Email is still how they get in. Microsoft ships sensible defaults and most tenants never touch them again. Answer four questions, then work the belts: three DNS records you can fix this afternoon, the protections you already own and haven't switched on, and the Defender controls you're paying for. Every control comes with the attack it stops, the MITRE ATT&CK techniques behind it, and the exact clicks. Walk out with a deployment plan.
Read this first — email breaks loudly and in public
Conditional Access locks you out of your own tenant. Email security is worse in one specific way: when you get it wrong, your customers find out before you do, because your invoices stop arriving. The order below isn't advice, it's the whole method.
- SPF and DKIM before DMARC. DMARC checks alignment between them. Enforce it before they're right and you'll reject your own mail.
- p=none, then p=quarantine, then p=reject. Never skip a step, however confident you feel about your sender list. You are not confident, you just haven't seen the reports yet.
- Two weeks between steps, reading the reports. A change nobody's measuring is a change you can't evaluate.
- Lowest-volume domain first. Your main domain last.
- Presets over hand-built policies. Microsoft keeps preset security policies current as attacks change. Your custom policy is frozen on the day you made it, and it drifts below the baseline in silence.
Full guidance: Set up DMARC to validate the From address domain ↗
Size up your environment
Four quick questions. The dojo tailors the control set to what you actually run — and tells you honestly when something isn't for you. If you've been through another dojo, your licence mix is already filled in.
Which licences do you have in the tenant? Select all that apply.
Do you have Defender for Office 365?
Asked, not guessed: Microsoft's docs disagree on whether E3 includes Plan 1 (announced, not shipped). Business Premium and E5/A5/G5 do. Check yours ↗. Not sure counts as no.
How does mail reach Microsoft?
Own domains you never send mail from?
Walk out with a plan
Your deployment plan lists every in-scope control with its status, MITRE references
and Microsoft Learn source. The PowerShell script contains the DNS records to publish
and the Exchange Online checks for your in-scope controls, in belt order — with every
Get- ready to run and every Set- left for you to run
deliberately, because that's how professionals roll out something that can bounce
their own invoices.