Netwrix 1Secure 提供跨数据和身份的统一可见性——免费试用14天,享有完全访问权限。开始免费试用

资源中心博客

Microsoft 365 安全性:如何强化您的租户,超越默认设置

Microsoft 365 安全性:如何强化您的租户,超越默认设置

Oct 6, 2026

Microsoft 365 的安全性依赖于默认设置留下的开放项,因此即使平台本身安全,identity、电子邮件、共享和数据控制也可能比策略要求的更弱。错误范围的访问规则、开放的协作默认设置、较短的日志保留窗口以及后续的配置漂移可能暴露数据并削弱审计证据。修复这些问题需要有意的 tenant 加固、文档化的审查以及对配置更改的持续可见性。

CoreView 报告称 过去12个月中,45%的大型组织经历了由 Microsoft 365 配置错误引起的安全或合规事件。 同一项基于对160万 Microsoft 365 用户分析的研究发现,90%的组织难以执行甚至基本的安全控制,包括 密码策略 和失败登录监控。

这些是配置失败,配置属于客户方面,这是Microsoft的共享责任模型的一部分。Microsoft保护平台本身,包括数据中心、虚拟机监控程序和服务代码。租户设置,从共享默认值到MFA策略范围,仍由客户负责,且许多默认设置更倾向于协作而非限制。有效的强化需要有意的配置、书面证据以及能够随着时间发现偏差的审查节奏。

为什么默认的 Microsoft 365 设置不够

微软的共享责任模型可以用一句话概括:微软负责保护基础设施,而客户则负责数据、账户、端点和access management,即使是在SaaS中也是如此。

Microsoft 提供了 安全默认设置,开箱即用,并在所有新租户上启用。安全默认设置强制所有用户注册多因素身份验证(MFA),要求16个管理员角色使用MFA,阻止传统身份验证协议,并且从2026年7月1日起,阻止新租户上的设备代码流。这是真正有用的基线,是无需额外配置即可获得的最大保护。

Security Defaults 没有中间选项:它们要么开启,要么关闭,不为 break-glass 账户提供例外,也没有设备合规性或位置条件,没有基于风险的策略,也没有 just-in-time admin elevation。它们也无法与 Conditional Access 共存;启用一个会禁用另一个。需要细粒度控制和例外的组织应使用 Conditional Access。

相同的模式在整个套件中重复。Standard 和 Strict 邮件保护预设 “未分配给任何人”,直到管理员分配它们,外部共享默认开启,管理员必须创建 数据丢失防护(DLP)策略。

Identity 和访问配置

Identity是大多数租户被攻破的起点,也是Microsoft将最多配置留给客户的地方。强化Identity意味着加强身份验证、一致执行访问策略,并将常驻权限削减到紧急访问实际所需的程度。

强制执行 MFA 并消除传统身份验证

将特权账户迁移到抗钓鱼MFA,并确认旧版身份验证在所有地方均被阻止。微软的authentication strengths将Fast Identity Online 2 (FIDO2)认证标准、Windows Hello for Business和基于证书的认证评为抗钓鱼;push notifications and time-based one-time password (TOTP) codes则不被认为是,因为中间人攻击工具会中继它们。

The Tycoon2FA kit每月覆盖超过50万个组织,Proofpoint 2025年更广泛的研究发现行业范围内被接管的账户中有59%启用了MFA。在传统认证方面,微软的数据表明超过97%的凭证填充攻击使用传统认证。微软已在所有Exchange Online租户中禁用基本认证,Simple Mail Transfer Protocol认证(SMTP AUTH)将是唯一的例外,直到2026年12月底。

Netwrix Auditor跟踪Entra ID中的更改,包括谁进行了更改、何时更改以及更改前后的值,因此被回滚的强化设置会留下记录。请求演示。

配置条件访问策略

围绕设备合规性、位置和风险构建条件访问,并以强制执行模式运行每项策略。坚实的Conditional Access基础在Entra ID P1中包括管理员多因素认证(MFA)、所有用户MFA、阻止传统身份验证和要求合规设备;基于风险的登录和用户策略需要Entra ID P2。

Huntress发现其分析的78个被攻破账户中有55个启用了需要MFA的条件访问策略,但由于范围设置错误、仅报告模式或条件不匹配,策略仍然失败。这使得执行模式成为决定结果的关键。请将您的emergency access accounts排除在这些策略之外,以确保误触发时紧急管理访问仍可用。

