MSG / MSG-04
Microsoft 365 or Google Workspace email hardening
Tuning existing email services to reduce abuse of accounts, delegation, forwarding and connected applications.

WHEN IT HELPS
A focused response
to a defined need.
Cloud administrator; legacy settings, unclear delegation or insufficient useful logging.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Roles and delegation
- forwarding rules and applications
- native protection, logs and recovery procedures
Deliverables
- Target configuration
- scoped changes
- exception documentation and acceptance tests
Acceptance evidence
Authorised business use is tested; sensitive settings have a target, owner and exception procedure.
DELIVERY
How the work is structured.
Approach
Map domains and senders; select controls; test in pilot/observation mode; enable gradually; organise exceptions, alerts and support.
Prerequisites & responsibilities
Customer: email/DNS administrators, sending teams and sender approval. Provider: configuration and tests. For financial fraud, involve payment owners.
Scope factors
Mailboxes, domains, volume, connectors, third-party senders and operating scope. Proofpoint or other licenses, storage and recurring service are separate from the project.
Questions to clarify
Which licences and features are active? Which forwarding is legitimate? Who administers shared mailboxes?
IMPORTANT BOUNDARIES
Available features depend on the subscription. Proposed settings are tested against application dependencies and user workflows before rollout.
No solution blocks every fraud attempt. Overly strict policies can block legitimate messages; pilots, exceptions and business procedures remain essential.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An SME has shared mailboxes with historical delegation. Project: review permissions and forwarding. Target outcome: limited access and governed external forwarding, validated with affected assistants and teams.
Scenario 02
A third-party application has broad email access. Project: assess permissions and business need. Target outcome: revoke or reduce access and add approval workflows without unexpectedly breaking a legitimate integration.
Technology and reference context
Microsoft 365 or Google Workspace; available native controls and licensed options.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
