# Securing Microsoft 365

**How do I secure Microsoft 365?**

For many businesses Microsoft 365 is the most important gateway to email and files. Whoever takes over that account reads along, writes in your name and reaches your documents. Securing it therefore starts with the accounts.

The first step is two factor authentication for every account, without exception. Management accounts in particular are often exempted because it is inconvenient. Those are precisely the accounts being targeted.

The second step concerns administrator rights. An account used to read email every day should not carry administrator rights. Separate the administrative account from the working account.

The third step is traceability. Switch on logging and check whether forwarding rules have been set up in the mailbox. An inconspicuous rule that copies incoming invoices to an outside address is a common way to redirect payments.

## Related terms
- [Cloud security](https://vetosec.at/en/it-security/cloud-sicherheit/)
- [Two-factor authentication (2FA)](https://vetosec.at/en/it-security/zwei-faktor-authentifizierung/)
- [Phishing](https://vetosec.at/en/it-security/phishing/)
- [SPF, DKIM and DMARC](https://vetosec.at/en/it-security/spf-dkim-dmarc/)

## Source
https://vetosec.at/en/it-security/microsoft-365-sicherheit/ (vetosec, schutz)
