SIEM

Enable MFA

Security defaults make it easier to help protect your organization from these attacks with preconfigured security settings:

Compliance Controls:

To enable security defaults in your directory:

Enable MFA For Just Admins

To create an MFA conditional access policy in your directory for admins:

Block Legacy Authentication

Legacy authentication is more susceptible to password spray attacks or brute force attacks because you cannot layer on MFA. It is advised to block all legacy authentication methods. Note that if you have any printers/copiers/scanners or IMAP accounts used for ticketing, you should update those protocols before blocking legacy auth.

To block legacy authentication via security defaults in your directory:

Enable Self-Service Password Reset

Do Not Expire Passwords

Compliance Controls

Delete/block accounts not used in last 30 days

Compliance Controls

Designate More than 1 Global Admin but fewer than 5

Compliance Controls

Do not allowusers to grant consent to unmanaged applications

Compliance Controls

Additional Resources