All Resources
Microsoft 365

How to Secure Microsoft 365 Against Business Email Compromise

Business email compromise (BEC) is not the same problem as generic phishing, and it deserves a different playbook. Where our [guide to securing email from phishing](/resources/secure-business-email-from-phishing) covers stopping malicious clicks and credential theft broadly, this article focuses specifically on the financial fraud that follows once an attacker has a foothold, or has simply convinced someone to move money.

Published August 9, 2026 Updated August 9, 2026 10 min read By Joshua Arimoro Greater Sudbury & Ontario
The short answer

Business email compromise uses compromised or impersonated mailboxes to redirect payroll deposits, submit fraudulent invoices, or impersonate vendors and executives to trigger wire transfers. It is best stopped with phishing-resistant MFA, Conditional Access, Defender impersonation protection, mailbox audit logging with inbox rule alerts, and a mandatory verbal verification step for any banking or payment detail change. According to the Canadian Centre for Cyber Security, fraud schemes like this remain among the most financially damaging forms of cybercrime affecting Canadian organizations.

How business email compromise actually works

Payroll diversion

An attacker, often posing as an employee, emails HR or payroll asking to update direct deposit banking details. If accepted without verbal verification, the next pay run goes to the attacker's account instead of the employee's.

Invoice fraud

Attackers monitor or spoof a vendor's communications, then send a fraudulent invoice or a note that "our banking details have changed" right before a legitimate payment is due.

Vendor and executive impersonation

A message appears to come from a known supplier or from the CEO, often with urgency and a request to keep it confidential, pressuring the recipient to act before verifying.

Malicious inbox rules

Once an attacker has a mailbox, they frequently create a hidden rule that forwards or deletes messages containing words like "invoice," "wire," or "password," letting them monitor and intercept financial conversations without the real owner noticing.

Token theft

Modern BEC increasingly bypasses passwords entirely through adversary-in-the-middle phishing kits that steal session tokens, letting an attacker into a mailbox even when MFA was used at sign-in. Microsoft Learn documents this technique and the Conditional Access and token protection features designed to counter it.

Layered controls that stop BEC

Controls mapped to the BEC technique they address
ControlWhat it stopsWhere it lives
Phishing-resistant MFA (FIDO2 or certificate-based)Credential theft and simple token replayMicrosoft Entra ID
Conditional Access with sign-in risk policiesSign-ins from unfamiliar locations or risky sessionsMicrosoft Entra ID P1, included in Business Premium
Defender for Office 365 impersonation protectionExecutive and vendor domain impersonationMicrosoft Defender for Office 365
Mailbox audit loggingDetects hidden forwarding and inbox rules after the factExchange Online
Automated inbox rule alertsFlags new forwarding or deletion rules the moment they're createdDefender / Exchange Online alert policies
Mandatory verbal verification for banking changesPayroll diversion and vendor bank-detail fraudInternal finance process, not a Microsoft setting
Security awareness trainingReduces the chance urgency-based requests succeedOngoing staff training program

Phishing-resistant MFA and Conditional Access

SMS and app-based push MFA stop the majority of attacks but can still be defeated by adversary-in-the-middle phishing kits. Phishing-resistant methods such as FIDO2 security keys or certificate-based authentication remove the shared secret an attacker could intercept. Pair this with Conditional Access policies that require a compliant device for access to finance systems, as described in our Microsoft 365 security best practices guide.

Worried about email fraud reaching your finance team?

We configure impersonation protection, mailbox alerting, and phishing-resistant MFA specifically to close the gaps BEC attackers rely on.

Request a BEC Risk Review

Impersonation protection and mailbox auditing

  • Configure Defender for Office 365 to name-protect your executives and finance staff so lookalike display names are flagged
  • Add key vendors and partners to a protected senders list where repeated fraud attempts have occurred
  • Enable mailbox audit logging tenant-wide so forwarding rules and mass mail actions are recoverable evidence
  • Set an alert policy that fires immediately when a new forwarding or deletion rule is created in any mailbox

The banking-change verification process

This is the single control that stops the most financially damaging BEC scenarios, and it costs nothing to implement, it just requires discipline. Any request to change banking details for payroll or a vendor payment must be verified by phone, using a number already on file, never a number provided in the email itself.

  1. Flag the request and do not action it immediately.
  2. Call the employee or vendor using a previously known phone number, not one in the email.
  3. Confirm the change verbally before updating any payment system.
  4. Document the verification in writing before processing the change.
  5. If verification fails or the contact cannot be reached, escalate to management before proceeding.

Security awareness training for BEC specifically

General phishing training teaches staff to spot suspicious links. BEC training needs to go further, teaching finance and HR staff specifically to recognize urgency, secrecy requests, and last-minute banking changes as red flags regardless of how legitimate the sender appears. Our security awareness training programs include BEC-specific scenarios for finance and payroll teams.

Incident response if BEC is suspected

  1. Do not process any pending payment or banking change until the request is independently verified.
  2. Reset the password and revoke all active sessions for the affected mailbox immediately.
  3. Review mailbox audit logs for forwarding rules, mass deletions, or unusual sent items.
  4. Check sign-in logs for unfamiliar locations or impossible travel patterns.
  5. Notify your bank immediately if funds have already been transferred, since recall windows are short.
  6. Notify affected vendors or employees whose data may have been exposed.
  7. Report the incident to the Canadian Anti-Fraud Centre and consider notification obligations under applicable privacy law.
  8. Document the full timeline for your cyber insurance provider and involve your MSP or IT provider from the first step.

Sources and further reading

Frequently asked questions

What is the difference between phishing and business email compromise?

Phishing is typically the delivery method, while business email compromise is the financial fraud outcome, whether achieved through a compromised mailbox, a spoofed domain, or a convincing impersonation with no compromise at all.

Can MFA alone stop business email compromise?

No. MFA stops many account takeovers, but BEC also happens through pure impersonation with no compromised account involved, which is why the banking verification process matters just as much.

How do attackers hide inbox rules from the account owner?

Attackers typically create rules through webmail that move or delete messages containing specific keywords, and these rules are often not visible in the desktop Outlook rules list, which is why mailbox audit logging matters.

What should we do if we already paid a fraudulent invoice?

Contact your bank immediately, since wire recall windows are short, then report the incident to the Canadian Anti-Fraud Centre and notify your IT provider to check for related mailbox compromise.

Is Defender for Office 365 required to stop BEC?

It is not strictly required, but its impersonation protection and Safe Links features materially reduce risk, and it is included in Microsoft 365 Business Premium.

About the author

Joshua Arimoro

Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.

More about our team

Close the gaps that lead to email fraud

We implement phishing-resistant MFA, impersonation protection, mailbox alerting, and a documented verification process to protect your finance team from business email compromise.

Technologies mentioned in this article

See what we support around each platform on our supported technologies hub.

Keep exploring

Related services, locations, and resources

Related services

Related resources