Netwrix 1Secure는 데이터와 아이덴티티 전반에 걸쳐 통합된 가시성을 제공합니다 - 14일간 무료로 전체 액세스가 가능합니다.무료 평가판 시작

리소스 센터블로그

Microsoft 365 보안: 기본 설정을 넘어 테넌트를 강화하는 방법

Microsoft 365 보안: 기본 설정을 넘어 테넌트를 강화하는 방법

Oct 6, 2026

Microsoft 365 보안은 기본 설정이 열어둔 설정에 의존하므로, 플랫폼 자체가 안전하더라도 identity, 이메일, 공유 및 데이터 제어가 정책 요구사항보다 약해질 수 있습니다. 잘못 설정된 접근 규칙, 열린 협업 기본값, 짧은 로그 보존 기간 및 이후의 구성 변동은 데이터를 노출시키고 감사 증거를 약화시킬 수 있습니다. 이를 해결하려면 의도적인 tenant 강화, 문서화된 검토 및 구성 변경에 대한 지속적인 가시성이 필요합니다.

CoreView는 보고했습니다 지난 12개월 동안 45%의 대규모 조직이 Microsoft 365 잘못된 구성으로 인해 보안 또는 규정 준수 사고를 경험했다고 합니다. 160만 명의 Microsoft 365 사용자를 분석한 동일한 연구에서는 90%의 조직이 암호 정책 및 로그인 실패 모니터링과 같은 기본 보안 제어조차 시행하는 데 어려움을 겪는 것으로 나타났습니다.

이는 구성 실패이며, 구성은 고객 측에 해당하는 Microsoft의 공동 책임 모델에 속합니다. Microsoft는 데이터 센터, 하이퍼바이저 및 서비스 코드를 포함한 플랫폼 자체를 보호합니다. 테넌트 설정은 공유 기본값에서 MFA 정책 범위 지정에 이르기까지 고객의 책임이며, 이러한 기본값 중 많은 부분이 제한보다 협업을 선호합니다. 효과적인 강화는 신중한 구성, 문서화된 증거 및 시간이 지남에 따라 변화를 감지하는 검토 주기를 필요로 합니다.

기본 Microsoft 365 설정이 충분하지 않은 이유

Microsoft의 공유 책임 모델은 한 문장으로 요약됩니다: Microsoft는 인프라를 보호하고, 고객은 데이터, 계정, 엔드포인트 및 access management에 대한 책임을 유지합니다. SaaS에서도 마찬가지입니다.

Microsoft는 보안 기본값을 기본 제공하며 모든 신규 테넌트에 이를 활성화합니다. 보안 기본값은 모든 사용자에 대해 다단계 인증(MFA) 등록을 강제하고, 16개 관리자 역할에 대해 MFA를 요구하며, 레거시 인증 프로토콜을 차단하고, 2026년 7월 1일부터 신규 테넌트에서 디바이스 코드 흐름을 차단합니다. 이는 추가 구성 없이도 최대한의 보호를 제공하는 매우 유용한 기준선입니다.

Security Defaults는 중간 지점을 제공하지 않습니다: 켜거나 끄는 것뿐이며, break-glass 계정에 대한 제외, 장치 준수 또는 위치 조건, 위험 기반 정책, 그리고 just-in-time admin elevation이 없습니다. 또한 Conditional Access와 공존할 수 없으며, 하나를 활성화하면 다른 하나가 비활성화됩니다. 세밀한 제어와 예외가 필요한 조직은 Conditional Access를 사용해야 합니다.

같은 패턴이 전체 제품군에 반복됩니다. Standard 및 Strict 이메일 보호 사전 설정은 "아무에게도 할당되지 않습니다" 관리자가 할당할 때까지, 외부 공유는 기본적으로 켜져 있으며 관리자는 데이터 손실 방지(DLP) 정책을 생성해야 합니다.

Identity 및 액세스 구성

Identity는 대부분의 테넌트 침해가 시작되는 지점이며, Microsoft가 고객에게 가장 많은 구성을 맡기는 부분이기도 합니다. Identity 강화란 인증을 강화하고, 액세스 정책을 일관되게 적용하며, 상시 권한을 긴급 액세스에 실제로 필요한 수준으로 줄이는 것을 의미합니다.

MFA를 적용하고 레거시 인증을 제거하세요

특권 계정을 피싱 방지 MFA로 전환하고 레거시 인증이 모든 곳에서 차단되었는지 확인하세요. Microsoft의 authentication strengths는 Fast Identity Online 2(FIDO2) 인증 표준, Windows Hello for Business 및 인증서 기반 인증을 피싱 방지로 평가합니다; push notifications and time-based one-time password (TOTP) codes는 그렇지 않은데, 중간자 공격 도구가 이를 중계하기 때문입니다.

The Tycoon2FA kit은 한 달에 50만 개 이상의 조직에 도달했으며, Proofpoint의 2025년 광범위한 연구에 따르면 업계 전반에서 탈취된 계정의 59%가 MFA를 활성화한 것으로 나타났습니다. 레거시 측면에서 Microsoft의 데이터는 97% 이상의 자격 증명 채우기 공격이 레거시 인증을 사용한다고 보여줍니다. Microsoft는 모든 Exchange Online 테넌트에서 기본 인증을 비활성화했으며, Simple Mail Transfer Protocol 인증(SMTP AUTH)은 2026년 12월 말까지 남은 예외입니다.

Netwrix Auditor는 Entra ID의 변경 사항을 누가 언제 했는지, 변경 전후 값을 포함하여 추적하므로 롤백된 강화 설정도 기록을 남깁니다. 데모를 요청하세요.

조건부 액세스 정책 구성

장치 준수, 위치 및 위험을 기반으로 조건부 액세스를 구축하고 모든 정책을 시행 모드로 실행하세요. 견고한 Conditional Access 기반인 Entra ID P1에는 관리자용 MFA, 모든 사용자용 MFA, 레거시 인증 차단 및 준수 장치 요구 사항이 포함됩니다. 위험 기반 로그인 및 사용자 정책에는 Entra ID P2가 필요합니다.

Huntress는 분석한 78개의 침해 계정 중 55개가 MFA를 요구하는 활성 조건부 액세스 정책을 가지고 있었지만, 잘못된 범위 지정, 보고 전용 모드 또는 조건 불일치로 인해 정책이 실패했다고 발견했습니다. 이는 시행 모드가 결과를 결정하는 세부 사항임을 의미합니다. emergency access accounts를 이러한 정책에서 제외하여 오작동 시 긴급 관리 액세스가 가능하도록 하십시오.

관리자 역할 감사 및 관리

상시 Global Administrator 할당을 긴급 액세스 계정으로 줄이고 나머지는 모두 Privileged Identity Management (PIM)를 통해 처리하세요. Global Administrator 할당을 5명 미만으로 제한하세요; Microsoft 관리 센터에서 테넌트가 이 임계값을 초과하면 알림을 받습니다.

PIM 은 Entra ID P2가 필요합니다. PIM 배포는 비상 접근을 제외하고는 영구적으로 활성화된 할당이 없어야 하며, 활성화 기간은 1~24시간이고 최소 두 명의 승인자가 있어야 합니다. 두 가지 영구 예외는 클라우드 전용 브레이크 글래스 계정이 *.onmicrosoft.com 도메인에서 연합 및 동기화와 독립적으로 유지되어야 합니다.

이메일 및 협업 강화

Microsoft 365의 협업 영역은 이메일, SharePoint, OneDrive, Teams를 포함하며, 기본 설정은 제한보다 사용 편의성을 우선합니다. 이를 강화하려면 잘못된 구성으로 사고가 발생하기 전에 인증, 공유 권한, 사서함 규칙 가시성을 강화해야 합니다.

이메일 인증 및 피싱 방지

Publish Sender Policy Framework (SPF) with a hard fail, enable DomainKeys Identified Mail (DKIM) on every custom domain, and move Domain-based Message Authentication, Reporting, and Conformance (DMARC) to p=reject. The standard SPF record is v=spf1 include:spf.protection.outlook.com -all, with -all recommended once DKIM and DMARC are also in place. DMARC should progress from p=none through p=quarantine to p=reject.

