Reduce the Exchange Online attack surface by blocking Exchange Web Services (EWS) when it is not required and migrate legitimate application dependencies to Microsoft Graph.
Hardening items
4 recommendations. Filter by category, criticality, maturity tier, or system.
Block Access to Exchange Web Services (EWS)
TrackUpdated Jul 31, 2026Microsoft 365 · Microsoft Exchange Online
Prevent Downloading of Enclosures
TrackPrevent users from downloading email attachments to unmanaged or untrusted devices to reduce the risk of data leakage and unauthorized file distribution.
Updated Jul 21, 2026Microsoft 365 · Microsoft Exchange Online · Microsoft Purview · Microsoft Defender
Configure Safe Links and Safe Attachments in Defender for Office 365
TrackEnable time-of-click URL scanning and sandbox-based attachment detonation to stop phishing links and malicious files before they reach users.
Updated Jul 9, 2026Microsoft 365 · Microsoft Exchange Online
Enforce MFA and Block Legacy Authentication with Conditional Access
TrackRequire multi-factor authentication for all users and block legacy protocols (IMAP, POP, SMTP AUTH) that bypass MFA entirely.
Updated Jul 9, 2026Microsoft 365 · Microsoft Entra ID · Microsoft Exchange Online