审核和管理管理员角色

将常设的Global Administrator分配减少到您的紧急访问账户,其他所有操作通过Privileged Identity Management(PIM)进行。将Global Administrator分配限制为少于五个;一旦租户超过该阈值,微软管理中心会提醒您。

PIM 需要 Entra ID P2。PIM 部署 应该在紧急访问之外没有永久激活的分配,激活窗口为1至24小时,且至少有两名审批人。两个永久例外应为 仅限云的断路账户,位于 *.onmicrosoft.com 域中,且保持独立于联合和同步。

电子邮件和协作加固

Microsoft 365 的协作平台涵盖电子邮件、SharePoint、OneDrive 和 Teams,默认设置偏向于易用性而非限制。加强安全意味着在配置错误成为事件之前,收紧身份验证、共享权限和邮箱规则的可见性。

电子邮件认证和反钓鱼

Publish Sender Policy Framework (SPF) with a hard fail, enable DomainKeys Identified Mail (DKIM) on every custom domain, and move Domain-based Message Authentication, Reporting, and Conformance (DMARC) to p=reject. The standard SPF record is v=spf1 include:spf.protection.outlook.com -all, with -all recommended once DKIM and DMARC are also in place. DMARC should progress from p=none through p=quarantine to p=reject.

入站过滤需要同等关注,因为默认的反钓鱼策略未配置身份冒充保护和钓鱼阈值。标准预设将钓鱼阈值提高到3级(“更积极”)并配置身份冒充保护,而严格模式则将可疑邮件发送到隔离区。

Safe Links 和 Safe Attachments 需要 Defender for Office 365。Business Premium 包含此功能,E3 自 2026年7月1日起包含。内置的 Configuration Analyzer 会将您的租户与 Standard 和 Strict 基线进行比较,并包含配置漂移分析标签页。

外部共享控制

在用户生成无法撤销的链接之前,收紧 SharePoint 和 OneDrive 的共享。Microsoft 默认启用外部共享,在整个环境中将 OneDrive 的默认链接类型设置为“拥有链接的任何人”,并允许任何人链接 完全绕过 Conditional Access 未管理设备策略。

Set the organization level to guests only, change the default link type to specific people, and apply domain allow or block lists, which support up to 5,000 domains. Teams needs a parallel pass. Microsoft enables guest access, federation with all external domains, and anonymous meeting join by default. Restrict federation to trusted domains and set lobby bypass to people in your organization.

邮箱规则和自动转发管理

请明确将出站自动转发设置为关闭,因为显示的默认值可能因租户年龄而异。默认值显示为“自动 - 系统控制”,对于2021年以后创建的租户,该值表现为关闭,但对于较旧的租户可能仍相当于开启,因此请明确设置该值,不要仅信赖显示。

使用 remote-domain 命令 关闭并行路径 Set-RemoteDomain -Identity Default -AutoForwardEnabled $false。然后审核高风险账户的收件箱规则。 邮箱审计默认记录规则操作。

Proofpoint的研究发现,2025年第四季度大约10%的被攻破账户在访问后创建了恶意邮箱规则,观察到的最快规则创建时间仅为接管后5秒。

Data protection configuration

Microsoft 365 data protection doesn't happen automatically. Sensitivity labels, DLP policies, and audit log retention all depend on administrators actively configuring them, and the defaults leave sensitive content unlabeled and under-logged until someone does.

Sensitivity labels and DLP policies

Enable label processing for SharePoint and OneDrive first, because downstream controls depend on it. The label-processing prerequisite is Set-SPOTenant -EnableAIPIntegration $true; after administrators apply it, a label and its encryption remain with the file wherever users store it, including after download.

Container labels on Teams and SharePoint sites don't flow down to the items inside them, and auto-labeling requires E5-tier licensing. Plan around both before rollout.

To block downloads to unmanaged devices, Set-SPOTenant -ConditionalAccessPolicy AllowLimitedAccess enforces browser-only access with no download, print, or sync. Those session controls don't support the Teams desktop application. For DLP itself, deploy in simulation mode first, review matches, then move to enforcement.

Retention and audit log configuration

Extend audit log retention past the default before an investigation forces the issue. Audit (Standard) retains records for 180 days. Audit (Premium) on E5 extends Entra ID, Exchange, SharePoint, and OneDrive events to one year, with a separate add-on reaching ten years.

IBM reported the average breach lifecycle at 241 days, and the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 requires twelve months of audit log retention. Sophos found logs missing in 47% of incident cases it analyzed.