수신 필터링도 동일한 주의가 필요합니다. 기본 안티 피싱 정책은 사칭 보호 및 피싱 임계값을 구성하지 않은 상태로 둡니다. Standard 사전 설정은 피싱 임계값을 레벨 3(“더 공격적”)으로 높이고 사칭 보호를 구성하며, Strict는 의심되는 메시지를 격리로 보냅니다.

Safe Links 및 Safe Attachments에는 Defender for Office 365가 필요합니다. Business Premium에 포함되어 있으며 E3에는 2026년 7월 1일부터 포함되어 있습니다. 내장된 Configuration Analyzer는 테넌트를 Standard 및 Strict 기준선과 비교하며 구성 변동 분석 탭을 포함합니다.

외부 공유 제어

사용자가 복구할 수 없는 링크를 생성하기 전에 SharePoint 및 OneDrive 공유를 강화하세요. Microsoft는 기본적으로 외부 공유를 활성화하고 환경 전체에 걸쳐 OneDrive의 기본 링크 유형을 "링크가 있는 모든 사용자"로 설정하며, 모든 사용자 링크가 Conditional Access 미관리 장치 정책을 완전히 우회하도록 허용합니다.

Set the organization level to guests only, change the default link type to specific people, and apply domain allow or block lists, which support up to 5,000 domains. Teams needs a parallel pass. Microsoft enables guest access, federation with all external domains, and anonymous meeting join by default. Restrict federation to trusted domains and set lobby bypass to people in your organization.

메일함 규칙 및 자동 전달 위생

테넌트 연령에 따라 표시되는 기본값이 달라질 수 있으므로 아웃바운드 자동 전달을 명시적으로 Off로 설정하세요. 기본값은 "자동 - 시스템 제어"로 표시되며, 2021년 이후 생성된 테넌트에는 Off로 작동하지만 이전 테넌트에는 On과 동일할 수 있으므로 값을 명시적으로 설정하세요 표시를 신뢰하지 말고.

다음 remote-domain 명령어로 병렬 경로를 닫으세요 Set-RemoteDomain -Identity Default -AutoForwardEnabled $false. 그런 다음 고위험 계정의 받은 편지함 규칙을 감사하세요. 사서함 감사 로그는 기본적으로 규칙 작업을 기록합니다.

Proofpoint 연구에 따르면 2025년 4분기에 침해된 계정의 약 10%가 접근 후 악성 사서함 규칙을 생성했으며, 가장 빠른 규칙 생성은 탈취 후 단 5초 만에 이루어졌습니다.

Data protection configuration

Microsoft 365 data protection doesn't happen automatically. Sensitivity labels, DLP policies, and audit log retention all depend on administrators actively configuring them, and the defaults leave sensitive content unlabeled and under-logged until someone does.

Sensitivity labels and DLP policies

Enable label processing for SharePoint and OneDrive first, because downstream controls depend on it. The label-processing prerequisite is Set-SPOTenant -EnableAIPIntegration $true; after administrators apply it, a label and its encryption remain with the file wherever users store it, including after download.

Container labels on Teams and SharePoint sites don't flow down to the items inside them, and auto-labeling requires E5-tier licensing. Plan around both before rollout.

To block downloads to unmanaged devices, Set-SPOTenant -ConditionalAccessPolicy AllowLimitedAccess enforces browser-only access with no download, print, or sync. Those session controls don't support the Teams desktop application. For DLP itself, deploy in simulation mode first, review matches, then move to enforcement.

Retention and audit log configuration

Extend audit log retention past the default before an investigation forces the issue. Audit (Standard) retains records for 180 days. Audit (Premium) on E5 extends Entra ID, Exchange, SharePoint, and OneDrive events to one year, with a separate add-on reaching ten years.

IBM reported the average breach lifecycle at 241 days, and the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 requires twelve months of audit log retention. Sophos found logs missing in 47% of incident cases it analyzed.

Entra ID sign-in logs run on a separate clock, with retention of just seven days on the free tier and 30 days on P1/P2.

The configuration drift problem

Huntress analyzed more than 12,000 tenants and found more than 50% of recommended controls missing in 60% of them, including environments that already used posture tooling. Microsoft's Secure Score history tracks regressions caused by configuration, user, or device changes.

