Skip to main content
Liberty GardenSolutions

Cybersecurity

How to protect Microsoft 365 accounts from phishing

How to protect Microsoft 365 accounts from phishing: multi-factor authentication, conditional access, admin consent controls, mailbox rules, and training.

Published July 13, 2026 · Updated July 19, 2026


Phishing is the single most common way small-business Microsoft 365 accounts get compromised, and the attacks are getting harder to spot — realistic login pages, fake approval prompts, and emails that appear to come from inside your own company after one account falls. The good news: a handful of controls, most already included in your Microsoft 365 license, stop the vast majority of these attacks. Here’s the practical list, in order of impact.

Turn on MFA and set sign-in rules

Multi-factor authentication (MFA) is the single most effective control you can enable. Even if an attacker obtains a password, they still can’t sign in without the second factor — the code on a phone or the approval prompt. Every account needs it, not just administrators, because a receptionist’s account is just as valuable to an attacker as the owner’s. In Microsoft 365, this is a settings change, not a project; do it this week. If you’re not ready for custom policies, start with the built-in security defaults, which enable MFA for everyone and block legacy sign-in methods automatically.

Once MFA is on, add conditional access to define who can sign in from where and under what conditions: require MFA everywhere, block sign-ins from countries you don’t do business with, and require a managed device for admins. Conditional access also defeats the newer phishing that steals session cookies — an attacker can’t replay a sign-in that requires your approval. This is where professional setup earns its keep, because the rules need to be tight enough to stop attacks without locking out legitimate staff.

A growing phishing technique doesn’t steal a password at all — it tricks a user into approving a malicious app’s access to their account through a fake consent screen. In Microsoft 365, restrict who can grant admin consent to apps, and require approval for everything else. Every app your staff uses should be visible in your tenant’s app inventory, and anything unapproved is a red flag.

Watch for mailbox rules and forwarding

Once an attacker controls an account, they often create inbox rules — “delete emails about invoices,” or “forward everything to this external address” — to hide their activity and exfiltrate data quietly. These rules are easy to miss, which is why regular audits matter: check for unexpected forwarding rules, and set alerts when external forwarding appears. If you were compromised last month, this is often how you’d find out.

Train people without blaming them

The best technical controls still fail eventually, so the last line of defense is a team that knows what to look for: unexpected attachments, urgency pressure, lookalike domains, and requests to move money or buy gift cards. Keep it practical — quarterly five-minute refreshers beat a one-hour annual lecture — and give people a simple way to report suspicious email. Make it safe to report a mistake; a team that hides clicks can’t help you catch an attack.

Next step

Most of these controls are already in your Microsoft 365 license — they just need to be turned on and configured properly, which is a few hours of work that saves you from a multi-day incident. Request a consultation and we’ll audit your tenant, enable MFA and conditional access, lock down app consent, and set up forwarding alerts as part of our Microsoft 365 support and networks & security services.

#cybersecurity#phishing#microsoft-365#mfa

Next step

Want to talk it through?

Articles are a starting point. If this topic matters to your business right now, a consultation is the fastest way to a straight answer.