top of page

Top Five M365 Forensics Finds

Writer: Greg Johnson
Greg Johnson
5 days ago
3 min read

The following misconfigurations are frequently found in our digital forensics. Is your mailbox set up correctly?


Very often, the digital forensics we perform here at Webcheck Security involve M365 tenants. We see so many misconfigurations it makes our heads spin. In this article, though by all means not comprehensive, we will list a few common elements that we've found. Hopefully these will be helpful to you and your organization. The objective of course, is to ensure that bad actors can’t easily gain access into your private e-mail tenant, resulting in critical information being leaked and the ability to spoof emails and send fraudulent wire requests.


  1. DMARC

Your email security journey begins here. DMARC stands for Domain-based Message Authentication, Reporting and Conformance and is a DNS-published policy. It lets a domain owner tell receiving mail servers what to do when a message claims to come from their domain but fails authentication. It also gets those servers to send back reports on what they're seeing. 


When this is not configured, SMTP lets anyone put any address in the visible 'From:'

header, which is the one the recipient actually sees. SPF and DKIM existed before DMARC, but neither one checks that visible 'From' address.

  • SPF checks whether the sending IP is allowed to send for the domain in the envelope sender (Return-Path), which users never see.

  • DKIM checks a cryptographic signature tied to whatever domain is in the d= tag, which can be any domain.

So a phisher could pass SPF and DKIM with their own domain while still showing From: ceo@yourcompany.com. DMARC configuration closes that gap.

computer coding code text

  1. Logging

M365 logging is not always on by default, meaning if bad stuff is happening your company will have limited insight. It’s critical that logging be turned on. If you do have M365 breach incidents or legitimate logins with harvested credentials and/or man-in-the-middle harvested login tokens, proper logging will tell the tale of “who done it” and how.


  1. MFA

Implement conditional access policies requiring MFA for all users. I’m not sure one can even use M365 without turning on MFA anymore, but it’s critical to ensure that every user and object mailbox responds with the need for appropriate authentication. Microsoft Authenticator and other industry authenticators are a good way to implement higher-level authentication methodology vs. simple SMS codes, and makes it more difficult to gain illegitimate entry.


  1. Enhanced Monitoring Features

Implement alerts for:

  1. Sign-ins from new locations/countries

  2. Multiple failed authentication attempts

  3. Successful followed by failed authentications from different locations

  4. MFA-related failures exceeding threshold

  5. Changes to DNS records

  6. Email forwarding rule changes


  1. Good Ol’ Analog Verification Procedures

phone call business woman holding a paper

Breaches can and will happen, so it behooves all organizations to have sound business process procedures. This is just good cyber governance! These procedures can include - 

  1. Implement formal verification procedures for all financial transactions.

  2. Create a policy requiring out-of-band confirmation for any banking information changes.

  3. Update vendor management processes to include verification of communication channels.

  4. Establish notification protocols for unusual financial activities.


Again, the above are only “blocking and tackling” basics in the cyber game where email is concerned, and there are dozens of other key factors one can do to strengthen configuration posture. 


We would be delighted to help you with this, and we have experts standing by to assess, advise, and help implement. Reach out to us using either the partner or other contact forms below, and we’ll respond same day!



 
 
 

Comments


bottom of page