Top Five M365 Forensics Finds

The following misconfigurations are frequently found in our digital forensics. Is your mailbox set up correctly?

Very often, the digital forensics we perform here at Webcheck Security involve M365 tenants. We see so many misconfigurations it makes our heads spin. In this article, though by all means not comprehensive, we will list a few common elements that we've found. Hopefully these will be helpful to you and your organization. The objective of course, is to ensure that bad actors can’t easily gain access into your private e-mail tenant, resulting in critical information being leaked and the ability to spoof emails and send fraudulent wire requests.
DMARC
Your email security journey begins here. DMARC stands for Domain-based Message Authentication, Reporting and Conformance and is a DNS-published policy. It lets a domain owner tell receiving mail servers what to do when a message claims to come from their domain but fails authentication. It also gets those servers to send back reports on what they're seeing.
When this is not configured, SMTP lets anyone put any address in the visible 'From:'
header, which is the one the recipient actually sees. SPF and DKIM existed before DMARC, but neither one checks that visible 'From' address.
SPF checks whether the sending IP is allowed to send for the domain in the envelope sender (Return-Path), which users never see.
DKIM checks a cryptographic signature tied to whatever domain is in the d= tag, which can be any domain.
So a phisher could pass SPF and DKIM with their own domain while still showing From: ceo@yourcompany.com. DMARC configuration closes that gap.

Logging
M365 logging is not always on by default, meaning if bad stuff is happening your company will have limited insight. It’s critical that logging be turned on. If you do have M365 breach incidents or legitimate logins with harvested credentials and/or man-in-the-middle harvested login tokens, proper logging will tell the tale of “who done it” and how.
MFA
Implement conditional access policies requiring MFA for all users. I’m not sure one can even use M365 without turning on MFA anymore, but it’s critical to ensure that every user and object mailbox responds with the need for appropriate authentication. Microsoft Authenticator and other industry authenticators are a good way to implement higher-level authentication methodology vs. simple SMS codes, and makes it more difficult to gain illegitimate entry.
Enhanced Monitoring Features
Implement alerts for:
Sign-ins from new locations/countries
Multiple failed authentication attempts
Successful followed by failed authentications from different locations
MFA-related failures exceeding threshold
Changes to DNS records
Email forwarding rule changes
Good Ol’ Analog Verification Procedures

Breaches can and will happen, so it behooves all organizations to have sound business process procedures. This is just good cyber governance! These procedures can include -
Implement formal verification procedures for all financial transactions.
Create a policy requiring out-of-band confirmation for any banking information changes.
Update vendor management processes to include verification of communication channels.
Establish notification protocols for unusual financial activities.
Again, the above are only “blocking and tackling” basics in the cyber game where email is concerned, and there are dozens of other key factors one can do to strengthen configuration posture.
We would be delighted to help you with this, and we have experts standing by to assess, advise, and help implement. Reach out to us using either the partner or other contact forms below, and we’ll respond same day!





Comments