Skip to content

Lab 04 — Microsoft 365 Security

Microsoft 365 is much more than:

Email

A typical Microsoft 365 environment may contain:

Exchange Online
Microsoft Teams
SharePoint Online
OneDrive
Microsoft Entra ID
Microsoft Defender
Compliance and Data Protection
Audit and Security Monitoring

These services hold some of the most sensitive information in an organization.

Examples include:

Business Email
Contracts
Customer Information
Internal Documents
Credentials
Financial Data
Chat Messages
Shared Files

For a security professional, the key question is:

Is the Microsoft 365 Tenant
Configured and Monitored
to Protect Identity,
Communication,
Collaboration,
and Data?

Lab: Microsoft 365 Security
Level: Beginner → Intermediate
Estimated Time: 180–240 minutes
Environment: Authorized Microsoft 365 training tenant
Primary Role: Microsoft 365 Security Engineer
Supporting Roles: SOC Analyst, Identity Engineer, Cloud Security Engineer, Security Consultant, Compliance Analyst

Your organization has adopted Microsoft 365 for:

Email
Collaboration
File Storage
Remote Work
External Sharing

The security team wants a structured tenant review.

You have been asked to assess:

Administrative Access
Identity Integration
Exchange Online
Email Security
Mailbox Configuration
Teams
SharePoint
OneDrive
External Sharing
Applications
Data Protection
Audit
Security Alerts
Security Monitoring

Your goal is to identify:

Excessive Privilege
Weak Email Protection
Unsafe External Sharing
Uncontrolled Data Access
Suspicious Mailbox Configuration
Logging Gaps
Unreviewed Applications
Security Monitoring Gaps

By completing this lab, you should be able to:

  • Understand the Microsoft 365 security model
  • Establish a tenant-security baseline
  • Review administrative access
  • Review privileged identities
  • Review Exchange Online security
  • Understand phishing and email protection
  • Review mailbox forwarding
  • Review mailbox permissions
  • Review Teams security
  • Review SharePoint security
  • Review OneDrive security
  • Assess external sharing
  • Understand data-protection controls
  • Review application access
  • Review tenant audit capabilities
  • Review security alerts
  • Build Microsoft 365 security findings
  • Prioritize remediation
  • Produce a Microsoft 365 security assessment report

Think:

IDENTITY
ADMINISTRATION
EMAIL
COLLABORATION
FILES
APPLICATIONS
DATA PROTECTION
AUDIT
DETECTION
RESPONSE
USERS
|
v
Microsoft Entra ID
|
v
Microsoft 365
|
+-------------+-------------+
| | |
v v v
Exchange Teams SharePoint
Online |
| v
| OneDrive
|
+-------------+-------------+
|
v
Corporate Data
|
v
Security / Compliance
|
v
Audit + Alerts

Before reviewing the tenant, document:

Tenant Name
Assessment Date
Business Owner
Technical Owner
Services in Scope
User Population
Guest Population
Critical Data Types
Critical Applications

Example scope:

Microsoft Entra ID
Exchange Online
Teams
SharePoint Online
OneDrive
Microsoft 365 Security Controls
Audit and Monitoring

Part 02 — Understand Shared Responsibility

Section titled “Part 02 — Understand Shared Responsibility”

Microsoft operates the cloud platform.

The organization remains responsible for areas such as:

Identity
Access
Configuration
Data
Sharing
Applications
Monitoring
User Behavior

A simplified model is:

Microsoft
Cloud Infrastructure
Customer
Identity + Configuration + Data + Access

Before changing anything, record the existing environment.

Your baseline should cover:

Users
Administrators
Guests
Domains
Exchange
Teams
SharePoint
OneDrive
Security Policies
Audit
Applications

Always know:

CURRENT STATE

before deciding:

DESIRED STATE

Identify the organization’s accepted and verified domains.

Document:

Domain Purpose Verified Owner
example.com Primary business Yes IT
subsidiary.example Subsidiary Yes IT
Legacy domain Review Review Review

Ask:

Is Every Domain Still Required?
Who Owns It?
Is DNS Properly Managed?
Are Old Domains Still Trusted?

Part 05 — Review Tenant Administrative Access

Section titled “Part 05 — Review Tenant Administrative Access”

Microsoft 365 administrators can make high-impact changes.

