Reduce the Exchange Online attack surface by blocking Exchange Web Services (EWS) when it is not required and migrate legitimate application dependencies to Microsoft Graph.
Hardening items
13 recommendations. Filter by category, criticality, maturity tier, or system.
Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Disable NetBIOS name resolution to reduce legacy attack surfaces, prevent name spoofing attacks, and encourage secure DNS-based name resolution.
Prevent users from downloading email attachments to unmanaged or untrusted devices to reduce the risk of data leakage and unauthorized file distribution.
Deploy Microsoft Defender for Identity sensors on every domain controller to detect reconnaissance, lateral movement, and identity-based attacks in real time.
Prevent sensitive business data from being exposed to AI services by implementing data classification, access controls, DLP policies, and approved AI usage guidelines.