Preventing business email compromise in Microsoft 365

Zybim guides · identity security

Business email compromise doesn't encrypt your files or announce itself with a ransom note — it quietly redirects your money, and by reported losses it outranks ransomware. The playbook is consistent: steal a credential, log in like a legitimate user, study the mailbox, then intervene in a real financial conversation at the perfect moment.

Why "hackers don't break in, they log in" is literally true

BEC needs no malware and no exploit. A phished or sprayed password plus an account where MFA isn't enforced equals full mailbox access that looks, to every security tool, like the user themselves. Attackers then add inbox rules to hide their tracks — auto-deleting replies from the bank, forwarding invoices externally — and wait.

The control stack that breaks the chain

Enforce MFA on every sign-in — the single highest-value control, breaking the stolen-password step. Block legacy authentication, or the enforcement has a bypass lane. Enable sign-in risk policies (Entra ID P2) so an impossible-travel login triggers a challenge or block. Turn on mailbox auditing and alerting for new inbox rules — the attacker's rule creation is often your earliest detectable signal. Add payment-process controls outside IT: any bank-detail change gets verified on a known phone number, no exceptions, including for the CEO.

Where your tenant stands right now

Every technical control above corresponds to a Microsoft Secure Score item — which means a two-minute assessment tells you exactly which parts of the BEC kill-chain are currently open in your tenant, ranked by impact.

How exposed is your tenant? Find out in two minutes with the free, read-only Microsoft 365 security assessment.

Run the free assessment