Back to category

Week 6

Assess Exchange Online Protection Policies for a Client Tenant

Beginner
Microsoft Security Engineer
Cloud Security Engineer
Microsoft Security Best Practices
Exchange Online Protection
Email Security

Client Background

A mid-size professional services firm has reported an increase in phishing emails reaching employee inboxes. Review the tenant's Exchange Online Protection (EOP) configuration, including anti-spam, anti-malware, and anti-phishing policies, to identify gaps allowing malicious mail through.

Business Environment

Bermont Advisory (220 employees, single M365 E3 tenant) migrated email to Exchange Online 18 months ago but left most EOP defaults untouched. Finance and client services staff are high-value phishing targets, and the firm processes wire-transfer instructions over email. IT is a four-person shared function with no dedicated email-security analyst.

Security Incident

No confirmed compromise; the trigger was three business-email-compromise (BEC) attempts in the past two months where spoofed payment-instruction emails reached the CFO's inbox and were narrowly avoided. Leadership commissioned this review to harden EOP before a near-miss becomes a loss.

Scope

Exchange Online Protection policies, mail flow rules, and connection filtering for the client tenant.

Objectives

  • Review anti-spam and anti-malware policy settings
  • Evaluate anti-phishing and impersonation protection
  • Assess mail flow rules (transport rules) for security gaps
  • Recommend EOP hardening improvements

Required Deliverables

EOP Configuration Assessment Report
2 hrs estimated