How to Secure Microsoft 365 Against Account Takeover
Practical steps for South African SMBs to protect Microsoft 365 from account takeover: MFA, conditional access, monitoring, backups and staff training.
Introduction
Account takeover in Microsoft 365 (M365) is a growing threat for South African small and medium-sized businesses. An attacker with a compromised M365 account can read emails, access files in OneDrive and SharePoint, and impersonate staff to trick customers or suppliers. That can lead to financial loss, reputational damage and costly recovery work.
This guide explains practical, prioritised steps you can apply today to reduce the risk of account takeover. The recommendations are written for SMBs in South Africa and assume limited internal IT resources — the focus is on effective controls you can implement quickly or get help to deploy.
Understand the attack paths
Before you act, know how attackers typically gain access:
- Phishing: deceptive emails or links that harvest credentials or MFA codes.
- Credential stuffing: using leaked passwords from other services.
- Brute force and password spray: automated attempts against weak passwords.
- Compromised devices: malware on a workstation that steals tokens or session cookies.
- Poorly configured admin accounts: excessive privileges or missing protections.
Essential steps to secure Microsoft 365
These controls offer the best balance of protection and practicality for SMBs.
1. Enforce Multi-Factor Authentication (MFA)
MFA blocks most account takeover attempts even if a password is compromised. Require MFA for all users, starting with administrators and finance staff. Use an authenticator app or hardware security keys rather than SMS when possible, as SMS is vulnerable to SIM swap attacks.
2. Configure Conditional Access policies
Azure Active Directory Conditional Access lets you apply rules based on location, device state and risk. For example:
- Block sign-ins from high-risk countries or anonymising proxies.
- Require compliant or hybrid-joined devices to access sensitive apps.
- Require MFA for risky sign-ins or high-privilege actions.
Start with simple, high-impact policies and refine as you learn how they affect users.
3. Protect privileged accounts
Limit the number of Global Administrators and use Privileged Identity Management (PIM) where available to provide just-in-time elevation. Ensure admin accounts have dedicated credentials and strict MFA enforcement. Monitor all admin activities and enable audit logging.
4. Harden authentication and passwords
Apply these password and identity hygiene measures:
- Disable legacy authentication protocols that bypass modern MFA.
- Implement a password policy that prevents reuse of breached credentials (Azure AD Password Protection).
- Encourage passphrases or use password managers to reduce weak passwords.
5. Monitor sign-in activity and alerts
Use Azure AD Identity Protection, Microsoft Defender for Office 365 and Microsoft Defender for Identity if licensed. Monitor for:
- Unfamiliar locations or impossible travel events.
- Multiple failed sign-ins or unusual application access patterns.
- Mass forwarding rules or suspicious mailbox delegations.
Configure alerting to the right people so incidents are investigated promptly.
6. Secure email and reduce phishing risk
Email is the most common vector. Implement standard protections:
- Enable Exchange Online Protection and anti-phishing policies.
- Use DKIM, SPF and DMARC to reduce email spoofing.
- Block external mail forwarding by default and review exceptions.
Complement technical controls with user education focused on recognising phishing attempts and verifying payment requests.
7. Backup critical Microsoft 365 data
M365 provides redundancy but not traditional point-in-time backups for user-deleted or modified data. Use a third-party backup solution for Exchange, OneDrive, SharePoint and Teams to ensure you can recover from account misuse, mass deletions or ransomware.
8. Secure endpoints and networks
Protect the devices users sign in from:
- Keep Windows and other OS patches current.
- Use endpoint protection with anti-malware and behavioural detection.
- Require disk encryption and strong access controls on laptops.
Where possible, prevent unmanaged devices from accessing sensitive data using Conditional Access.
Operational practices and incident readiness
Regular review and least privilege
Review user and app permissions quarterly. Remove stale accounts and reduce mailbox delegates. Apply least privilege to applications that request access to M365 data.
Logging, retention and playbooks
Retain audit logs for investigation and compliance. Create an incident response playbook that covers detection, containment, account recovery and notification. Ensure a trained person or external partner can act quickly outside normal hours.
User training and simulated phishing
Regular, practical training reduces risk. Run occasional phishing simulations to measure awareness and target further coaching where users click malicious links or disclose credentials.
Cost-conscious planning for South African SMBs
Budgeting for M365 security can be challenging. Focus on cost-effective, high-impact controls first: MFA, disabling legacy auth, email protections and backups. Many protections are included in Microsoft 365 Business Premium; evaluate whether upgrading licensing or using targeted third-party tools gives better value than reactive recovery work.
If internal capacity is limited, engage a trusted local partner who can implement Conditional Access, PIM and backups with minimal disruption. RandTech IT specialises in hands-on support so your team isn’t used as a learning environment — we implement proven configurations quickly so you can get back to business.
Quick checklist to secure Microsoft 365
- Enforce MFA for all users — avoid SMS where possible.
- Disable legacy authentication protocols.
- Apply Conditional Access for risky locations and compliant devices.
- Restrict and monitor Global Admins; enable PIM if available.
- Enable Exchange anti-phishing, SPF/DKIM/DMARC.
- Deploy third-party backups for Exchange, OneDrive and SharePoint.
- Train staff on phishing and run simulations.
- Keep endpoints patched and protected.
Frequently asked questions
How quickly can MFA be rolled out?
MFA for administrators can be enabled in hours. A staged rollout for all users, including support for authenticator apps and tied devices, typically takes several days depending on company size and user readiness.
Is SMS-based MFA acceptable for small businesses?
SMS offers better protection than none but is vulnerable to SIM swap attacks. Use authenticator apps or hardware keys for higher-risk accounts like finance and administrators.
Do I need Microsoft Defender licenses to be secure?
Defender products add detection and recovery capabilities, but strong baseline controls (MFA, Conditional Access, email protection, backups) provide substantial protection even without premium licences.
What should I do immediately after detecting an account takeover?
Contain the incident: block access, reset credentials, revoke active sessions, remove malicious forwarding rules, and restore affected data from backups. Then perform a root-cause analysis and strengthen the controls that failed.
Can RandTech IT help implement these controls?
Yes. RandTech IT offers hands-on implementation, monitoring and incident response for South African SMBs. We prioritise experienced engineers who implement securely and quickly.
Conclusion
Securing Microsoft 365 against account takeover is achievable for South African SMBs with a focused set of controls: enforce MFA, apply Conditional Access, protect privileged accounts, secure email and endpoints, and maintain backups. Combine technical controls with user training and clear incident procedures.
If you need practical, experienced assistance to implement these protections without disrupting your business, contact RandTech IT. We can assess your current M365 configuration, prioritise improvements and implement them quickly so you can operate securely.
Contact RandTech IT — reach out for a pragmatic, experienced partner to secure your Microsoft 365 environment and reduce the risk of account takeover.


