Security | Enabled |
| Guest Access | Reviewed |
| External Sharing | Controlled |
| Application Permissions | Least privilege |
| Audit | Enabled/Available |
| Security Alerts | Monitored |
Part 65 — Compare Baseline to Actual State
Section titled “Part 65 — Compare Baseline to Actual State”Example:
| Control | Expected | Actual | Result |
|---|---|---|---|
| Admin MFA | Required | Enabled | Pass |
| Forwarding | Restricted | External found | Fail |
| Guest Review | Current | Stale guests | Fail |
| App Permissions | Minimum | Broad access | Fail |
| Audit | Available | Available | Pass |
Part 66 — Prioritize Findings
Section titled “Part 66 — Prioritize Findings”Use factors such as:
Privilege
Data Sensitivity
External Exposure
Exploitability
Business Impact
Monitoring
Compensating ControlsExample
Section titled “Example”External Forwarding +Executive Mailbox +Sensitive Data +No Business Approval ↓High PriorityPart 67 — Finding: Excessive Privilege
Section titled “Part 67 — Finding: Excessive Privilege”Finding:Excessive Microsoft 365 Administrative Role
Observation:A user has tenant-level administrativeprivilege beyond their documentedresponsibilities.
Risk:Account compromise may result in broadimpact across Microsoft 365 services.
Recommendation:Apply least privilege and removeunnecessary administrative assignments.Part 68 — Finding: External Forwarding
Section titled “Part 68 — Finding: External Forwarding”Finding:Unapproved External Mail Forwarding
Observation:A mailbox forwards corporate messages toan external destination without documentedapproval.
Risk:Sensitive communications may leave themanaged Microsoft 365 environment.
Recommendation:Disable unapproved forwarding and establisha controlled exception process.Part 69 — Finding: Stale Guest
Section titled “Part 69 — Finding: Stale Guest”Finding:Stale Microsoft 365 Guest Access
Observation:An external user retains collaborationaccess after the associated businessengagement has ended.
Risk:The guest may continue accessing corporatefiles or conversations without currentauthorization.
Recommendation:Remove stale guest access and implementrecurring sponsor-based access reviews.Part 70 — Finding: Broad File Sharing
Section titled “Part 70 — Finding: Broad File Sharing”Finding:Excessive External Sharing
Observation:Sensitive files can be accessed throughsharing permissions broader than thebusiness requirement.
Risk:Information may be disclosed to unintendedrecipients.
Recommendation:Restrict sharing to approved users andreview existing external links.Part 71 — Finding: Application Permission
Section titled “Part 71 — Finding: Application Permission”Finding:Over-Privileged Microsoft 365 Application
Observation:A connected application has access to dataor services beyond what its documentedfunction requires.
Risk:Compromise or misuse of the applicationcould affect a larger portion of theMicrosoft 365 environment.
Recommendation:Reduce application permissions to theminimum required and periodically reviewaccess.Part 72 — Finding: Monitoring Gap
Section titled “Part 72 — Finding: Monitoring Gap”Finding:Microsoft 365 Security Monitoring Gap
Observation:Critical tenant activities are logged butare not routinely reviewed or connected toan established security-monitoring process.
Risk:Suspicious administrative, identity, ordata-access activity may not be identifiedin a timely manner.
