Microsoft 365 Security Perth -- Beyond MFA Protection
A Perth accounting firm owner called me last month after discovering something alarming. Her staff were accessing client tax returns and financial records from personal laptops at home. No encryption. Some were shared family computers. One employee was checking emails on their teenager's phone.
All with full Microsoft 365 access, despite having MFA enabled.
"I thought we were protected," she said. "We've got the two-factor thing turned on."
MFA is essential, but it only verifies who is logging in. It doesn't control what they're logging in from or where they're doing it from. That's where most Perth businesses have a blind spot in their Microsoft 365 security setup.
Why MFA Alone Isn't Enough for Perth Business Data
Multi-factor authentication stops hackers who steal passwords. It doesn't stop legitimate users from accessing sensitive data on compromised or unmanaged devices.
Here's what I see regularly with Perth businesses:
Staff working from personal devices with no oversight. A Subiaco law firm discovered paralegals were downloading client contracts to personal laptops with no encryption. When one laptop was stolen from a car, every file on it was accessible to whoever found it.
Shared home computers accessing business systems. Employees letting family members use the same computer they access payroll and client data from. Kids downloading games and software that introduce malware risks.
Mobile devices without basic security. Staff checking business emails on phones with no lock screen, storing sensitive attachments that sync to personal cloud accounts.
Public Wi-Fi access to confidential data. Employees logging into Microsoft 365 from café Wi-Fi in Fremantle, airports, or co-working spaces where network traffic can be monitored.
The Australian Compliance Risk
Under Australia's Privacy Act, businesses must take reasonable steps to secure personal information. If client data is breached because staff accessed it from an unmanaged personal device, that's a compliance issue.
The Australian Cyber Security Centre's Essential Eight framework specifically addresses this with application control and restricting administrative privileges - controls that extend beyond basic MFA.
Device Management: What Perth Businesses Need to Control
Microsoft 365's device management capabilities let you control which devices can access your business data. This isn't about spying on staff - it's about protecting client information and business systems.
Device compliance requirements. Set minimum standards for any device accessing business data: encryption enabled, screen lock required, up-to-date operating system.
Application restrictions. Prevent business data from being copied to personal apps or cloud storage services on employee devices.
Remote wipe capabilities. If a device is lost or stolen, you can remotely remove all business data without touching personal files.
A Perth engineering firm implemented device compliance after an employee's personal laptop was infected with malware that started sending spam from their business email account. Now any device accessing their systems must meet security requirements or it's automatically blocked.
Conditional Access Policies for Perth Business Protection
Conditional Access policies act like smart bouncers for your Microsoft 365 environment. They evaluate each login attempt based on multiple factors and decide whether to allow access, block it, or require additional verification.
Location-Based Access Controls
IP address restrictions. Allow access only from your office, staff home addresses, or specific locations. Block login attempts from high-risk countries or locations you don't do business with.
Travel notifications. Automatically flag when someone tries to access business data from an unexpected location. Useful for detecting compromised accounts or ensuring staff notify you about business travel.
Device and Risk-Based Controls
Trusted device requirements. Require staff to register their work devices and block access from unregistered personal devices.
Risk-based authentication. Automatically require additional verification when login patterns seem suspicious - different device, unusual location, or multiple failed attempts.
Session controls. Limit what users can do based on their device or location. Staff on personal devices might only get read access to emails, not the ability to download attachments.
Application-Specific Restrictions
Some applications need stricter controls than others. A Perth medical practice might allow general email access from personal devices but require managed devices for accessing patient management systems.
Step-by-Step Microsoft 365 Security Hardening
1. Enable Advanced MFA Options
Move beyond basic SMS codes to app-based authentication or hardware tokens. SMS can be intercepted, especially on public mobile networks.
Configure MFA for all users, not just administrators. The receptionist's account can be just as valuable to attackers if it has access to client data.
2. Implement Conditional Access Policies
Start with location-based restrictions. Most Perth businesses can identify the locations where staff legitimately need access and block everything else.
Add device compliance requirements gradually. Begin with basic requirements like screen locks and current operating systems, then add encryption and application restrictions.
3. Configure Device Management
Enrol work devices in Microsoft Intune for full management. For personal devices used for work, implement app-based management that only controls business applications and data.
Set up automatic device compliance checking. Non-compliant devices should be blocked from accessing business data until they meet your requirements.
4. Monitor and Respond to Threats
Enable Microsoft Defender for Office 365 to detect suspicious activity and potential compromises. Configure alerts for unusual login patterns, mass file downloads, or access from new locations.
Review security reports monthly. Look for patterns in blocked access attempts, compliance violations, or risky user behaviour that might indicate training needs.
Getting Microsoft 365 Security Right in Perth
Your Microsoft 365 security needs to match how Perth businesses actually work. Staff working from home, using personal devices, accessing data from various locations. The security controls should make business easier, not harder.
Start with the biggest risks first. If staff are accessing sensitive client data from unmanaged personal devices, implement device compliance requirements. If you're seeing login attempts from suspicious locations, add geographical restrictions.
Don't try to implement everything at once. Roll out new security controls gradually and train staff on why these protections matter for client confidentiality and business continuity.

