Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For most Microsoft 365 organizations, the starting point is to require multifactor authentication (MFA) for every user, block legacy authentication, and monitor sign-ins. Use Microsoft Entra security defaults for a simple baseline without Entra ID P1, or Conditional Access for customizable policies if your licensing supports it. Then review Outlook forwarding and mailbox activity; OneDrive protection relies heavily on those shared identity controls, permissions, and monitoring.

Choose a tenant-wide MFA baseline

Microsoft offers two main ways to apply MFA protections across a work or school Microsoft 365 tenant. Security defaults are the simpler option; Conditional Access offers more control but demands policy design and testing.

Option License requirement What it provides Operational trade-off
Security defaults No Entra ID P1 license required. Requires all users to register for MFA, requires administrators to use MFA, and blocks legacy authentication. It is a baseline rather than a customizable policy set. Simpler to enable, but offers less flexibility for exceptions and conditions.
Conditional Access At least Microsoft Entra ID P1. Microsoft lists Microsoft 365 Business Premium and E3 as P1 examples; E5 is a P2 example. Confirm the organization’s current license assignments and entitlements. Lets administrators customize access policies and, where the required licensing and Identity Protection features are available, apply risk-based conditions. Requires policy design, testing, exclusions, and ongoing monitoring. Older clients or service workflows may be affected if they rely on legacy authentication.

Do not turn off security defaults until replacement Conditional Access protections are enabled. Microsoft identifies baseline policies for MFA for all users, MFA for administrators, blocking legacy authentication, and MFA for Azure management. An organization moving from defaults should have the replacement protections ready rather than leaving a gap.

Protect privileged accounts separately

Require MFA for ordinary users as well as administrators. Microsoft recommends keeping separate administration and standard-use accounts, rather than using a privileged account for routine productivity. This limits how often the higher-impact account is exposed to everyday sign-in risks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Consider risk-based policies where available

With the necessary licensing and Identity Protection features, Conditional Access can require MFA when sign-in risk is medium or higher and require a secure password change when user risk is high. These are conditional controls, not features to assume are available in every Microsoft 365 plan.

Select authentication methods that fit your users and tenant

MFA is the baseline; passwordless methods can change how users authenticate. Microsoft names Windows Hello for Business, Authenticator phone sign-in, and FIDO as passwordless options. Availability depends on the user’s account, device, and tenant configuration.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Authenticator phone sign-in: can provide a passwordless sign-in experience through the Microsoft Authenticator app. Users still need a workable recovery path if they lose or replace their phone.
  • Windows Hello for Business: is a passwordless option tied to a supported Windows sign-in setup; device and tenant compatibility matter.
  • FIDO2 security key: a hardware-key option for compatible accounts and policies. Check tenant and device support before choosing keys; buying a key does not itself enable tenant MFA or guarantee protection in every sign-in flow.

Microsoft states in its 2024 security-defaults guidance that “MFA can block over 99.2% of identity-based attacks” in a discussion of removing the MFA registration grace period. That is Microsoft’s stated figure, not a guarantee for a particular organization. The same Microsoft page separately says that more than 99.9% of common identity-related attacks are stopped by MFA and blocking legacy authentication; the figures describe different scopes and controls and should not be combined.

Find legacy sign-ins before blocking them

Legacy protocols such as POP, IMAP, and SMTP do not support MFA, so an attacker with a compromised password may be able to use an older authentication path that bypasses modern controls. Microsoft recommends enabling modern authentication in Exchange Online and SharePoint Online, then blocking legacy authentication through Conditional Access for appropriately licensed tenants or through security defaults.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Review sign-in logs first. Look for legacy-client use, including noninteractive user sign-ins, and identify users, devices, or service workflows that depend on it.
  2. Test Conditional Access in report-only mode. Microsoft recommends evaluating a policy’s impact before enforcing it. Use the results to identify sign-ins that would be blocked and resolve legitimate dependencies.
  3. Keep emergency access available. Maintain appropriate emergency access accounts and account for them in policy exclusions so a configuration mistake does not lock administrators out.
  4. Enforce only after review. Once dependencies and likely impact have been addressed, apply the block using the tenant’s selected baseline.

Harden Outlook against forwarding and mailbox abuse

Review external forwarding and unexpected rules

Attackers may create external forwarding rules to copy messages outside the organization or retain access to information. Use Microsoft’s Secure Score forwarding-rule review to find external forwarding and consider whether it should be prevented. Review the Autoforwarded messages report for forwarding activity. A destination or rule the mailbox owner does not recognize is an investigation lead, not proof by itself that an account was compromised.

Make it easy to report suspicious messages

Encourage users to use Outlook’s built-in Report button. Administrators can configure reported messages to go to an internal reporting mailbox, Microsoft, or both. Microsoft documents that cloud mailboxes receive built-in protections, with suspected malware and high-confidence phishing quarantined by default under the service’s documented behavior. Broad allowlists can override protections, so avoid adding senders or domains without a specific, reviewed need.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Secure OneDrive through identity and permission controls

The Microsoft identity guidance relevant here supports MFA, blocking legacy authentication, suitable Conditional Access, and monitoring sign-in and audit logs; it does not establish a separate OneDrive account-takeover checklist. Treat OneDrive access as part of the same identity perimeter as Outlook rather than assuming a separate app setting can compensate for a compromised sign-in.

  • Apply the tenant’s MFA baseline and block legacy authentication after checking for dependencies.
  • Use least-privilege access so users and applications have only the access they need.
  • Monitor sign-in and audit logs for activity that warrants investigation.
  • Audit application permissions that users have consented to. A malicious app permission can expose or manipulate email and other user data, so review granted access rather than focusing only on passwords.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use logs and audit records when investigating a suspected takeover

Mailbox auditing is turned on by default in Microsoft 365 organizations. Microsoft says it records predefined mailbox actions for owner, delegate, and admin sign-in types, and administrators can search those records. The default does not mean every conceivable action is captured: Microsoft documents limitations, including caveats for cross-geo mailbox auditing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

When a mailbox may be compromised, correlate mailbox evidence with identity activity rather than relying on one signal alone. Review unexpected inbox rules and forwarding destinations, mailbox access records, and sign-in activity. Where Entra ID Protection is available, review risky sign-in and risky-user reports. Microsoft recommends monitoring sign-in and audit logs; organizations needing longer retention can export logs to Azure Monitor or a SIEM.

  • Unexpected forwarding: compare mailbox rules and destinations with the user’s expected behavior and the Autoforwarded messages report.
  • Unfamiliar mailbox activity: search available mailbox audit records for relevant owner, delegate, or administrator actions, bearing in mind the documented audit limits.
  • Risk signals: check sign-in logs and, if licensed and available, risky sign-in and risky-user reports.
  • Connected applications: review application consent and permissions that could expose or manipulate the user’s data.

Microsoft’s identity infrastructure guidance describes security defaults as enforcing MFA for all users in a tenant and blocking legacy-protocol sign-ins tenant-wide. The practical value is that the same identity controls help protect access to both Outlook and OneDrive, while mailbox rules, app permissions, and audit records provide additional places to find suspicious activity.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.