On-Demand
This event is part of a learning series brought to you by the Microsoft 365 Community Conference. Join us in Orlando, April 21–23, 2026. Use code SAVE150 to save $150.
Today’s threats go far beyond email phishing. Attackers actively target Teams, SharePoint, Exchange, Entra ID, and app permissions, using a series of calculated steps to gain access, elevate privileges, and quietly persist inside your tenant.
In this session, Microsoft security expert Rob Edmondson breaks down the anatomy of a real-world Microsoft 365 attack, drawing on incidents like Microsoft’s Midnight Blizzard breach. You’ll see how attackers move through a tenant, where security gaps commonly go unnoticed, and why configuration drift often creates long-term exposure.
Rob will close with practical governance and security actions organizations are implementing today to reduce risk, detect issues earlier, and respond faster across their Microsoft 365 environment.
How attackers really move through Microsoft 365
The common path from reconnaissance → entry (password spray, phishing, OAuth abuse) → privilege elevation → persistence → data exfiltration or ransomware.
The “quiet” risks defenders often miss
Exposed Teams and SharePoint surfaces, risky external sharing, excessive Entra app permissions, and dangerous configuration drift.
How to harden your tenant’s entry points
A practical checklist covering MFA everywhere, Conditional Access, legacy authentication blocking, Safe Links, baseline DLP, and tighter app consent controls.
How to detect persistence before damage is done
What to monitor for early warning signs—risky configuration changes, new OAuth apps, mailbox auto-forwarding, audit log tampering—and why configuration change management is critical.
Rob Edmondson is the Senior Director of Product Marketing at CoreView, with deep expertise spanning email security, privileged access management, DevOps, and identity security. With over a decade of experience working across Microsoft 365, DevOps, and SaaS security platforms, Rob brings a practitioner’s perspective to solving real-world challenges faced by Fortune 1,000 IT and security teams. He is widely recognized for translating complex security concepts into actionable guidance organizations can apply immediately.