Netwrix 1Secureは、データとアイデンティティ全体にわたる統合された可視性を提供します。14日間の無料トライアルでフルアクセス可能です。無料トライアルを開始

リソースセンターブログ

Microsoft 365 セキュリティ: デフォルトを超えてテナントを強化する方法

Microsoft 365 セキュリティ: デフォルトを超えてテナントを強化する方法

Oct 6, 2026

Microsoft 365 のセキュリティは、デフォルト設定が開放している設定に依存しているため、プラットフォーム自体が安全でも、identity、メール、共有、データのコントロールがポリシーの要求よりも弱くなることがあります。誤ったアクセス範囲のルール、オープンなコラボレーションのデフォルト、短いログ保持期間、後の設定の変動により、データが露出し、監査証拠が弱まる可能性があります。これらを修正するには、意図的な tenant の強化、文書化されたレビュー、および設定変更の継続的な可視化が必要です。

CoreViewは報告しました 過去12か月間に、45%の大規模組織がMicrosoft 365の誤設定によりセキュリティまたはコンプライアンスのインシデントを経験したことを。同じ調査は、160万人のMicrosoft 365ユーザーの分析に基づき、90%の組織が パスワードポリシー やログイン失敗の監視など、基本的なセキュリティコントロールの実施に苦労していることを明らかにしました。

これらは構成の失敗であり、構成は顧客側にあるMicrosoftの共有責任モデルの一部です。Microsoftはデータセンター、ハイパーバイザー、サービスコードを含むプラットフォーム自体を保護します。テナント設定は、共有のデフォルトからMFAポリシーの範囲指定まで顧客の責任であり、多くのデフォルト設定は制限よりもコラボレーションを優先しています。効果的な強化には、意図的な構成、文書化された証拠、および時間の経過によるずれを検出するレビューの頻度が必要です。

なぜMicrosoft 365のデフォルト設定では不十分なのか

Microsoftの共有責任モデルは一言で言うと、Microsoftがインフラを保護し、顧客がデータ、アカウント、エンドポイント、およびaccess managementの責任を負う、ということです。SaaSでも同様です。

Microsoftはセキュリティ既定値を標準で提供し、すべての新しいテナントで有効にします。セキュリティ既定値は、すべてのユーザーに多要素認証(MFA)の登録を強制し、16の管理者ロールにMFAを要求し、レガシー認証プロトコルをブロックし、2026年7月1日以降、新しいテナントでデバイスコードフローをブロックします。これは追加設定なしで利用可能な最大限の保護であり、本当に役立つベースラインです。

Security Defaultsには中間の選択肢はありません:オンかオフのどちらかであり、break-glassアカウントの除外、デバイス準拠や場所の条件、リスクベースのポリシー、そしてjust-in-time admin elevationはありません。また、Conditional Accessと共存できず、一方を有効にするともう一方が無効になります。詳細な制御や例外が必要な組織はConditional Accessを使用すべきです。

同じパターンがスイート全体で繰り返されます。StandardおよびStrictのメール保護プリセットは「誰にも割り当てられていません」 管理者が割り当てるまで、外部共有はデフォルトでオンになっており、管理者はデータ損失防止(DLP)ポリシーを作成する必要があります。

Identity とアクセスの構成

Identityはほとんどのテナント侵害が始まる場所であり、Microsoftが最も多くの設定を顧客に任せている部分でもあります。Identityの強化とは、認証を強化し、アクセス ポリシーを一貫して適用し、常時権限を緊急アクセスに実際に必要な範囲に削減することを意味します。

MFAを強制し、レガシー認証を排除する

特権アカウントをフィッシング耐性のMFAに移行し、レガシー認証がすべての場所でブロックされていることを確認してください。Microsoftのauthentication strengthsは、Fast Identity Online 2(FIDO2)認証標準、Windows Hello for Business、および証明書ベースの認証をフィッシング耐性としてランク付けしています;push notifications and time-based one-time password (TOTP) codesはそうではありません。中間者攻撃キットがこれらを中継するためです。

The Tycoon2FA kitは月間50万以上の組織に届き、Proofpointの2025年の広範な調査によると、業界全体で乗っ取られたアカウントの59%がMFAを有効にしていました。レガシー側では、Microsoftのデータは97%以上のクレデンシャルスタッフィング攻撃がレガシー認証を使用していることを示しています。MicrosoftはすべてのExchange Onlineテナントで基本認証を無効にしており、Simple Mail Transfer Protocol認証(SMTP AUTH)が2026年12月末まで唯一の例外となっています。

Netwrix AuditorはEntra IDの変更を、誰がいつ行ったか、変更前後の値を含めて追跡するため、ロールバックされた強化設定も記録が残ります。デモをリクエストしてください。

条件付きアクセス ポリシーを構成する

デバイスの準拠状況、場所、リスクに基づいて条件付きアクセスを構築し、すべてのポリシーを強制モードで実行します。堅牢なConditional Accessの基盤であるEntra ID P1には、管理者向けMFA、すべてのユーザー向けMFA、レガシー認証のブロック、および準拠デバイスの要件が含まれます。リスクベースのサインインおよびユーザーポリシーにはEntra ID P2が必要です。

Huntressは、分析した78件の侵害アカウントのうち55件がMFAを要求するアクティブな条件付きアクセス ポリシーを持っていましたが、スコープの誤り、レポート専用モード、条件の不一致によりポリシーは失敗しました。これにより、施行モードが結果を決定する要素となります。これらのポリシーからemergency access accountsを除外し、誤作動があっても緊急管理アクセスが利用可能な状態にしてください。

管理者ロールの監査と管理

常時のGlobal Administratorの割り当てを緊急アクセスアカウントに絞り、それ以外はすべてPrivileged Identity Management(PIM)を通じてルーティングします。Global Administratorの割り当ては5未満に制限してください。Microsoftの管理センターは、テナントがその閾値を超えた場合に通知します。

PIM には Entra ID P2 が必要です. PIM の展開は 緊急アクセス以外で常時アクティブな割り当てを持たず、1~24時間の有効化ウィンドウと少なくとも2人の承認者が必要です。2つの恒久的な例外は クラウド専用のブレークグラスアカウント*.onmicrosoft.com ドメインで、フェデレーションと同期から独立しています。

メールとコラボレーションの強化

Microsoft 365のコラボレーション領域は、メール、SharePoint、OneDrive、Teamsを含み、デフォルト設定は制限よりも使いやすさを優先しています。強化するには、誤設定がインシデントになる前に認証、共有権限、メールボックスルールの可視性を厳しくする必要があります。

メール認証とフィッシング対策

Publish Sender Policy Framework (SPF) with a hard fail, enable DomainKeys Identified Mail (DKIM) on every custom domain, and move Domain-based Message Authentication, Reporting, and Conformance (DMARC) to p=reject. The standard SPF record is v=spf1 include:spf.protection.outlook.com -all, with -all recommended once DKIM and DMARC are also in place. DMARC should progress from p=none through p=quarantine to p=reject.

受信フィルタリングも同様の注意が必要です。デフォルトのアンチフィッシングポリシーでは、なりすまし保護とフィッシングのしきい値が未設定のままです。Standardプリセットはフィッシングのしきい値をレベル3(「より積極的」)に上げ、なりすまし保護を設定し、Strictは疑わしいメッセージを隔離に送ります。

Safe Links と Safe Attachments には Defender for Office 365 が必要です。Business Premium に含まれており、E3 には 2026年7月1日から含まれています。組み込みの Configuration Analyzer は、テナントを Standard および Strict ベースラインと比較し、構成のドリフト分析タブを含みます。

外部共有コントロール

ユーザーが取り消せないリンクを生成する前に、SharePoint と OneDrive の共有を厳格化します. Microsoft は デフォルトで外部共有を有効にし、環境全体で OneDrive のデフォルトリンクタイプを「リンクを知っている全員」に設定し、Anyone リンクが Conditional Access の管理されていないデバイス ポリシーを完全にバイパスすることを許可します.

Set the organization level to guests only, change the default link type to specific people, and apply domain allow or block lists, which support up to 5,000 domains. Teams needs a parallel pass. Microsoft enables guest access, federation with all external domains, and anonymous meeting join by default. Restrict federation to trusted domains and set lobby bypass to people in your organization.

メールボックスルールと自動転送の衛生管理

テナントの年齢によって表示されるデフォルトが異なるため、送信側の自動転送を明示的にオフに設定してください。デフォルトは「自動 - システム制御」と表示され、2021年以降に作成されたテナントではオフとして機能しますが、古いテナントではオンと同等のままの場合があります。したがって、値を明示的に設定してください 表示を信用せずに。

次の remote-domain コマンド で並列パスを閉じます Set-RemoteDomain -Identity Default -AutoForwardEnabled $false。次に、高リスクアカウントの受信トレイルールを監査します。 メールボックス監査ログはデフォルトでルール操作を記録します。

Proofpointの調査によると、2025年第4四半期に侵害されたアカウントの約10%でアクセス後に悪意のあるメールボックスルールが作成され、最速のルール作成は乗っ取り後わずか5秒でした。

Data protection configuration

Microsoft 365 data protection doesn't happen automatically. Sensitivity labels, DLP policies, and audit log retention all depend on administrators actively configuring them, and the defaults leave sensitive content unlabeled and under-logged until someone does.

Sensitivity labels and DLP policies

Enable label processing for SharePoint and OneDrive first, because downstream controls depend on it. The label-processing prerequisite is Set-SPOTenant -EnableAIPIntegration $true; after administrators apply it, a label and its encryption remain with the file wherever users store it, including after download.

Container labels on Teams and SharePoint sites don't flow down to the items inside them, and auto-labeling requires E5-tier licensing. Plan around both before rollout.

To block downloads to unmanaged devices, Set-SPOTenant -ConditionalAccessPolicy AllowLimitedAccess enforces browser-only access with no download, print, or sync. Those session controls don't support the Teams desktop application. For DLP itself, deploy in simulation mode first, review matches, then move to enforcement.