Review:

Administrative Roles
Role Membership
Permanent Privilege
Emergency Access
Authentication Strength
Access Review Status
ADMINISTRATOR
ROLE
TENANT CAPABILITY

The more powerful the role:

The Stronger
the Security Requirements
Should Be

Create:

Administrator Role Required MFA Permanent
Admin-A High Privilege Yes Yes Review
Admin-B Service Admin Yes Yes Review
User-C High Privilege No Review Yes

Ask:

Does This Identity Need This Role?
Could a Smaller Role Work?
Does Access Need to Be Permanent?

Finding Example — Excessive Tenant Privilege

Section titled “Finding Example — Excessive Tenant Privilege”
Finding:
Excessive Microsoft 365 Administrative Access
Observation:
A user retains a broad tenant administrative
role beyond the permissions required for
their documented job responsibilities.
Risk:
Compromise or misuse of the identity could
affect multiple Microsoft 365 services and
enterprise data.
Recommendation:
Replace broad administrative access with
the minimum role required and periodically
review privileged assignments.

Part 07 — Review Administrator Authentication

Section titled “Part 07 — Review Administrator Authentication”

Privileged identities should use strong authentication.

Review:

MFA
Authentication Method
Conditional Access
Device Requirements
Emergency Access
Administrative Role
+
Password-Only Authentication
=
High Risk

Exchange Online is a critical Microsoft 365 service.

It handles:

Email
Calendars
Contacts
Mailbox Data
Mail Flow

Email is a major security target because it is frequently used for:

Phishing
Credential Theft
Malware Delivery
Business Email Compromise
Social Engineering

Part 09 — Exchange Security Mental Model

Section titled “Part 09 — Exchange Security Mental Model”
INTERNET
EMAIL
MAIL SECURITY CONTROLS
MAILBOX
USER

Protect across:

Sender
Message
Attachment
Link
Mailbox
User

Review:

Accepted Domains
Mail Domains
Legacy Domains
Unused Domains

Ask:

Is Every Mail Domain Expected?
Is Ownership Clear?
Are Old Domains Still Active?

Mail-flow rules can influence:

Routing
Message Handling
Headers
Filtering
External Communication

Review all important rules.

For each record:

Rule Name
Purpose
Owner
Conditions
Actions
Exceptions

A powerful mail-flow rule can accidentally:

Bypass Security
Redirect Email
Alter Message Handling

Automatic forwarding deserves special attention.

Potential scenario:

Mailbox
Automatic Forwarding
External Address

This may be legitimate.

It may also indicate:

Misconfiguration
Data Leakage
Mailbox Compromise

Ask:

Which Mailboxes Forward?
Where?
Who Approved It?
Why?
Is the Destination External?
Is It Still Required?
Finding:
Unapproved External Mail Forwarding
Observation:
A user mailbox automatically forwards
messages to an external address without
documented business approval.
Risk:
Corporate email and potentially sensitive
information may leave the organization's
managed environment.
Recommendation:
Remove unapproved forwarding and establish
a controlled approval process for external
mail forwarding.

Mailbox access may be delegated to others.

Review:

Full Access
Send As
Send on Behalf

Ask:

Who Has Access?
Why?
Was It Approved?
Is the Original Business Requirement
Still Valid?

Shared mailboxes may support:

Finance
HR
Support
Sales
Operations

Review:

Owners
Members
Delegation
Business Purpose
External Forwarding
Lifecycle

Modern email security relies on domain-level controls.

Understand:

SPF
DKIM
DMARC
SPF
Who Is Allowed to Send?
DKIM
Was the Message Cryptographically Signed?
DMARC
What Should Receivers Do
When Authentication Fails?

These controls reduce domain impersonation risk but do not eliminate phishing.

Check whether business domains have an appropriate SPF policy.

Security questions:

Which Systems Are Authorized to Send?
Are Old Providers Still Included?
Is the Record Overly Broad?
Are Multiple Third Parties Included?

Assess whether approved domains use DKIM where required.

Ask:

Is DKIM Enabled?
Which Domains Use It?
Are Signing Configurations Current?

Review the organization’s DMARC strategy.

Understand the progression conceptually:

MONITOR
UNDERSTAND MAIL SOURCES
ENFORCE APPROPRIATE POLICY

Avoid deploying strict email-authentication policy blindly without understanding legitimate mail sources.

Review tenant controls addressing:

Impersonation
Spoofing
Phishing
Malicious URLs
Malicious Attachments

depending on the tenant’s available security capabilities.

