IDENTITY / FOXBYTE SYSTEMS
Secure the accounts and email your business runs on.
Start with the tenant you actually have. Agree identity and email controls that fit its licences, users, legitimate senders and support responsibilities.
IDENTITY + EMAIL
- Who can sign in?
- What can they access?
- Which messages are trusted?
- Who checks changes?
Review identity and mail flow together.
| Area | What the review should establish |
|---|---|
| Sign-in and MFA | Which users and privileged roles are covered, how exceptions are controlled and how recovery works. |
| Administrator access | Who holds privileged roles, why they need them and how access is reviewed. |
| Mailbox behaviour | Whether forwarding, rules, delegated access and account changes match approved business use. |
| Email authentication | Which systems send legitimately for the domain and how SPF, DKIM and DMARC are configured and monitored. |
| Phishing protection | Which relevant protections are licensed and configured, and how staff report suspicious messages. |
| Staff changes | How access, shared information and business continuity are handled when people join, move or leave. |
Plan changes that protect access without disrupting work.
Illustrative process — agree the actual scope before implementation.
- InventoryConfirm licences, accounts, applications and legitimate senders.
- DesignAgree sign-in policies, exceptions and recovery access.
- PilotTest representative users, devices and business workflows.
- Roll outCommunicate the change and handle exceptions.
- ReviewCheck coverage, logs and unresolved gaps.
A subscription feature is not proof of configuration or coverage. Microsoft provides different MFA deployment approaches with different licensing and policy behaviour. Choose against the tenant’s actual requirements, and retain controlled emergency access and a tested recovery path.
Protect legitimate email while addressing spoofing.
Email authentication work starts with an inventory of approved senders: user mail, website forms, finance systems and other authorised services. A strict policy applied without that inventory can affect legitimate mail. Changes should have a recorded owner, an observation period appropriate to the environment and a way to resolve unexpected rejection.
Authentication does not make every message safe. An attacker may use a compromised legitimate account or persuade a person to approve a request. Combine domain controls with sign-in protection, mailbox review and a usable reporting process.
What a useful handover should contain.
- The tenant and account scope, without exposing credentials.
- The intended controls, exceptions and configuration owner.
- A record of representative testing and unresolved issues.
- The joiner, mover, leaver and administrator-review responsibilities.
- An agreed suspicious-message and suspected-account-compromise contact path.
- Licensing, reporting, support hours and excluded activities.
Questions before tenant changes.
Does Microsoft 365 already include everything we need?
The answer depends on your actual subscriptions and requirements. Inventory licences and enabled controls; do not assume that an Office 365 and Microsoft 365 plan with a similar name includes the same features.
Does MFA remove phishing risk?
MFA strengthens sign-in protection, but it does not make every authentication method or interaction equally resistant to phishing. Select suitable methods and retain user guidance, session and application controls where appropriate.
Can you investigate a currently compromised mailbox?
Describe the situation through a safe contact route and confirm the available scope first. Do not assume emergency response, forensics or a particular response time. Follow your organisation’s incident plan and authorised responder arrangements.
Should we send an administrator password?
No. Initial scoping needs a description, account counts and relevant concerns. Any access must later use an approved, limited and accountable method.
Sources and further reading
Start with the tenant and the concern.
Tell us whether the priority is access, suspicious email, administrative control or a clearer security baseline.
Foxbyte Insights
Prepare for the decision.
Cybersecurity
Microsoft 365 security: a buyer’s checklist
Ask what is licensed, what is configured, what has been checked and who responds. A feature appearing in a subscription is not evidence that it protects every intended account or that an operational owner reviews its alerts.
Foxbyte InsightsPublished Updated
Read the guide: Microsoft 365 security: a buyer’s checklistCybersecurity
SPF, DKIM and DMARC: what a business owner should ask
SPF, DKIM and DMARC help receiving systems evaluate email-domain authenticity. They are useful controls, but they do not prove that a message’s business instruction is legitimate.
Foxbyte InsightsPublished Updated
Read the guide: SPF, DKIM and DMARC: what a business owner should askCybersecurity
Employee offboarding: close access without losing business records
Offboarding should close access at the agreed time while preserving authorised business records. Deleting an account is only one possible step in that process.
Foxbyte InsightsPublished Updated
Read the guide: Employee offboarding: close access without losing business records