Administrators roll back settings to unblock a project, exceptions accumulate as staff turns over, and each change looks reasonable in isolation. The Netwrix 2026 Data and Identity Security Report found that 76% of organizations don't immediately and automatically revoke access after users no longer need it. In the survey behind it, 66% said some or most privileged roles keep standing, always-on access.

CoreView reported that 38% of organizations detect configuration tampering through manual review alone and 17% have no detection method at all.

Mapping configuration to compliance evidence

Effective audit evidence must show both control design and operating effectiveness. Auditors across frameworks define design evidence as the configuration at a point in time. Operating-effectiveness evidence proves the control ran continuously, covered the full population, and handled exceptions.

The same Netwrix research found that 74% of organizations cannot get a single unified view of where sensitive data resides and which identities can access it. A Service Organization Control 2 (SOC 2) Type II report evaluates controls over six months or more.

Cybersecurity Maturity Model Certification (CMMC) assessors verify controls using three defined methods, described in assessment guidance as "examine, interview, and test." One NOT MET assessment objective fails the entire security requirement. Health Insurance Portability and Accountability Act (HIPAA) enforcement follows the same logic. The Office for Civil Rights' (OCR's) 2025 action against Warby Parker cited "a failure to implement procedures to regularly review records of information system activity" as a distinct violation, meaning logging that nobody reviews still fails.

The most common evidence failures are an MFA policy left in report-only mode when enforcement is required and drafts or other unofficial records standing in for written policy. Both are avoidable.

Building a repeatable configuration review cadence

Quarterly is the right baseline for a full configuration review, and it matches how assessors and agencies already operate. The Cybersecurity and Infrastructure Security Agency's (CISA's) Binding Operational Directive 25-01 requires federal agencies to report Microsoft 365 secure-configuration assessment results quarterly.

A practical quarterly pass covers Conditional Access effectiveness and privileged role review, including conversion of permanent assignments to PIM-eligible. It should also cover consented apps with high-risk permission grants and a configuration diff against the prior quarter. Record every change in a documented change log.

Microsoft Secure Score belongs in that review as a directional signal only. Microsoft states plainly that "it isn't an absolute measurement of how likely your system or data could be breached" and that the recommendations don't cover every attack surface. Changes take 24–48 hours to reflect, and Microsoft separately tracks risk-acceptance trends. Treat a dropping score as a prompt to investigate and a rising score as a directional indicator.

Documentation makes the cadence repeatable across staff changes. For secure configurations, establish and maintain a secure configuration process, per Center for Internet Security (CIS) Controls Safeguard 4.1. Also record approved deviations from the baseline and a change log showing what moved since the last review. The National Institute of Standards and Technology (NIST) SP 800-171r3 additionally separates temporary deficiencies, tracked in a plan of action and milestones (POA&M), from enduring exceptions documented in the system security plan.

How Netwrix helps harden and monitor Microsoft 365

A current, centralized record of configuration state is what turns quarterly reviews and audit prep from manual reconstruction into a lookup. Netwrix Auditor records configuration and permission changes across Entra ID, SharePoint Online, and Active Directory with before-and-after values in a single, searchable audit trail, deployable in about 30 minutes

Flagler Bank, a Florida community bank with a one-person IT department, shortened its investigations by deploying Netwrix Auditor. What used to take hours now takes about 10 minutes, and the platform delivered usable value within 30 minutes of setup.

First National Bank and Trust of Beloit turned OCC audit preparation into a repeatable, evidence-backed process across its 17 locations. Group Policy changes, Structured Query Language (SQL) activity, and privileged access logs now come from a single platform in about an hour, work that used to take an entire week.

Keeping pace with a tenant that never stops changing

Microsoft security gaps reappear as administrators adjust policies, licenses reshape available controls, and exceptions outlive the systems they supported. A current configuration record helps teams investigate those changes and preserve the evidence needed for audits, rather than reconstructing it under a deadline.

Request a demo to see how Netwrix Auditor shows who changed a setting in your own Entra ID and SharePoint Online environment, and what it said before.

Microsoft 365 보안 구성에 대한 자주 묻는 질문

공유하기

더 알아보기

저자 소개

Asset Not Found

Netwrix Team