Reduce the chance that:

ATTACKER
FAKE EMAIL
USER
CREDENTIAL THEFT

succeeds.

Link-protection technologies may help evaluate potentially malicious URLs.

Think:

EMAIL LINK
SECURITY EVALUATION
USER ACCESS

Attachment-protection capabilities may inspect or analyze suspicious files.

Think:

ATTACHMENT
SECURITY ANALYSIS
ALLOW / BLOCK / DETONATE

depending on the available configuration.

Review controls addressing:

Spam
Bulk Mail
Spoofing
Suspicious Senders

Do not evaluate spam policy only by asking:

Is Spam Blocked?

Also ask:

How Are False Positives Handled?
Who Can Release Messages?
Are Allow Lists Controlled?

Security teams should pay special attention to:

Allowed Senders
Allowed Domains
Security Bypasses
Transport Exceptions

because excessive allow-listing may weaken filtering.

Finding:
Overly Broad Email Security Exception
Observation:
A broad sender or domain exception bypasses
normal email-security controls.
Risk:
Messages from the exempted source may
receive reduced inspection, increasing the
impact of source compromise or spoofing.
Recommendation:
Remove broad exceptions where possible and
use narrowly scoped, documented exceptions
only when required.

Review:

Who Can Access Quarantine?
Who Can Release Messages?
Are Administrative Releases Audited?
Are Users Allowed to Release High-Risk
Message Types?

Part 25 — Business Email Compromise Scenario

Section titled “Part 25 — Business Email Compromise Scenario”

Scenario:

Finance Executive
Account Compromised
Attacker Sends Payment Request

Investigation should consider:

Sign-In Activity
Inbox Rules
Forwarding
Sent Mail
Authentication Methods
Mailbox Delegation
Session Activity

Mailbox rules can be abused to:

Hide Messages
Delete Alerts
Move Email
Forward Information

Review suspicious or unexpected rules.

Security questions:

Who Created the Rule?
What Does It Do?
When Was It Created?
Does the User Recognize It?

Part 27 — Suspicious Mailbox Rule Finding

Section titled “Part 27 — Suspicious Mailbox Rule Finding”
Finding:
Unrecognized Mailbox Processing Rule
Observation:
A mailbox contains a rule that redirects or
hides messages without a documented user or
business requirement.
Risk:
A malicious or unauthorized rule could hide
security notifications or redirect sensitive
communications.
Recommendation:
Validate the rule with the mailbox owner,
remove unauthorized rules, and review recent
mailbox and sign-in activity.

Part 28 — Review Microsoft Teams Security

Section titled “Part 28 — Review Microsoft Teams Security”

Microsoft Teams combines:

Chat
Meetings
Files
Applications
External Collaboration

This means Teams security touches:

Identity
Data
Sharing
Applications
Guests

Assess:

External Users
Federation
Guest Access
Meeting Access
Anonymous Participation

Ask:

Is External Collaboration Required?
Who Can Use It?
Which Controls Apply?
Is Access Reviewed?

Guest access should have:

Sponsor
Business Need
Defined Scope
Review
Expiration

Finding Example — Unreviewed Guest Access

Section titled “Finding Example — Unreviewed Guest Access”
Finding:
Unreviewed Microsoft Teams Guest Access
Observation:
External guest users retain access to Teams
resources after the associated business
engagement has ended.
Risk:
External parties may continue accessing
corporate conversations and shared files
without current authorization.
Recommendation:
Implement sponsor-based guest reviews and
remove external access when the business
need expires.

Teams can integrate third-party and custom applications.

Review:

Installed Applications
Allowed Applications
Blocked Applications
Application Owners
Business Need
Data Access

An application may access:

Messages
Files
User Information
External Services

depending on permissions.

Assess relevant meeting controls such as:

Anonymous Access
Recording
External Participants
Screen Sharing
Lobby Behavior

Apply based on business need and data sensitivity.

SharePoint often stores:

Policies
Project Documents
Financial Information
Business Records
Shared Team Files
SITE
OWNERS
MEMBERS
VISITORS
FILES

Inventory important sites.

Capture:

Site Owner Sensitivity External Sharing Review
Finance Finance High Restricted Current
Project-A Project Team Medium Enabled Review
Legacy Unknown Unknown Review Review

Every business-critical SharePoint site should have:

Known Owner
Business Purpose
Appropriate Membership
Defined Sharing Policy
Site Exists
+
No Owner
=
Governance Problem

Review:

Owners
Members
Visitors
Guests
Direct Permissions
Sharing Links

Ask:

Who Can Read?
Who Can Edit?
Who Can Manage?
Who Can Share?

