Business IT

How to Secure Microsoft 365 Against Account Takeover

Practical steps for South African SMBs to protect Microsoft 365 from account takeover, including MFA, device management, monitoring and incident response.

Tash Bhairo5 August 20265 min read

Introduction

Account takeover of Microsoft 365 can interrupt business, expose sensitive data and lead to costly recovery. South African small and medium-sized businesses (SMBs) face targeted attacks because they hold valuable data but often lack hardened controls. This guide explains practical, prioritised steps you can take today to secure Microsoft 365 against account takeover, tailored to the realities of SMBs in Gauteng and across South Africa.

Understand the risk and common attack methods

Attackers use several routes to take over M365 accounts. Knowing these helps you focus defences.

Phishing and credential harvesting

Fraudulent emails and fake login pages remain the most common method for stealing credentials. Compromised credentials let attackers bypass perimeter defences quickly.

Brute force and credential stuffing

Reused or weak passwords are vulnerable to automated attacks that try large password lists or use leaked credentials from other breaches.

Legacy protocols and insecure clients

Older protocols (IMAP, POP) and unpatched email clients can bypass modern authentication and allow direct access.

Priority controls to prevent account takeover

Implement the following controls in order of impact. These are cost-effective and feasible for SMBs, including those in Johannesburg and wider Gauteng.

1. Enforce Multi-Factor Authentication (MFA)

MFA is the single most effective control to stop account takeover. Require it for all users including administrators. Use app-based authenticators or hardware FIDO2 keys where possible.

2. Enable Conditional Access

Azure AD Conditional Access lets you require MFA or block access from risky locations and unmanaged devices. Start with policies that require MFA for:

  • All admin roles
  • Access from outside South Africa if not business-critical
  • Unmanaged or non-compliant devices

3. Block legacy authentication

Disallow legacy protocols such as IMAP, POP and SMTP AUTH where possible. These do not support modern authentication and are a frequent attack vector.

4. Use strong password policies and passphrases

Encourage long passphrases and ban password reuse. Consider Azure AD Password Protection to block commonly used passwords and leaked credentials.

5. Harden admin accounts

Limit the number of global admins. Use dedicated breakout accounts for elevated tasks and protect them with MFA and FIDO2 keys.

Device and endpoint controls

Compromised endpoints are often the start of account takeover. Reduce this risk with device management and secure configurations.

Microsoft Defender and endpoint management

Deploy Microsoft Defender for Business or equivalent endpoint protection. Use Intune or another Mobile Device Management (MDM) solution to enforce patching, encryption and device compliance.

Restrict access from unmanaged devices

Conditional Access can block or limit access for unmanaged endpoints. Require device compliance for access to sensitive apps and data.

Monitor, detect and respond

Prevention is essential, but rapid detection and response reduce damage when incidents occur.

Enable unified auditing and alerts

Turn on Microsoft 365 audit logs and alerting for suspicious activities like impossible travel, mass mailbox rule creation, forwarding rules and sign-ins from unusual locations.

Use activity monitoring and analytics

Azure AD Identity Protection and Microsoft Defender for Office 365 provide risk scores and automated actions for risky sign-ins. Review reports regularly and tune alerts to reduce false positives.

Establish an incident response plan

Have a documented, tested plan for account compromise. Typical steps include isolating affected accounts, resetting credentials and reviewing mailbox rules and forwarding. Assign responsibilities and escalation paths.

Email hygiene and data protection

Protect against email-based attacks

Enable anti-phishing, anti-spam and safe links/safe attachments in Defender for Office 365. Configure DMARC, DKIM and SPF for your domains to reduce successful spoofing.

Limit external forwarding and mailbox delegation

Prevent automatic forwarding to external addresses unless business-critical. Regularly review mailbox delegation and shared mailbox permissions.

Operational practices for SMBs

Practical day-to-day practices help keep your Microsoft 365 environment secure without large overhead.

  • Conduct regular user awareness training focused on phishing and social engineering.
  • Onboard and offboard users with a documented process that includes revoking access and removing licences.
  • Review licence assignments and remove unnecessary admin privileges.
  • Schedule quarterly security reviews and post-incident lessons learned.

Cost considerations for South African SMBs

Many security features are included in Microsoft 365 Business Premium or can be added affordably. Compare licence tiers against the cost of recovery from a compromise, which may include productivity loss, data recovery and reputational damage. RandTech IT can help choose the right mix to fit your budget in Rands and operational needs.

FAQ

How quickly should I enable MFA?

Enable MFA immediately. Start with administrators and users with access to sensitive data, then roll out to all staff. This is a high-impact control you can implement in days.

Will blocking legacy authentication break email for staff?

It can affect older email clients. Survey your users, move clients to modern authentication-capable software, and use Conditional Access to phase the change.

Do SMBs need Microsoft Defender for Office 365?

It’s highly recommended if your business relies on email. It adds targeted anti-phishing, link protection and automated investigation features that reduce risk and workload.

How do we handle a suspected account compromise?

Immediately disable the account, reset passwords and revoke active sessions and tokens. Review mailbox rules, forwarding and recent activity. Engage your IT support or a managed service provider for containment and recovery.

Can RandTech IT manage these settings for us?

Yes. RandTech IT offers managed Microsoft 365 security and practical implementation services to ensure controls are correctly configured and maintained.

Conclusion

Securing Microsoft 365 against account takeover is achievable for South African SMBs with focused, practical actions: enforce MFA, use Conditional Access, block legacy authentication, protect endpoints and monitor activity. These steps reduce risk quickly and cost-effectively.

If you need practical, experienced assistance to implement or review Microsoft 365 security, contact RandTech IT. Our engineers work rapidly to protect your business so you can get back to running it.

About the author

Tash Bhairo

Tash Bhairo leads Randtech IT with nearly two decades of hands-on experience in business support, infrastructure, cloud systems and software development.