Recommendation:Define monitoring requirements forcritical Microsoft 365 events and integratethem into the organization's securityoperations workflow.Part 73 — Microsoft 365 Security Report
Section titled “Part 73 — Microsoft 365 Security Report”Your report should contain:
1. Executive Summary
Section titled “1. Executive Summary”Document:
Tenant Assessed
Overall Security Posture
Critical Findings
Immediate Priorities2. Administrative Security
Section titled “2. Administrative Security”Include:
Administrative Roles
MFA
Least Privilege
Permanent Privilege
Emergency Access3. Exchange Online
Section titled “3. Exchange Online”Document:
Mail Flow
Forwarding
Mailbox Delegation
Inbox Rules
Shared Mailboxes4. Email Protection
Section titled “4. Email Protection”Document:
SPF
DKIM
DMARC
Anti-Phishing
Anti-Malware
Security Exceptions5. Teams
Section titled “5. Teams”Document:
Guest Access
External Access
Applications
Meeting Security6. SharePoint and OneDrive
Section titled “6. SharePoint and OneDrive”Document:
Site Ownership
Permissions
External Sharing
Sharing Links
Sensitive Data7. Applications
Section titled “7. Applications”Document:
Connected Applications
Owners
Permissions
Consent
Business Purpose8. Data Protection
Section titled “8. Data Protection”Document:
Classification
Sensitivity
DLP
Retention
Sharing Controls9. Monitoring
Section titled “9. Monitoring”Document:
Audit
Security Alerts
Mailbox Activity
Administrative Changes
Incident Visibility10. Findings
Section titled “10. Findings”For each finding include:
Finding ID
Title
Severity
Observation
Evidence
Risk
Recommendation
Owner
Target Date
ValidationPart 74 — Microsoft 365 Security Checklist
Section titled “Part 74 — Microsoft 365 Security Checklist”Tenant
Section titled “Tenant”- Defined tenant scope
- Reviewed domains
- Identified critical services
- Identified business owners
Administration
Section titled “Administration”- Reviewed administrative roles
- Reviewed privileged users
- Reviewed authentication
- Reviewed permanent privilege
- Reviewed emergency access
Exchange Online
Section titled “Exchange Online”- Reviewed accepted domains
- Reviewed mail-flow rules
- Reviewed external forwarding
- Reviewed mailbox delegation
- Reviewed shared mailboxes
- Reviewed suspicious mailbox rules
Email Security
Section titled “Email Security”- Reviewed SPF
- Reviewed DKIM
- Reviewed DMARC
- Reviewed anti-phishing controls
- Reviewed malware protection
- Reviewed URL protection
- Reviewed security exceptions
- Reviewed quarantine governance
- Reviewed external access
- Reviewed guest access
- Reviewed meeting controls
- Reviewed Teams applications
- Reviewed guest lifecycle
SharePoint
Section titled “SharePoint”- Reviewed important sites
- Reviewed owners
- Reviewed members
- Reviewed guests
- Reviewed external sharing
- Reviewed broad links
OneDrive
Section titled “OneDrive”- Reviewed sharing
- Reviewed external access
- Reviewed sensitive data
- Reviewed offboarding process
Applications
Section titled “Applications”- Reviewed enterprise applications
- Reviewed owners
- Reviewed permissions
- Reviewed consent
- Identified excessive access
Data Protection
Section titled “Data Protection”- Reviewed classification
- Reviewed sensitivity labels
- Reviewed DLP concepts
- Reviewed retention
- Reviewed sensitive external sharing
Monitoring
Section titled “Monitoring”- Reviewed audit activity
- Reviewed security alerts
- Reviewed administrative changes
- Reviewed mailbox activity
- Reviewed sharing activity
- Created investigation timelines
Reporting
Section titled “Reporting”- Created admin-access matrix
- Created Exchange security matrix
- Created collaboration matrix
- Created sharing inventory
- Created application matrix
- Created data-protection matrix
- Documented findings
- Produced final report
Common Microsoft 365 Security Mistakes
Section titled “Common Microsoft 365 Security Mistakes”Avoid:
Too Many Tenant Administrators
Weak Administrator Authentication
Uncontrolled Email Forwarding
Ignoring Mailbox Rules
Broad Email Security Exceptions
Unreviewed Guest Accounts
Anonymous or Broad Sharing Without Need
Unknown SharePoint Owners
Excessive Application Permissions
Ignoring Third-Party Applications
Treating Audit as Monitoring
Ignoring Sensitive Data Classification
Keeping Old Collaboration Access ForeverMicrosoft 365 Security Maturity Model
Section titled “Microsoft 365 Security Maturity Model”Level 1 — Basic
Section titled “Level 1 — Basic”Users
Email
File Sharing
Basic AdministrationLevel 2 — Controlled
Section titled “Level 2 — Controlled”MFA
Email Protection
Sharing Restrictions
Least PrivilegeLevel 3 — Managed
Section titled “Level 3 — Managed”Guest Reviews
Application Governance
Data Classification
DLP
Central MonitoringLevel 4 — Integrated Security
Section titled “Level 4 — Integrated Security”Identity Risk
Advanced Email Protection
Data Governance
Automated Detection
Incident Response
Continuous Access ReviewCareer Connection
Section titled “Career Connection”This lab directly supports:
Microsoft 365 Security Engineer
Microsoft Security Engineer
SOC Analyst
Cloud Security Engineer
Identity Security Engineer
Security Consultant
Compliance Analyst
Security AdministratorInterview Scenario 01
Section titled “Interview Scenario 01”Why is Microsoft 365 security more than email security?