External sharing is useful but high impact.

Possible scenarios:

Specific People
Authenticated Guests
Broad Sharing Links

depending on configuration.

For sensitive information:

THE MORE SENSITIVE THE DATA
THE MORE CONTROLLED THE SHARING

Look for links that may be:

Broad
Long-Lived
Unowned
No Longer Required
Finding:
Excessive External File Sharing
Observation:
Sensitive content is accessible through a
sharing method broader than required by the
documented business use case.
Risk:
Corporate information may be accessed by
unintended recipients or remain accessible
after the original collaboration ends.
Recommendation:
Restrict sharing to explicitly authorized
users and periodically review active
external-sharing links.

OneDrive often contains individual user files.

Review:

Sharing
External Links
Sensitive Data
Offboarding
Ownership Transfer

When an employee leaves:

Who Owns Required Business Data?
How Is It Preserved?
How Is Access Removed?
How Long Is It Retained?

Scenario:

Employee Creates External Link
to Confidential Spreadsheet

Review:

Data Sensitivity
Recipients
Link Type
Expiration
Business Need

Security decisions improve when data is classified.

Example model:

PUBLIC
INTERNAL
CONFIDENTIAL
HIGHLY CONFIDENTIAL
CLASSIFICATION
HANDLING REQUIREMENT
ACCESS
SHARING
PROTECTION

Sensitivity labels can help classify and protect information.

Depending on configuration, they may influence:

Marking
Encryption
Sharing
Access
Container Settings

Classification is useful only when:

Users Understand It
Policies Support It
Controls Are Enforced

DLP aims to reduce inappropriate handling of sensitive information.

A simple model:

SENSITIVE DATA
USER ACTION
DLP EVALUATION
ALLOW / WARN / RESTRICT

Organizations may protect:

Financial Information
Personal Information
Customer Data
Credentials
Health Information
Intellectual Property

according to business and regulatory needs.

Scenario:

Employee Attempts
to Share Sensitive Data
Externally

A DLP policy may:

Detect
Warn
Require Justification
Restrict

depending on policy design.

Retention controls help organizations manage:

How Long Data Is Kept
When Data Can Be Deleted
Regulatory Requirements
Business Records

Do not confuse:

Retention

with:

Backup

They serve different objectives.

Microsoft 365 can integrate with:

SaaS Apps
Automation
Add-Ins
Enterprise Applications
Custom Applications

Review:

Owner
Permissions
Users
Consent
Business Purpose

Application consent may grant access to:

User Profiles
Mail
Files
Calendars
Directories
Other Data

depending on permissions.

Ask:

Does the Application
Actually Need This Permission?

Finding Example — Excessive Application Access

Section titled “Finding Example — Excessive Application Access”
Finding:
Third-Party Application Has Excessive Access
Observation:
A connected application possesses
permissions broader than required for its
documented business purpose.
Risk:
Compromise or misuse of the application
could expose Microsoft 365 data beyond the
intended scope.
Recommendation:
Review and reduce application permissions
to the minimum required and establish
periodic application-access reviews.

Audit records help answer:

Who Did What?
When?
From Where?
To Which Resource?

Important activities may include:

Administrative Changes
Mailbox Activity
File Sharing
User Changes
Application Changes
Security Events
ACTION
USER / ADMIN / APP
RESOURCE
TIME
AUDIT RECORD
INVESTIGATION

Using the approved Microsoft 365/Purview audit interface available in the training environment, review recent events.

Focus on:

Privileged Changes
Mailbox Actions
Sharing Changes
Application Changes
User Administration

Example:

09:12 Suspicious Sign-In
09:18 Mailbox Rule Created
09:22 External Forwarding Added
09:30 Sensitive Email Accessed

Now you have:

Events

turned into:

Incident Context

Security platforms may generate alerts related to:

Phishing
Malware
Suspicious Identity
Mailbox Activity
Applications
Data

depending on services enabled.

ALERT
IDENTITY
RESOURCE
ACTIVITY
EVIDENCE
SCOPE
DECISION

Remember:

Alert
Confirmed Compromise

You need:

Context
Evidence
Timeline
Impact

Part 54 — Phishing Investigation Scenario

Section titled “Part 54 — Phishing Investigation Scenario”

Scenario:

User Reports Suspicious Email

Review:

Sender
Recipient
Subject
Links
Attachments
Authentication Results
Other Recipients
User Interaction

Then determine:

Was It Delivered Elsewhere?
Did Anyone Click?
Was Credential Access Attempted?
Did Sign-In Activity Change?

