Securing Microsoft 365 with Conditional Access
How suspicious account activity led to a Microsoft 365 security review, an upgrade to Business Premium and the introduction of Conditional Access to dramatically reduce the organisation’s exposure to account compromise.
Overview
The incident began when a customer reported receiving suspicious emails that appeared to have originated from within their organisation.
This immediately raised the possibility that a Microsoft 365 account may have been compromised.
Rather than simply changing a password and considering the matter closed, the incident triggered a wider investigation into the organisation’s Microsoft 365 security posture.
The Challenge
Suspicious Emails
Emails consistent with phishing or account compromise were being received, creating concern that credentials may have been exposed.
Overseas Sign-in Attempts
Microsoft Entra ID sign-in information showed authentication activity originating from multiple countries outside the organisation’s normal operating locations.
Identity Security
The existing configuration relied heavily on usernames, passwords and the authentication controls already in place.
Limited Access Controls
The existing Microsoft 365 licensing did not provide the full Conditional Access capabilities required for the security improvements we wanted to implement.
Immediate Response
When account compromise is suspected, the first priority is containment.
Before making wider configuration changes, action was taken to secure the affected account and invalidate any access that an attacker may already have obtained.
Password Reset
The user’s Microsoft 365 password was changed to prevent continued access using potentially compromised credentials.
Multi-Factor Authentication Reviewed
The user’s authentication methods were reviewed and reset where appropriate to ensure an attacker had not registered or retained an authentication method.
Active Sessions Revoked
Existing Microsoft 365 sessions were revoked so that previously issued authentication tokens could no longer simply continue accessing the account.
Sign-in Activity Investigated
Microsoft Entra ID sign-in information was reviewed to identify unusual locations, authentication attempts and other suspicious activity.
Why changing the password isn’t always enough
If an attacker already has an authenticated session, simply changing the user’s password may not immediately terminate every existing session. Revoking sessions and reviewing authentication methods are therefore important parts of responding to a suspected Microsoft 365 account compromise.
What the Investigation Found
The Microsoft Entra ID sign-in logs provided valuable visibility into authentication attempts against the tenant.
Attempts were being made from geographical locations that were inconsistent with the customer’s normal business activity.
While unsuccessful overseas authentication attempts do not automatically mean that an account has been compromised, they demonstrate an important reality of cloud services:
This led to a wider discussion about reducing the organisation’s attack surface rather than simply reacting to suspicious login attempts after they occurred.
The Licensing Gap
The customer was using Microsoft 365 Business Standard.
Business Standard provides the core Microsoft 365 productivity services, but the additional identity, device management and security capabilities included with Microsoft 365 Business Premium made it a much better fit for the security controls required.
This wasn’t simply an Office licensing upgrade. Business Premium opened the door to a much broader set of security and management capabilities, including Microsoft Entra ID Conditional Access and Microsoft Intune.
The Solution: Conditional Access
Conditional Access allows Microsoft Entra ID to evaluate the circumstances surrounding a sign-in before deciding whether access should be granted.
Instead of relying solely on the question:
Microsoft 365 can consider additional information such as:
- who the user is
- where the sign-in originates
- which application is being accessed
- whether multi-factor authentication has been completed
- the type of device being used
- whether the device is managed or compliant
- the level of risk associated with the sign-in
This allows access decisions to be based on context rather than simply possession of a username and password.
Using Named Locations
The organisation’s users normally operated from the United Kingdom, so geographical information could be used as an additional security control.
Named Locations were configured within Microsoft Entra ID and incorporated into the Conditional Access design.
This allowed sign-ins originating from unexpected geographical regions to be restricted rather than simply allowing authentication attempts from anywhere in the world.
Reducing the attack surface
If an organisation has no legitimate requirement for users to sign in from certain parts of the world, restricting those locations can remove a significant amount of unnecessary exposure.
Location controls are not a silver bullet
Geographical restrictions should form part of a layered security strategy. Attackers can use VPNs, proxies or compromised infrastructure within an allowed country, so location should never replace strong authentication, device controls and sensible monitoring.
Strengthening Multi-Factor Authentication
Conditional Access was also used to strengthen the way multi-factor authentication was applied.
MFA provides an important additional layer of protection because possession of a password alone should not be enough to access company information.
However, MFA is most effective when combined with sensible access policies and modern authentication methods.
Password
The user’s password remains one component of authentication, but it should never be treated as the organisation’s only defence.
MFA
Additional authentication helps prevent stolen credentials alone from providing immediate access to Microsoft 365.
Location
Conditional Access can identify whether the authentication request originates from an expected or permitted location.
Device
Business Premium also provides the foundations for controlling access according to whether a device is managed and compliant.
A Layered Approach to Microsoft 365 Security
The project demonstrated why modern Microsoft 365 security shouldn’t depend upon one individual control.
No single technology makes an organisation immune to phishing or account compromise.
Instead, several controls work together:
- strong passwords
- multi-factor authentication
- Conditional Access
- Named Locations
- session revocation during security incidents
- authentication method reviews
- Microsoft Entra ID sign-in monitoring
- managed and compliant devices
- endpoint protection
- user awareness
If one layer fails, another can still prevent or limit the attack.
The Results
Stronger Security
Microsoft 365 access was protected by additional identity-based controls.
Reduced Exposure
Unnecessary authentication from unexpected geographical locations could be restricted.
Improved Authentication
MFA became part of a wider Conditional Access strategy rather than a standalone control.
Future Ready
Business Premium provided additional options for Intune, device compliance and endpoint security.
The immediate security incident was contained, but more importantly, the organisation emerged with a considerably stronger Microsoft 365 security posture.
Rather than waiting for the next suspicious login and reacting to it, controls were introduced to make many unwanted authentication attempts far less likely to succeed in the first place.
Going Further with Business Premium
Conditional Access was one of the most important improvements, but Microsoft 365 Business Premium provides considerably more security capability than geographical restrictions alone.
Further controls can include:
- Microsoft Intune device management
- device compliance policies
- requiring compliant devices for sensitive services
- Microsoft Defender for Business
- Windows security baselines
- BitLocker management
- stronger authentication methods
- application protection policies
- controlled administrator access
From Incident Response to Better Security
What began as an investigation into suspicious emails ultimately became an opportunity to strengthen the customer’s entire Microsoft 365 security posture.
By reviewing the sign-in evidence, securing the affected account, upgrading to Microsoft 365 Business Premium and implementing Conditional Access, the organisation gained much greater control over how and where its cloud services could be accessed.
Good security isn’t just about responding to an attack. It’s about making the next attack considerably harder.