Because Microsoft 365 also contains:
Identity
Collaboration
Files
Applications
Data Protection
Audit
Security MonitoringInterview Scenario 02
Section titled “Interview Scenario 02”Why is external mailbox forwarding a security concern?
Because corporate messages may leave the managed environment and could expose sensitive business information.
Interview Scenario 03
Section titled “Interview Scenario 03”What are SPF, DKIM, and DMARC used for?
They support email-domain authentication and help reduce sender impersonation and spoofing risk.
Interview Scenario 04
Section titled “Interview Scenario 04”Why are SharePoint sharing links important during a security assessment?
Because overly broad or long-lived links may expose corporate information beyond the intended audience.
Interview Scenario 05
Section titled “Interview Scenario 05”What would you investigate after a suspected mailbox compromise?
Review:
Sign-Ins
Authentication Methods
Sessions
Inbox Rules
Forwarding
Delegation
Sent Mail
Audit Activity40 Microsoft 365 Security Interview Questions
Section titled “40 Microsoft 365 Security Interview Questions”- What is Microsoft 365 security?
- Which major services exist in Microsoft 365?
- Why is identity important to Microsoft 365 security?
- What is least privilege?
- Why should tenant administrators be limited?
- Why is strong MFA important for administrators?
- What is Exchange Online?
- Why is email a major attack vector?
- What is phishing?
- What is business email compromise?
- What is external mail forwarding?
- Why should mailbox forwarding be reviewed?
- What is mailbox delegation?
- What is an inbox rule?
- How can mailbox rules be abused?
- What is SPF?
- What is DKIM?
- What is DMARC?
- What is anti-phishing protection?
- Why are broad mail-security exceptions risky?
- What is Microsoft Teams guest access?
- What is Teams external access?
- Why should Teams applications be reviewed?
- What is SharePoint Online?
- What is OneDrive?
- Why is external file sharing risky?
- What is a sharing link?
- Why should SharePoint sites have owners?
- What is data classification?
- What is a sensitivity label?
- What is DLP?
- What is data retention?
- What is application consent?
- Why should application permissions be reviewed?
- What is Microsoft 365 audit activity?
- What is a security alert?
- Why does an alert not automatically mean compromise?
- How would you investigate a suspicious mailbox?
- How would you assess Microsoft 365 external sharing?
- How would you perform a Microsoft 365 security assessment?
Final Microsoft 365 Security Mental Model
Section titled “Final Microsoft 365 Security Mental Model”When assessing a tenant, ask:
WHO ADMINISTERS IT? ↓HOW ARE ADMINS PROTECTED? ↓HOW IS EMAIL PROTECTED? ↓WHO CAN FORWARD MAIL? ↓WHO CAN ACCESS MAILBOXES? ↓WHO CAN COLLABORATE EXTERNALLY? ↓WHO CAN SHARE FILES? ↓WHAT APPLICATIONS HAVE ACCESS? ↓HOW IS SENSITIVE DATA PROTECTED? ↓WHAT IS AUDITED? ↓WHAT IS MONITORED?Mission Accomplished
Section titled “Mission Accomplished”You have now assessed Microsoft 365 security across:
Administrative Access
Exchange Online
Email Security
Mailbox Configuration
Teams
SharePoint
OneDrive
External Sharing
Applications
Data Protection
Audit
Security AlertsThe key lesson is:
Microsoft 365 SecurityIs the Protection ofIdentity + Communication + Collaboration + Datanot simply the configuration of email filters.
What’s Next?
Section titled “What’s Next?”➡️ Lab 05 — Windows Security
In the final Microsoft lab, you will move deeper into Windows host security and assess:
Windows Security Architecture ↓Local Security Configuration ↓User Rights ↓Authentication ↓Windows Defender ↓Firewall ↓BitLocker ↓Audit Policy ↓PowerShell Security ↓Services ↓Persistence ↓Security Logs ↓Hardening ↓Security FindingsYour Microsoft path continues:
Lab 01 — Active Directory ↓Lab 02 — Endpoint Security ↓Lab 03 — Identity Security ↓Lab 04 — Microsoft 365 Security ↓Lab 05 — Windows Security ↓Runbook 01 — Active Directory Assessment ↓Runbook 02 — Microsoft 365 Security Review ↓Runbook 03 — Windows Security Assessment