Indicators:

Unusual Sign-In
New Inbox Rule
External Forwarding
Unexpected Sent Mail
Authentication Change

Investigation sequence:

IDENTITY
SIGN-IN
MAILBOX
RULES
FORWARDING
SENT ITEMS
SESSIONS
IMPACT

Scenario:

Sensitive File
Shared Outside Organization

Review:

File
Owner
Recipient
Sharing Method
Timestamp
Sensitivity
Business Approval

Part 57 — Administrative Change Scenario

Section titled “Part 57 — Administrative Change Scenario”

Scenario:

Security Policy Changed

Investigate:

Who Changed It?
When?
What Changed?
Was It Approved?
What Was the Security Impact?

Part 58 — Build Administrative Access Matrix

Section titled “Part 58 — Build Administrative Access Matrix”
Identity Role MFA Required Review
Admin-A High Privilege Yes Yes Current
Admin-B Exchange Admin Yes Yes Current
User-C High Privilege Review No Remove/Review

Part 59 — Build Exchange Security Matrix

Section titled “Part 59 — Build Exchange Security Matrix”
Control Expected Actual Result
External Forwarding Restricted Review
Mailbox Delegation Approved Review
Email Authentication Configured Review
Anti-Phishing Enabled Review
Security Exceptions Minimal Review
Service External Access Owners Sensitive Data Review
Teams Review Known Medium
SharePoint Review Known High
OneDrive Review User Variable
Resource Owner External Link Type Expiration Action
Finance Site Finance No N/A N/A None
Project Doc Project Yes Specific Review Review
Old File Unknown Yes Broad None Remove/Review

Part 62 — Build Application Access Matrix

Section titled “Part 62 — Build Application Access Matrix”
Application Owner Permissions Required Review
App-A Finance Limited Yes Current
App-B Unknown Broad Review Investigate
App-C IT Limited Yes Current
Data Type Classification External Sharing DLP Owner
Financial Confidential Restricted Required Finance
HR Confidential Restricted Required HR
Public Content Public Allowed Basic Marketing

Part 64 — Establish Microsoft 365 Security Baseline

Section titled “Part 64 — Establish Microsoft 365 Security Baseline”

A practical baseline might include:

Area Expected State
Privileged Accounts Strongly protected
Admin Roles Least privilege
External Forwarding Controlled
Email Authentication Configured
Email Security Enabled
Guest Access Reviewed
External Sharing Controlled
Application Permissions Least privilege
Audit Enabled/Available
Security Alerts Monitored

Part 65 — Compare Baseline to Actual State

Section titled “Part 65 — Compare Baseline to Actual State”

Example:

Control Expected Actual Result
Admin MFA Required Enabled Pass
Forwarding Restricted External found Fail
Guest Review Current Stale guests Fail
App Permissions Minimum Broad access Fail
Audit Available Available Pass

Use factors such as:

Privilege
Data Sensitivity
External Exposure
Exploitability
Business Impact
Monitoring
Compensating Controls
External Forwarding
+
Executive Mailbox
+
Sensitive Data
+
No Business Approval
High Priority
Finding:
Excessive Microsoft 365 Administrative Role
Observation:
A user has tenant-level administrative
privilege beyond their documented
responsibilities.
Risk:
Account compromise may result in broad
impact across Microsoft 365 services.
Recommendation:
Apply least privilege and remove
unnecessary administrative assignments.
Finding:
Unapproved External Mail Forwarding
Observation:
A mailbox forwards corporate messages to
an external destination without documented
approval.
Risk:
Sensitive communications may leave the
managed Microsoft 365 environment.
Recommendation:
Disable unapproved forwarding and establish
a controlled exception process.
Finding:
Stale Microsoft 365 Guest Access
Observation:
An external user retains collaboration
access after the associated business
engagement has ended.
Risk:
The guest may continue accessing corporate
files or conversations without current
authorization.
Recommendation:
Remove stale guest access and implement
recurring sponsor-based access reviews.
Finding:
Excessive External Sharing
Observation:
Sensitive files can be accessed through
sharing permissions broader than the
business requirement.
Risk:
Information may be disclosed to unintended
recipients.
Recommendation:
Restrict sharing to approved users and
review existing external links.

