How to Secure Microsoft 365 Against Account Takeover
Practical steps South African SMBs can take to secure Microsoft 365 against account takeover, from MFA to monitoring, policies and incident response.
Introduction
Account takeover is one of the most common and damaging cyber threats for small and medium-sized businesses (SMBs). For South African organisations using Microsoft 365—email, Teams, OneDrive and SharePoint—a compromised account can expose sensitive client data, interrupt operations and damage reputation. This guide explains practical, cost-effective steps SMBs in South Africa can implement to secure Microsoft 365 against account takeover.
Understand the risk
Account takeover typically starts with credential theft—phishing, reused passwords or leaked credentials—and escalates through privilege abuse and lateral movement. In the Microsoft 365 environment, attackers target admin accounts, mailboxes and file shares because they provide broad access.
Why SMBs are at risk
- Limited IT resources often mean basic controls are missing.
- Users may reuse passwords across personal and work accounts.
- Remote or hybrid work increases login attempts from varied locations.
Core controls to prevent account takeover
Start with these high-impact controls. They’re practical for small teams and deliver measurable protection.
1. Enforce multi-factor authentication (MFA)
MFA is the single most effective control to prevent account takeover. Require it for all users, not just admins. Use app-based authenticators or hardware tokens rather than SMS when possible, since SMS can be intercepted.
2. Apply conditional access policies
Conditional access lets you require stronger authentication or block access based on risk factors such as location, device compliance and sign-in risk. For Johannesburg- or Gauteng-based offices, set trusted locations and restrict high-risk countries.
3. Harden admin accounts
- Use dedicated admin accounts: no email, no regular browsing.
- Require MFA and stronger authentication for all admin roles.
- Limit the number of users with Global Administrator privileges.
4. Enforce strong password policies and passphrases
Encourage passphrases and ban legacy patterns like “Password123”. Use Azure AD password protection to block common or compromised passwords and consider passwordless options like Windows Hello for Business or FIDO2 security keys for critical users.
5. Enable mailbox and audit logging
Turn on unified audit logging and mailbox auditing. Logs help you detect suspicious activity—like mass forwarding rules or mailbox delegation—that often accompany account takeover.
Detection and response
Preventive controls reduce risk, but detection and response minimise damage if an account is compromised.
Monitor sign-in activity
Regularly review sign-in reports in the Azure portal. Look for unusual patterns such as sign-ins from unexpected countries, impossible travel indicators or repeated failed attempts.
Set up alerting and automated actions
Configure Microsoft Defender for Office 365 and Azure AD Identity Protection to alert on and automatically respond to risky sign-ins—forcing password resets, blocking access or requiring reauthentication.
Incident response playbook
- Isolate the compromised account: disable sign-in if needed.
- Reset the user’s credentials and revoke active sessions and refresh tokens.
- Search mailboxes and SharePoint for suspicious forwarding rules, sharing links and data exfiltration.
- Restore from known-good backups if data was corrupted or deleted.
- Document and review the incident to close gaps in controls.
Protect email and data
Email is a primary target. These measures reduce exposure and harden communications.
Anti-phishing and safe attachments
- Enable Microsoft Defender for Office 365 anti-phishing policies.
- Use Safe Links and Safe Attachments to inspect content in transit.
Control external sharing
Restrict external sharing on SharePoint and OneDrive where possible. Require link expiration and limit sharing to authenticated users. Regularly review externally shared content and revoke access that’s no longer required.
Endpoint and device controls
Compromised endpoints are a common attack vector. Ensure devices connecting to M365 meet minimum security standards.
Use Microsoft Intune or an MDM solution
- Enforce device encryption, PINs and updated operating systems.
- Require device compliance before granting access via conditional access policies.
Patch and antivirus
Maintain a patch schedule and run reputable endpoint protection. For smaller firms, managed services can handle these tasks consistently and cost-effectively.
Policies, training and governance
Technical controls are essential, but people and processes complete the defence.
User awareness training
Phishing simulations and focused training reduce the chances of credential theft. Keep sessions short and practical—show examples relevant to South African business contexts, such as fake SARS or banking emails.
Least privilege and access reviews
- Apply least privilege principles across M365 roles and groups.
- Perform periodic access reviews and remove inactive or unnecessary accounts.
Backups and business continuity
Microsoft 365 provides high availability but native retention doesn’t replace backups. Use third-party backup solutions to protect against accidental deletion, ransomware and long-term retention needs.
Cost-conscious approaches for South African SMBs
SMBs must balance security with budget. Prioritise controls that yield the greatest reduction in risk for the lowest cost.
- Start with organisation-wide MFA—low cost, high impact.
- Adopt conditional access rules for risky scenarios rather than broad licensing upgrades immediately.
- Consider managed security services to get experienced engineers without hiring full-time specialists.
If budget is limited, focus on the critical user accounts (finance, HR, executive) first and expand controls as resources allow.
Conclusion
Securing Microsoft 365 against account takeover requires a combination of identity controls, device management, monitoring and user education. For South African SMBs, practical steps—MFA, conditional access, admin hardening, logging and backups—deliver meaningful protection without excessive cost. Consistent policies and a tested incident response plan will reduce downtime and business impact when incidents occur.
FAQ
1. Is MFA enough to stop account takeover?
MFA significantly reduces risk but is not a silver bullet. Combine MFA with conditional access, password protection and monitoring for comprehensive protection.
2. Can my small business afford these controls?
Many controls—like MFA, password policies and basic logging—are low-cost or included in Microsoft 365 plans. Managed security services can provide expertise cost-effectively for smaller budgets.
3. How quickly should I respond to a suspected compromise?
Isolate the account immediately, reset credentials, revoke sessions and search for suspicious activity. Acting within hours can prevent lateral movement and data loss.
4. Do I need extra backup for Microsoft 365?
Yes. Native retention may not meet regulatory or recovery needs. Third-party backups protect against accidental deletion, ransomware and long-term retention requirements.
5. What role does user training play?
User training reduces the likelihood of credential theft via phishing. Regular, relevant sessions and phishing simulations improve resilience significantly.
Get practical help
If your business needs experienced engineers to secure Microsoft 365 quickly and correctly, RandTech IT can help. We focus on fast resolution by seasoned technicians who implement proven controls with minimal disruption. Contact RandTech IT to arrange a review and practical next steps tailored to your environment.


