How to Secure Microsoft 365 Against Business Email Compromise
Business email compromise (BEC) is not the same problem as generic phishing, and it deserves a different playbook. Where our [guide to securing email from phishing](/resources/secure-business-email-from-phishing) covers stopping malicious clicks and credential theft broadly, this article focuses specifically on the financial fraud that follows once an attacker has a foothold, or has simply convinced someone to move money.
Business email compromise uses compromised or impersonated mailboxes to redirect payroll deposits, submit fraudulent invoices, or impersonate vendors and executives to trigger wire transfers. It is best stopped with phishing-resistant MFA, Conditional Access, Defender impersonation protection, mailbox audit logging with inbox rule alerts, and a mandatory verbal verification step for any banking or payment detail change. According to the Canadian Centre for Cyber Security, fraud schemes like this remain among the most financially damaging forms of cybercrime affecting Canadian organizations.
How business email compromise actually works
Payroll diversion
An attacker, often posing as an employee, emails HR or payroll asking to update direct deposit banking details. If accepted without verbal verification, the next pay run goes to the attacker's account instead of the employee's.
Invoice fraud
Attackers monitor or spoof a vendor's communications, then send a fraudulent invoice or a note that "our banking details have changed" right before a legitimate payment is due.
Vendor and executive impersonation
A message appears to come from a known supplier or from the CEO, often with urgency and a request to keep it confidential, pressuring the recipient to act before verifying.
Malicious inbox rules
Once an attacker has a mailbox, they frequently create a hidden rule that forwards or deletes messages containing words like "invoice," "wire," or "password," letting them monitor and intercept financial conversations without the real owner noticing.
Token theft
Modern BEC increasingly bypasses passwords entirely through adversary-in-the-middle phishing kits that steal session tokens, letting an attacker into a mailbox even when MFA was used at sign-in. Microsoft Learn documents this technique and the Conditional Access and token protection features designed to counter it.
Layered controls that stop BEC
| Control | What it stops | Where it lives |
|---|---|---|
| Phishing-resistant MFA (FIDO2 or certificate-based) | Credential theft and simple token replay | Microsoft Entra ID |
| Conditional Access with sign-in risk policies | Sign-ins from unfamiliar locations or risky sessions | Microsoft Entra ID P1, included in Business Premium |
| Defender for Office 365 impersonation protection | Executive and vendor domain impersonation | Microsoft Defender for Office 365 |
| Mailbox audit logging | Detects hidden forwarding and inbox rules after the fact | Exchange Online |
| Automated inbox rule alerts | Flags new forwarding or deletion rules the moment they're created | Defender / Exchange Online alert policies |
| Mandatory verbal verification for banking changes | Payroll diversion and vendor bank-detail fraud | Internal finance process, not a Microsoft setting |
| Security awareness training | Reduces the chance urgency-based requests succeed | Ongoing staff training program |
Phishing-resistant MFA and Conditional Access
SMS and app-based push MFA stop the majority of attacks but can still be defeated by adversary-in-the-middle phishing kits. Phishing-resistant methods such as FIDO2 security keys or certificate-based authentication remove the shared secret an attacker could intercept. Pair this with Conditional Access policies that require a compliant device for access to finance systems, as described in our Microsoft 365 security best practices guide.
Worried about email fraud reaching your finance team?
We configure impersonation protection, mailbox alerting, and phishing-resistant MFA specifically to close the gaps BEC attackers rely on.
Request a BEC Risk ReviewImpersonation protection and mailbox auditing
- Configure Defender for Office 365 to name-protect your executives and finance staff so lookalike display names are flagged
- Add key vendors and partners to a protected senders list where repeated fraud attempts have occurred
- Enable mailbox audit logging tenant-wide so forwarding rules and mass mail actions are recoverable evidence
- Set an alert policy that fires immediately when a new forwarding or deletion rule is created in any mailbox
The banking-change verification process
This is the single control that stops the most financially damaging BEC scenarios, and it costs nothing to implement, it just requires discipline. Any request to change banking details for payroll or a vendor payment must be verified by phone, using a number already on file, never a number provided in the email itself.
- Flag the request and do not action it immediately.
- Call the employee or vendor using a previously known phone number, not one in the email.
- Confirm the change verbally before updating any payment system.
- Document the verification in writing before processing the change.
- If verification fails or the contact cannot be reached, escalate to management before proceeding.
Security awareness training for BEC specifically
General phishing training teaches staff to spot suspicious links. BEC training needs to go further, teaching finance and HR staff specifically to recognize urgency, secrecy requests, and last-minute banking changes as red flags regardless of how legitimate the sender appears. Our security awareness training programs include BEC-specific scenarios for finance and payroll teams.
Incident response if BEC is suspected
- Do not process any pending payment or banking change until the request is independently verified.
- Reset the password and revoke all active sessions for the affected mailbox immediately.
- Review mailbox audit logs for forwarding rules, mass deletions, or unusual sent items.
- Check sign-in logs for unfamiliar locations or impossible travel patterns.
- Notify your bank immediately if funds have already been transferred, since recall windows are short.
- Notify affected vendors or employees whose data may have been exposed.
- Report the incident to the Canadian Anti-Fraud Centre and consider notification obligations under applicable privacy law.
- Document the full timeline for your cyber insurance provider and involve your MSP or IT provider from the first step.
Sources and further reading
Frequently asked questions
What is the difference between phishing and business email compromise?
Phishing is typically the delivery method, while business email compromise is the financial fraud outcome, whether achieved through a compromised mailbox, a spoofed domain, or a convincing impersonation with no compromise at all.
Can MFA alone stop business email compromise?
No. MFA stops many account takeovers, but BEC also happens through pure impersonation with no compromised account involved, which is why the banking verification process matters just as much.
How do attackers hide inbox rules from the account owner?
Attackers typically create rules through webmail that move or delete messages containing specific keywords, and these rules are often not visible in the desktop Outlook rules list, which is why mailbox audit logging matters.
What should we do if we already paid a fraudulent invoice?
Contact your bank immediately, since wire recall windows are short, then report the incident to the Canadian Anti-Fraud Centre and notify your IT provider to check for related mailbox compromise.
Is Defender for Office 365 required to stop BEC?
It is not strictly required, but its impersonation protection and Safe Links features materially reduce risk, and it is included in Microsoft 365 Business Premium.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamClose the gaps that lead to email fraud
We implement phishing-resistant MFA, impersonation protection, mailbox alerting, and a documented verification process to protect your finance team from business email compromise.
Technologies mentioned in this article
See what we support around each platform on our supported technologies hub.
Related services, locations, and resources
Related services
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Microsoft 365 Business Setup Checklist for Small Businesses
A complete, phased checklist for setting up a new Microsoft 365 tenant correctly the first time, from domai…
- Microsoft 365 Business Premium: Is It Worth It?
A capability-level comparison of Microsoft 365 Business Basic, Standard, and Premium, and honest guidance o…
- How Much Does Microsoft 365 Cost for a Small Business in Canada?
Microsoft 365 pricing depends on licence tier, commitment term, add-ons, and how you buy. Here is how the c…
- IT Onboarding Checklist for New Employees
A practical IT onboarding checklist for new hires: accounts, MFA, device setup, security, permissions, Micr…