Part 71 — Finding: Application Permission

Section titled “Part 71 — Finding: Application Permission”
Finding:
Over-Privileged Microsoft 365 Application
Observation:
A connected application has access to data
or services beyond what its documented
function requires.
Risk:
Compromise or misuse of the application
could affect a larger portion of the
Microsoft 365 environment.
Recommendation:
Reduce application permissions to the
minimum required and periodically review
access.
Finding:
Microsoft 365 Security Monitoring Gap
Observation:
Critical tenant activities are logged but
are not routinely reviewed or connected to
an established security-monitoring process.
Risk:
Suspicious administrative, identity, or
data-access activity may not be identified
in a timely manner.
Recommendation:
Define monitoring requirements for
critical Microsoft 365 events and integrate
them into the organization's security
operations workflow.

Your report should contain:

Document:

Tenant Assessed
Overall Security Posture
Critical Findings
Immediate Priorities

Include:

Administrative Roles
MFA
Least Privilege
Permanent Privilege
Emergency Access

Document:

Mail Flow
Forwarding
Mailbox Delegation
Inbox Rules
Shared Mailboxes

Document:

SPF
DKIM
DMARC
Anti-Phishing
Anti-Malware
Security Exceptions

Document:

Guest Access
External Access
Applications
Meeting Security

Document:

Site Ownership
Permissions
External Sharing
Sharing Links
Sensitive Data

Document:

Connected Applications
Owners
Permissions
Consent
Business Purpose

Document:

Classification
Sensitivity
DLP
Retention
Sharing Controls

Document:

Audit
Security Alerts
Mailbox Activity
Administrative Changes
Incident Visibility

For each finding include:

Finding ID
Title
Severity
Observation
Evidence
Risk
Recommendation
Owner
Target Date
Validation

Part 74 — Microsoft 365 Security Checklist

Section titled “Part 74 — Microsoft 365 Security Checklist”
  • Defined tenant scope
  • Reviewed domains
  • Identified critical services
  • Identified business owners
  • Reviewed administrative roles
  • Reviewed privileged users
  • Reviewed authentication
  • Reviewed permanent privilege
  • Reviewed emergency access
  • Reviewed accepted domains
  • Reviewed mail-flow rules
  • Reviewed external forwarding
  • Reviewed mailbox delegation
  • Reviewed shared mailboxes
  • Reviewed suspicious mailbox rules
  • Reviewed SPF
  • Reviewed DKIM
  • Reviewed DMARC
  • Reviewed anti-phishing controls
  • Reviewed malware protection
  • Reviewed URL protection
  • Reviewed security exceptions
  • Reviewed quarantine governance
  • Reviewed external access
  • Reviewed guest access
  • Reviewed meeting controls
  • Reviewed Teams applications
  • Reviewed guest lifecycle
  • Reviewed important sites
  • Reviewed owners
  • Reviewed members
  • Reviewed guests
  • Reviewed external sharing
  • Reviewed broad links
  • Reviewed sharing
  • Reviewed external access
  • Reviewed sensitive data
  • Reviewed offboarding process
  • Reviewed enterprise applications
  • Reviewed owners
  • Reviewed permissions
  • Reviewed consent
  • Identified excessive access
  • Reviewed classification
  • Reviewed sensitivity labels
  • Reviewed DLP concepts
  • Reviewed retention
  • Reviewed sensitive external sharing
  • Reviewed audit activity
  • Reviewed security alerts
  • Reviewed administrative changes
  • Reviewed mailbox activity
  • Reviewed sharing activity
  • Created investigation timelines
  • Created admin-access matrix
  • Created Exchange security matrix
  • Created collaboration matrix
  • Created sharing inventory
  • Created application matrix
  • Created data-protection matrix
  • Documented findings
  • Produced final report

Avoid:

Too Many Tenant Administrators
Weak Administrator Authentication
Uncontrolled Email Forwarding
Ignoring Mailbox Rules
Broad Email Security Exceptions
Unreviewed Guest Accounts
Anonymous or Broad Sharing Without Need
Unknown SharePoint Owners
Excessive Application Permissions
Ignoring Third-Party Applications
Treating Audit as Monitoring
Ignoring Sensitive Data Classification
Keeping Old Collaboration Access Forever
Users
Email
File Sharing
Basic Administration
MFA
Email Protection
Sharing Restrictions
Least Privilege
Guest Reviews
Application Governance
Data Classification
DLP
Central Monitoring
Identity Risk
Advanced Email Protection
Data Governance
Automated Detection
Incident Response
Continuous Access Review

This lab directly supports:

Microsoft 365 Security Engineer
Microsoft Security Engineer
SOC Analyst
Cloud Security Engineer
Identity Security Engineer
Security Consultant
Compliance Analyst
Security Administrator

Why is Microsoft 365 security more than email security?

