IDENTITY / FOXBYTE SYSTEMS

Secure the accounts and email your business runs on.

Start with the tenant you actually have. Agree identity and email controls that fit its licences, users, legitimate senders and support responsibilities.

IDENTITY + EMAIL

  • Who can sign in?
  • What can they access?
  • Which messages are trusted?
  • Who checks changes?

Review identity and mail flow together.

AreaWhat the review should establish
Sign-in and MFAWhich users and privileged roles are covered, how exceptions are controlled and how recovery works.
Administrator accessWho holds privileged roles, why they need them and how access is reviewed.
Mailbox behaviourWhether forwarding, rules, delegated access and account changes match approved business use.
Email authenticationWhich systems send legitimately for the domain and how SPF, DKIM and DMARC are configured and monitored.
Phishing protectionWhich relevant protections are licensed and configured, and how staff report suspicious messages.
Staff changesHow access, shared information and business continuity are handled when people join, move or leave.

Plan changes that protect access without disrupting work.

Illustrative process — agree the actual scope before implementation.

  1. InventoryConfirm licences, accounts, applications and legitimate senders.
  2. DesignAgree sign-in policies, exceptions and recovery access.
  3. PilotTest representative users, devices and business workflows.
  4. Roll outCommunicate the change and handle exceptions.
  5. ReviewCheck coverage, logs and unresolved gaps.

A subscription feature is not proof of configuration or coverage. Microsoft provides different MFA deployment approaches with different licensing and policy behaviour. Choose against the tenant’s actual requirements, and retain controlled emergency access and a tested recovery path.

Protect legitimate email while addressing spoofing.

Email authentication work starts with an inventory of approved senders: user mail, website forms, finance systems and other authorised services. A strict policy applied without that inventory can affect legitimate mail. Changes should have a recorded owner, an observation period appropriate to the environment and a way to resolve unexpected rejection.

Authentication does not make every message safe. An attacker may use a compromised legitimate account or persuade a person to approve a request. Combine domain controls with sign-in protection, mailbox review and a usable reporting process.

What a useful handover should contain.

  • The tenant and account scope, without exposing credentials.
  • The intended controls, exceptions and configuration owner.
  • A record of representative testing and unresolved issues.
  • The joiner, mover, leaver and administrator-review responsibilities.
  • An agreed suspicious-message and suspected-account-compromise contact path.
  • Licensing, reporting, support hours and excluded activities.
Use the Microsoft 365 Security Buyer Checklist Keep Microsoft 365 within the broader security plan

Questions before tenant changes.

Does Microsoft 365 already include everything we need?

The answer depends on your actual subscriptions and requirements. Inventory licences and enabled controls; do not assume that an Office 365 and Microsoft 365 plan with a similar name includes the same features.

Does MFA remove phishing risk?

MFA strengthens sign-in protection, but it does not make every authentication method or interaction equally resistant to phishing. Select suitable methods and retain user guidance, session and application controls where appropriate.

Can you investigate a currently compromised mailbox?

Describe the situation through a safe contact route and confirm the available scope first. Do not assume emergency response, forensics or a particular response time. Follow your organisation’s incident plan and authorised responder arrangements.

Should we send an administrator password?

No. Initial scoping needs a description, account counts and relevant concerns. Any access must later use an approved, limited and accountable method.

Start with the tenant and the concern.

Tell us whether the priority is access, suspicious email, administrative control or a clearer security baseline.

Foxbyte Insights

Prepare for the decision.

Talk to Us

Talk to Us

AI-assisted · Human help available

How can we help?

I’m Foxbyte’s AI assistant. Ask about a service, or talk to a person.

Scroll to Top