Business email compromise is one of the biggest threats to Microsoft 365 tenants—and most environments are more exposed than they think. Nathan Taylor unpacks how these attacks work, where the real gaps are, and how to fix them fast. From MFA to email and identity protection, get a 7 step approach to locking down your tenant.
Business email compromise isn’t going away—Nathan Taylor continues the conversation with a focus on how organizations can actually secure their Microsoft 365 environments.
Most security issues come from gaps in configuration and inconsistent enforcement of basic controls. Nathan walks through how to approach tenant hardening step by step, starting with understanding your current environment through an assessment.
From there, he breaks down how to prioritize high-impact changes. The focus stays on identity and access, where MFA and conditional access policies play a central role. He explains why identity has become the primary security boundary and how small misconfigurations can create entry points for attackers.
The episode also covers email security, including DMARC, SPF, and phishing protection, before moving into risks like dormant accounts and unmanaged applications. As the conversation progresses, Nathan touches on more advanced threats like token theft and how approaches like FIDO2 authentication and compliant device policies help reduce exposure.
What You’ll Learn:
- How to identify and prioritize Microsoft 365 security gaps
- Why MFA and identity protection are the foundation of tenant security
- How email security settings impact phishing and spoofing risk
- What risks dormant accounts and unused devices create
- How FIDO2 authentication helps defend against advanced attacks
- Why security needs to be approached as an ongoing process
About the Speaker:
Nathan Taylor is Senior Vice President and Global Microsoft Practice Leader at Sourcepass, where he leads the Sourcepass Center of Excellence for Microsoft, also known as the Sourcepass MCOE. With nearly two decades of experience, he helps organizations navigate complex Microsoft cloud and security decisions by turning technology into secure, scalable outcomes.
Episode Highlights:
[00:05:30] Starting with an Assessment
The first step in securing a tenant is understanding what exists today. Nathan explains how running an assessment helps identify gaps and focus on improvements that reduce risk quickly without overwhelming teams or disrupting users.
[00:12:40] Why Identity is the New Security Boundary
Security has shifted from network perimeters to user identity. This section explores why MFA, conditional access, and authentication methods are now the most critical controls for preventing unauthorized access.
[00:20:15] Dormant Accounts as a Risk Factor
Unused accounts often go unnoticed but remain accessible. These accounts are typically not secured with MFA and can be exploited through password resets or social engineering, making them a common entry point for attackers.
[00:27:10] Strengthening Email Security Controls
Email continues to be the primary attack vector. Nathan outlines how DMARC, SPF, and Defender policies help reduce phishing and spoofing risks and why many tenants are still misconfigured.
[00:31:20] Defending Against Token-Based Attacks
More advanced attacks target authentication tokens instead of credentials. This section explains how FIDO2 authentication and device-based policies make it harder for attackers to gain persistent access.
Episode Resources: