Business IT

How to Secure Microsoft 365 Against Account Takeover

Practical steps South African SMEs can use to protect Microsoft 365 accounts from takeover, with guidance tailored for fast, experienced IT support.

Tash Bhairo5 August 20266 min read

Introduction

Microsoft 365 is the backbone of many South African small and medium-sized businesses (SMEs). Its email, Teams and Office apps keep teams productive, but they also present a prime target for account takeover attacks. For businesses in Gauteng and across South Africa, a compromised M365 account can mean lost invoices, exposed client data and costly downtime.

This article provides a clear, practical roadmap on how to secure Microsoft 365 against account takeover. It focuses on measures that deliver immediate protection and are realistic for SMEs, highlighting where experienced support speeds implementation and reduces risk.

Understand the risk: how account takeover happens

Account takeover (ATO) generally follows a predictable pattern. Attackers use stolen credentials, phishing, credential stuffing or exploitation of weak authentication to gain access. Once inside, they can forward emails, reset passwords at other services, and use the account to launch further attacks.

SMEs are particularly vulnerable because they often lack hardened identity controls and rapid incident response.

Core protections every SME should deploy

1. Enable and enforce multi-factor authentication (MFA)

MFA is the single most effective control against ATO. Require MFA for all accounts, not just administrators. Prefer authenticator apps or security keys over SMS, which can be vulnerable to SIM swap attacks.

  • Use Microsoft Authenticator or hardware FIDO2 keys for high-risk users.
  • Apply MFA via Conditional Access (see below) for gradual rollout and exceptions.

2. Use Conditional Access policies

Conditional Access lets you enforce rules based on user, device, location and risk. For an SME, useful policies include:

  • Require MFA for all access from outside South Africa or untrusted networks.
  • Block legacy authentication protocols (IMAP, POP) that don’t support modern auth.
  • Require compliant or hybrid-joined devices for sensitive resources.

3. Block legacy authentication and modernise protocols

Legacy authentication is commonly exploited in automated credential stuffing. Disable basic auth where possible and migrate mail clients to use modern authentication (OAuth).

4. Configure secure password policies and identity protection

Strong password policies matter, but they’re less effective without MFA. Use Azure AD Password Protection to block common and compromised passwords, and enable Microsoft Defender for Identity or Azure AD Identity Protection to detect risky sign-ins.

Hardening mail and collaboration to prevent abuse

1. Protect email flow and prevent forwarding

Compromised mailboxes are often used to defraud suppliers or clients. Configure these controls:

  • Disable automatic mailbox forwarding to external addresses unless explicitly required.
  • Enable mailbox auditing and alerting for unusual forwarding rules.
  • Use Exchange Online Protection and anti-phishing policies to flag impersonation attempts.

2. Configure DKIM, DMARC and SPF properly

Set up SPF, DKIM and DMARC for your business domains to reduce email spoofing and improve deliverability. A DMARC policy set to quarantine or reject reduces successful phishing impersonations of your domain.

3. Restrict third-party app permissions

OAuth consent grants can give malicious apps long-lived access. Regularly review and restrict app permissions; require admin approval for high-risk apps.

Monitoring, detection and rapid response

1. Enable logging and alerts

Turn on sign-in and audit logs in Azure AD and Exchange Online. Create alerts for anomalous activity such as:

  • Impossible travel or sign-ins from unexpected countries.
  • Mass mailbox rule creation or deletions.
  • Multiple failed sign-ins followed by success.

2. Use Defender and SIEM for richer detection

Microsoft Defender for Office 365 and Defender for Identity provide threat analytics. Feeding logs into a SIEM or Microsoft Sentinel (even a scaled deployment for SMEs) helps correlate events and speed response.

3. Have an incident response plan

Predefine steps for suspected ATO: isolate affected accounts, reset credentials, force reauthentication, review activity, notify impacted parties and, if needed, involve specialist incident responders. Practised playbooks reduce downtime and risk.

Operational practices that reduce exposure

1. Least privilege and role separation

Assign admin roles sparingly. Use Privileged Identity Management (PIM) for just-in-time elevation so high privileges are rarely active. Limit global admin accounts and require MFA for them.

2. Regular user training and simulated phishing

Human error is a frequent cause of account takeover. Deliver targeted training and simulated phishing campaigns to help staff recognise social engineering. Focus on finance, HR and staff who handle external communications.

3. Keep devices and endpoints patched

Compromised endpoints can bypass identity controls. Ensure Windows updates and security patches are applied, use endpoint protection and enforce disk encryption on laptops used outside the office.

Practical rollout steps for SMEs in South Africa

  1. Audit: catalogue M365 users, admin accounts and third-party app permissions.
  2. Immediate: enable MFA for all users and block legacy authentication.
  3. Short term (2–6 weeks): implement Conditional Access, configure DKIM/SPF/DMARC, enable logging and basic alerting.
  4. Medium term (1–3 months): deploy Defender features, set up PIM, run staff training and simulated phishing.
  5. Ongoing: review alerts, perform quarterly access reviews and practice incident response playbooks.

These steps are practical for SMEs and can be staged to match resource availability. For many businesses, partnering with experienced engineers ensures fast, low-disruption execution.

Cost considerations for South African SMEs

Microsoft 365 licensing affects which features are available. MFA and basic security controls are included in most plans, while Defender, PIM and advanced Conditional Access features may require higher-tier licences. Factor in:

  • Licence upgrades where necessary.
  • Costs for security keys (FIDO2) or additional endpoint protection.
  • Managed service or consultant fees for setup and monitoring.

Budgeting in advance avoids unexpected costs and ensures the right level of protection for the business. For many SMEs the cost of managed security is small compared with the potential expense of a breach.

Frequently asked questions

Can MFA be bypassed?

MFA significantly reduces risk but is not infallible. Attackers can use sophisticated phishing or session capture. Pair MFA with Conditional Access, device compliance checks and monitoring to strengthen protection.

How quickly should we act after a suspected takeover?

Immediate containment is critical: disable or block the account, force password reset and revoke active sessions. Then conduct a focused investigation and follow incident response steps.

Is it hard to disable legacy authentication?

It can affect older mail clients and devices. Test changes with a small user group first and provide guidance for migrating to modern authentication. Blocking legacy auth is essential for security.

Do we need a SIEM for an SME?

A full SIEM is not mandatory, but centralised logging and alerting are important. Consider managed SIEM or Microsoft Sentinel in a scaled deployment if you need advanced correlation and 24/7 monitoring.

How often should we review admin accounts and app permissions?

Conduct reviews at least quarterly. Remove unused admin accounts and revoke unnecessary app permissions to reduce attack surface.

Conclusion

Securing Microsoft 365 against account takeover is achievable for South African SMEs with practical controls: enforce MFA, use Conditional Access, block legacy authentication, harden email, monitor activity and prepare an incident response plan. These measures reduce risk quickly and can be implemented in stages that suit your business.

RandTech IT specialises in helping SMEs deploy these protections with minimal disruption. If you want experienced engineers who prioritise fast resolution over learning on the job, contact RandTech IT for practical assistance securing your Microsoft 365 environment.

Contact RandTech IT — reach out for a security review, MFA rollout, Conditional Access setup or incident response support tailored to South African SMEs.

About the author

Tash Bhairo

Tash Bhairo leads Randtech IT with nearly two decades of hands-on experience in business support, infrastructure, cloud systems and software development.