Because Microsoft 365 also contains:

Identity
Collaboration
Files
Applications
Data Protection
Audit
Security Monitoring

Why is external mailbox forwarding a security concern?

Because corporate messages may leave the managed environment and could expose sensitive business information.

What are SPF, DKIM, and DMARC used for?

They support email-domain authentication and help reduce sender impersonation and spoofing risk.

Why are SharePoint sharing links important during a security assessment?

Because overly broad or long-lived links may expose corporate information beyond the intended audience.

What would you investigate after a suspected mailbox compromise?

Review:

Sign-Ins
Authentication Methods
Sessions
Inbox Rules
Forwarding
Delegation
Sent Mail
Audit Activity

40 Microsoft 365 Security Interview Questions

Section titled “40 Microsoft 365 Security Interview Questions”
  1. What is Microsoft 365 security?
  2. Which major services exist in Microsoft 365?
  3. Why is identity important to Microsoft 365 security?
  4. What is least privilege?
  5. Why should tenant administrators be limited?
  6. Why is strong MFA important for administrators?
  7. What is Exchange Online?
  8. Why is email a major attack vector?
  9. What is phishing?
  10. What is business email compromise?
  11. What is external mail forwarding?
  12. Why should mailbox forwarding be reviewed?
  13. What is mailbox delegation?
  14. What is an inbox rule?
  15. How can mailbox rules be abused?
  16. What is SPF?
  17. What is DKIM?
  18. What is DMARC?
  19. What is anti-phishing protection?
  20. Why are broad mail-security exceptions risky?
  21. What is Microsoft Teams guest access?
  22. What is Teams external access?
  23. Why should Teams applications be reviewed?
  24. What is SharePoint Online?
  25. What is OneDrive?
  26. Why is external file sharing risky?
  27. What is a sharing link?
  28. Why should SharePoint sites have owners?
  29. What is data classification?
  30. What is a sensitivity label?
  31. What is DLP?
  32. What is data retention?
  33. What is application consent?
  34. Why should application permissions be reviewed?
  35. What is Microsoft 365 audit activity?
  36. What is a security alert?
  37. Why does an alert not automatically mean compromise?
  38. How would you investigate a suspicious mailbox?
  39. How would you assess Microsoft 365 external sharing?
  40. How would you perform a Microsoft 365 security assessment?

When assessing a tenant, ask:

WHO ADMINISTERS IT?
HOW ARE ADMINS PROTECTED?
HOW IS EMAIL PROTECTED?
WHO CAN FORWARD MAIL?
WHO CAN ACCESS MAILBOXES?
WHO CAN COLLABORATE EXTERNALLY?
WHO CAN SHARE FILES?
WHAT APPLICATIONS HAVE ACCESS?
HOW IS SENSITIVE DATA PROTECTED?
WHAT IS AUDITED?
WHAT IS MONITORED?

You have now assessed Microsoft 365 security across:

Administrative Access
Exchange Online
Email Security
Mailbox Configuration
Teams
SharePoint
OneDrive
External Sharing
Applications
Data Protection
Audit
Security Alerts

The key lesson is:

Microsoft 365 Security
Is the Protection of
Identity + Communication + Collaboration + Data

not simply the configuration of email filters.

➡️ Lab 05 — Windows Security

In the final Microsoft lab, you will move deeper into Windows host security and assess:

Windows Security Architecture
Local Security Configuration
User Rights
Authentication
Windows Defender
Firewall
BitLocker
Audit Policy
PowerShell Security
Services
Persistence
Security Logs
Hardening
Security Findings

Your Microsoft path continues:

Lab 01 — Active Directory
Lab 02 — Endpoint Security
Lab 03 — Identity Security
Lab 04 — Microsoft 365 Security
Lab 05 — Windows Security
Runbook 01 — Active Directory Assessment
Runbook 02 — Microsoft 365 Security Review
Runbook 03 — Windows Security Assessment