Conquer Microsoft 365 ransomware protection for your tenant

Microsoft 365 Ransomware Considerations

20 January 2023

All IT professionals will be familiar with the collaboration tools, email, cloud storage, Office apps, and other features offered by the Microsoft Office 365 ecosystem. It is only logical to wonder where the risks are within Microsoft 365 ransomware attacks that continue to afflict businesses of all sizes.

Microsoft 365 Ransomware

Microsoft 365 is not inherently dangerous, to be precise. However, suppose you do not use the security features built into the ecosystem while adhering to best practices. In that case, your company may be vulnerable to ransomware assaults through Microsoft 365. The reality of ransomware is that you will be a target today. Whatever your turnover or size, it is a matter of when, not if.

This article will discuss a few Microsoft 365 locations where threat actors can access data. It outlines practical ransomware prevention measures to raise your Microsoft 365 instance’s security posture.

It pays to prepare and defend yourself in advance because you must take these preventative steps (plus a lot more) if attacked.

The Threat of Microsoft 365 Ransomware Arises

Fraudulent emails

Threat actors create and distribute convincing emails that persuade recipients to click on malicious links or divulge their application login information. These phishing emails represent an essential entry point for ransomware attacks into a network. When replying to an email in Outlook, an unaware employee could accidentally divulge their login information. Another option is for a worker to download an attachment that infects their local computer. Phishing emails may cause a damaging ransomware attack if insufficient controls exist.

Directory Synchronisation

Synchronising Active Directory accounts between organisations’ on-premises Active Directory and its Office 365 tenancy is joint. Authentication is the first system you put online, and email is the second. Therefore, if they remove both your 365 and your internal or Azure servers, they have taken both, which, in addition to everything else, implies that you cannot even communicate with your staff. Check that the backdoor accounts cannot be misused and confirm that the appropriate alerting is enabled for any admin-level operations. None of this comes with Microsoft 365 as standard equipment, but it is still a product feature. Just the correct setup is needed.

SharePoint Online

It is not good when one local machine contracts ransomware, but it is not the end of the game. The real problems start when ransomware spreads by a lateral movement to other hosts, eventually shutting down an entire enterprise.

An attacker could take over one local workstation and upload a malicious file to SharePoint Online. Users who engage with this file, such as through an email attachment or a link shared in Teams, infect more workstations, accelerating the ransomware spread. Giving employees access to SharePoint libraries they do not need only adds fuel to the fire because it violates the principle of least privilege.

Tips for Avoiding Microsoft 365 Ransomware

Microsoft 365 ransomware protection is built-in protection against ransomware, but you must be aware of them and ensure they are appropriately set up.

  • Since Microsoft 365 already contains the required tools, it is left to comprehend and customise them to your company’s needs. Here are some concrete suggestions you can use to stop ransomware attacks on Microsoft 365 as a starting point.
  • Protect endpoints with detection and response (EDR) software: It is more challenging to observe endpoint device behaviour and interactions with other devices on a network when employees are remote and mobile. A specialised EDR solution is required to protect end-user devices like laptops and desktops. Windows Defender, Microsoft’s EDR product that uses AI-driven methodology and behavioural analytics, is integrated into Microsoft 365. If Defender is connected to Azure Sentinel for visibility, it can detect irregularities that could indicate compromise.
  • Please adhere to the principle of least privilege: These code limits access rights so that people can only access the files, apps, and data necessary to conduct their daily tasks. This security principle helps guard against the possibility that ransomware will spread throughout your network if someone manages to compromise an account with elevated privileges. Use Microsoft 365’s role-based access control (RBAC) and privileged identity management (PIM) to implement this best practice principle.
  • Set your organisation’s password expiration policy in the Microsoft 365 admin centre to require frequent password changes. Every few months, you should make someone change their password. If Multifactor Authentication (MFA) is enabled, the duration can be increased to a year.

Regular password changes are required by ISO 27001 (Annex 9.4.3) and PCI (Payment Card Industry) DSS (3.2.1). However, the Department of Commerce National Institute of Standards and Technology recently changed this requirement to favour MFA. Hackers may conduct network reconnaissance for weeks or months using compromised accounts. The importance of routine password changes cannot be overstated for administrators.

  • Use multi-factor authentication. Since users are the weakest point in your company’s security defences, you must use authentication controls to keep them safe. Before allowing users to log in or conduct specific actions, Multi-Factor Authentication requires an additional layer of verification in addition to their login credentials. Ensure you turn on the mandatory MFA security default setting in all Microsoft 365 plans for your entire organisation.
  • Use conditional access to limit access to only specific IP ranges or nations. Conditional access allows you to set controls restricting access from all other sources. A login attempt from a new region of the world would be rejected if your employees were spread across four different nations. Through the Azure Active Directory admin centre, conditional access can be enabled and customised.

As explained in our blog post on SaaS (Software as a Service) backup, please back up your M365 data because it is not automatically backed up. Microsoft uses a shared responsibility model, which means you are responsible for backing up and managing your data while they guarantee the uptime of your platform. It is possible to back up M365 using third-party solutions. You need to know what your M365 backup tool covers when looking for one. Does it only protect mailboxes, or does it also cover Teams channels and SharePoint libraries?

What to do?

Protecting your Microsoft 365 data is crucial, especially in the face of increasing Microsoft 365 ransomware attacks that can compromise your critical files and information.

With its impressive security features, Microsoft 365 will keep ransomware from wreaking havoc on your company. Our selection of contemporary office solutions at Server Consultancy can strengthen your Microsoft 365 ransomware defences. Our Microsoft 365 backup solution keeps your data secure and readily recoverable. We offer enterprise security services, covering essential topics like identity and privileged access control. Act right away to stop ransomware because, to put it simply, prevention is always preferable to treatment. Contact our knowledgeable staff immediately to find out how we can assist you.