Most email compromise starts with a setting that was never configured, not a sophisticated attack. Work through this list.
- Multifactor authentication is enforced, not optional. A conditional access policy that requires it, rather than a recommendation staff can ignore.
- Anti-phishing policies are turned on. Microsoft Defender's impersonation protection catches lookalike domains and display-name spoofing that basic filtering misses.
- External email is labeled. A banner marking messages from outside your organization makes spoofed internal emails easier for staff to spot.
- Mail forwarding rules are reviewed. Auto-forwarding to external addresses is a common sign of a compromised mailbox — and one attackers rely on to stay hidden.
- Safe Links and Safe Attachments are enabled, if your licensing includes them, so malicious links and files are checked before they reach an inbox.
- Legacy authentication protocols are blocked. Older sign-in methods don't support modern MFA and are a common way stolen passwords are still exploited.
None of these require new software — they're switches inside the tenant you're already paying for.

