Skip to content

Home Expertise / Email & fraud protection

MSG / MSG-04

Microsoft 365 or Google Workspace email hardening

Tuning existing email services to reduce abuse of accounts, delegation, forwarding and connected applications.

WHEN IT HELPS

A focused response
to a defined need.

Cloud administrator; legacy settings, unclear delegation or insufficient useful logging.

AT A GLANCE

Family
Email & fraud protection

Engagement
Implementation

Reference
MSG-04

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Roles and delegation
  • forwarding rules and applications
  • native protection, logs and recovery procedures

Deliverables

  • Target configuration
  • scoped changes
  • exception documentation and acceptance tests

Acceptance evidence

Authorised business use is tested; sensitive settings have a target, owner and exception procedure.

DELIVERY

How the work is structured.

Approach

Map domains and senders; select controls; test in pilot/observation mode; enable gradually; organise exceptions, alerts and support.

Prerequisites & responsibilities

Customer: email/DNS administrators, sending teams and sender approval. Provider: configuration and tests. For financial fraud, involve payment owners.

Scope factors

Mailboxes, domains, volume, connectors, third-party senders and operating scope. Proofpoint or other licenses, storage and recurring service are separate from the project.

Questions to clarify

Which licences and features are active? Which forwarding is legitimate? Who administers shared mailboxes?

IMPORTANT BOUNDARIES

Available features depend on the subscription. Proposed settings are tested against application dependencies and user workflows before rollout.

No solution blocks every fraud attempt. Overly strict policies can block legitimate messages; pilots, exceptions and business procedures remain essential.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

An SME has shared mailboxes with historical delegation. Project: review permissions and forwarding. Target outcome: limited access and governed external forwarding, validated with affected assistants and teams.

Scenario 02

A third-party application has broad email access. Project: assess permissions and business need. Target outcome: revoke or reduce access and add approval workflows without unexpectedly breaking a legitimate integration.

Technology and reference context

Microsoft 365 or Google Workspace; available native controls and licensed options.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.