Entra ID sign-in logs run on a separate clock, with retention of just seven days on the free tier and 30 days on P1/P2.

The configuration drift problem

Huntress analyzed more than 12,000 tenants and found more than 50% of recommended controls missing in 60% of them, including environments that already used posture tooling. Microsoft's Secure Score history tracks regressions caused by configuration, user, or device changes.

Administrators roll back settings to unblock a project, exceptions accumulate as staff turns over, and each change looks reasonable in isolation. The Netwrix 2026 Data and Identity Security Report found that 76% of organizations don't immediately and automatically revoke access after users no longer need it. In the survey behind it, 66% said some or most privileged roles keep standing, always-on access.

CoreView reported that 38% of organizations detect configuration tampering through manual review alone and 17% have no detection method at all.

Mapping configuration to compliance evidence

Effective audit evidence must show both control design and operating effectiveness. Auditors across frameworks define design evidence as the configuration at a point in time. Operating-effectiveness evidence proves the control ran continuously, covered the full population, and handled exceptions.

The same Netwrix research found that 74% of organizations cannot get a single unified view of where sensitive data resides and which identities can access it. A Service Organization Control 2 (SOC 2) Type II report evaluates controls over six months or more.

Cybersecurity Maturity Model Certification (CMMC) assessors verify controls using three defined methods, described in assessment guidance as "examine, interview, and test." One NOT MET assessment objective fails the entire security requirement. Health Insurance Portability and Accountability Act (HIPAA) enforcement follows the same logic. The Office for Civil Rights' (OCR's) 2025 action against Warby Parker cited "a failure to implement procedures to regularly review records of information system activity" as a distinct violation, meaning logging that nobody reviews still fails.

The most common evidence failures are an MFA policy left in report-only mode when enforcement is required and drafts or other unofficial records standing in for written policy. Both are avoidable.

Building a repeatable configuration review cadence

Quarterly is the right baseline for a full configuration review, and it matches how assessors and agencies already operate. The Cybersecurity and Infrastructure Security Agency's (CISA's) Binding Operational Directive 25-01 requires federal agencies to report Microsoft 365 secure-configuration assessment results quarterly.

A practical quarterly pass covers Conditional Access effectiveness and privileged role review, including conversion of permanent assignments to PIM-eligible. It should also cover consented apps with high-risk permission grants and a configuration diff against the prior quarter. Record every change in a documented change log.

Microsoft Secure Score belongs in that review as a directional signal only. Microsoft states plainly that "it isn't an absolute measurement of how likely your system or data could be breached" and that the recommendations don't cover every attack surface. Changes take 24–48 hours to reflect, and Microsoft separately tracks risk-acceptance trends. Treat a dropping score as a prompt to investigate and a rising score as a directional indicator.

Documentation makes the cadence repeatable across staff changes. For secure configurations, establish and maintain a secure configuration process, per Center for Internet Security (CIS) Controls Safeguard 4.1. Also record approved deviations from the baseline and a change log showing what moved since the last review. The National Institute of Standards and Technology (NIST) SP 800-171r3 additionally separates temporary deficiencies, tracked in a plan of action and milestones (POA&M), from enduring exceptions documented in the system security plan.

How Netwrix helps harden and monitor Microsoft 365

A current, centralized record of configuration state is what turns quarterly reviews and audit prep from manual reconstruction into a lookup. Netwrix Auditor records configuration and permission changes across Entra ID, SharePoint Online, and Active Directory with before-and-after values in a single, searchable audit trail, deployable in about 30 minutes

Flagler Bank, a Florida community bank with a one-person IT department, shortened its investigations by deploying Netwrix Auditor. What used to take hours now takes about 10 minutes, and the platform delivered usable value within 30 minutes of setup.

First National Bank and Trust of Beloit turned OCC audit preparation into a repeatable, evidence-backed process across its 17 locations. Group Policy changes, Structured Query Language (SQL) activity, and privileged access logs now come from a single platform in about an hour, work that used to take an entire week.

Keeping pace with a tenant that never stops changing

Microsoft security gaps reappear as administrators adjust policies, licenses reshape available controls, and exceptions outlive the systems they supported. A current configuration record helps teams investigate those changes and preserve the evidence needed for audits, rather than reconstructing it under a deadline.

Request a demo to see how Netwrix Auditor shows who changed a setting in your own Entra ID and SharePoint Online environment, and what it said before.

关于 Microsoft 365 安全配置的常见问题

分享到

了解更多

关于作者

Asset Not Found

Netwrix Team