Retention and audit log configuration

Extend audit log retention past the default before an investigation forces the issue. Audit (Standard) retains records for 180 days. Audit (Premium) on E5 extends Entra ID, Exchange, SharePoint, and OneDrive events to one year, with a separate add-on reaching ten years.

IBM reported the average breach lifecycle at 241 days, and the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 requires twelve months of audit log retention. Sophos found logs missing in 47% of incident cases it analyzed.

Entra ID sign-in logs run on a separate clock, with retention of just seven days on the free tier and 30 days on P1/P2.

The configuration drift problem

Huntress analyzed more than 12,000 tenants and found more than 50% of recommended controls missing in 60% of them, including environments that already used posture tooling. Microsoft's Secure Score history tracks regressions caused by configuration, user, or device changes.

Administrators roll back settings to unblock a project, exceptions accumulate as staff turns over, and each change looks reasonable in isolation. The Netwrix 2026 Data and Identity Security Report found that 76% of organizations don't immediately and automatically revoke access after users no longer need it. In the survey behind it, 66% said some or most privileged roles keep standing, always-on access.

CoreView reported that 38% of organizations detect configuration tampering through manual review alone and 17% have no detection method at all.

Mapping configuration to compliance evidence

Effective audit evidence must show both control design and operating effectiveness. Auditors across frameworks define design evidence as the configuration at a point in time. Operating-effectiveness evidence proves the control ran continuously, covered the full population, and handled exceptions.

The same Netwrix research found that 74% of organizations cannot get a single unified view of where sensitive data resides and which identities can access it. A Service Organization Control 2 (SOC 2) Type II report evaluates controls over six months or more.

Cybersecurity Maturity Model Certification (CMMC) assessors verify controls using three defined methods, described in assessment guidance as "examine, interview, and test." One NOT MET assessment objective fails the entire security requirement. Health Insurance Portability and Accountability Act (HIPAA) enforcement follows the same logic. The Office for Civil Rights' (OCR's) 2025 action against Warby Parker cited "a failure to implement procedures to regularly review records of information system activity" as a distinct violation, meaning logging that nobody reviews still fails.

The most common evidence failures are an MFA policy left in report-only mode when enforcement is required and drafts or other unofficial records standing in for written policy. Both are avoidable.

Building a repeatable configuration review cadence

Quarterly is the right baseline for a full configuration review, and it matches how assessors and agencies already operate. The Cybersecurity and Infrastructure Security Agency's (CISA's) Binding Operational Directive 25-01 requires federal agencies to report Microsoft 365 secure-configuration assessment results quarterly.

A practical quarterly pass covers Conditional Access effectiveness and privileged role review, including conversion of permanent assignments to PIM-eligible. It should also cover consented apps with high-risk permission grants and a configuration diff against the prior quarter. Record every change in a documented change log.

Microsoft Secure Score belongs in that review as a directional signal only. Microsoft states plainly that "it isn't an absolute measurement of how likely your system or data could be breached" and that the recommendations don't cover every attack surface. Changes take 24–48 hours to reflect, and Microsoft separately tracks risk-acceptance trends. Treat a dropping score as a prompt to investigate and a rising score as a directional indicator.

Documentation makes the cadence repeatable across staff changes. For secure configurations, establish and maintain a secure configuration process, per Center for Internet Security (CIS) Controls Safeguard 4.1. Also record approved deviations from the baseline and a change log showing what moved since the last review. The National Institute of Standards and Technology (NIST) SP 800-171r3 additionally separates temporary deficiencies, tracked in a plan of action and milestones (POA&M), from enduring exceptions documented in the system security plan.

How Netwrix helps harden and monitor Microsoft 365

A current, centralized record of configuration state is what turns quarterly reviews and audit prep from manual reconstruction into a lookup. Netwrix Auditor records configuration and permission changes across Entra ID, SharePoint Online, and Active Directory with before-and-after values in a single, searchable audit trail, deployable in about 30 minutes

Flagler Bank, a Florida community bank with a one-person IT department, shortened its investigations by deploying Netwrix Auditor. What used to take hours now takes about 10 minutes, and the platform delivered usable value within 30 minutes of setup.

First National Bank and Trust of Beloit turned OCC audit preparation into a repeatable, evidence-backed process across its 17 locations. Group Policy changes, Structured Query Language (SQL) activity, and privileged access logs now come from a single platform in about an hour, work that used to take an entire week.

Keeping pace with a tenant that never stops changing

Microsoft security gaps reappear as administrators adjust policies, licenses reshape available controls, and exceptions outlive the systems they supported. A current configuration record helps teams investigate those changes and preserve the evidence needed for audits, rather than reconstructing it under a deadline.

Request a demo to see how Netwrix Auditor shows who changed a setting in your own Entra ID and SharePoint Online environment, and what it said before.

Microsoft 365 セキュリティ構成に関するよくある質問

共有する

もっと詳しく

著者について

Asset Not Found

Netwrix Team