{"id":63051,"date":"2026-08-31T19:48:24","date_gmt":"2026-08-31T15:48:24","guid":{"rendered":"https:\/\/www.msp360.com\/resources\/?p=63051"},"modified":"2026-08-31T19:53:52","modified_gmt":"2026-08-31T15:53:52","slug":"how-to-protect-microsoft-365-and-google-workspace-from-business-email-compromise","status":"publish","type":"post","link":"https:\/\/www.msp360.com\/resources\/blog\/how-to-protect-microsoft-365-and-google-workspace-from-business-email-compromise\/","title":{"rendered":"How to Protect Microsoft 365 and Google Workspace from Business Email Compromise"},"content":{"rendered":"<div style=\"display: none;\">\n<style>.entry-content .table-of-content ul ul{display:none;}<\/style>\n<\/div>\n<p>According to the <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2025_IC3Report.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">FBI\u2019s Internet Crime Complaint Center\u2019s latest report<\/a>, in 2025 there were 24,768 BEC complaints, which led to $3.04 billion in losses.<!--more--><div class=\"table-of-content \">\n\t\t\t\t<p>Table of Contents<\/p>\n\t\t\t\t<ul><\/ul>\n\t\t\t\t<\/div><\/p>\n<p>While Microsoft 365 and Google Workspace come with robust security controls, the reality is that BEC attacks can happen through many different pathways and no single setting will protect against them all.<\/p>\n<p>Moreover, email in both platforms is just one aspect of a larger cloud identity. As <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/responding-to-a-compromised-email-account\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft points out<\/a>, if Entra ID credentials are compromised, it can lead to the associated mailbox, calendars, contacts, documents, shared files, third-party apps, SharePoint folders, and OneDrive files being exposed as well. Google Workspace administrators can investigate activity across Gmail and Drive in supported editions.<\/p>\n<blockquote><p><strong>Note: A compromised mailbox is therefore rarely just an email problem.<\/strong><\/p><\/blockquote>\n<p>Finally, we should understand what Business Email Compromise doesn\u2019t look like: a traditional cyber attack. Many users mistakenly believe that the typical way for BEC is a malicious attachment, suspicious link, or request for a password. The attacker may write a two-line message in a familiar tone and insert it into a genuine supplier conversation. Sometimes it even comes from a real account. That makes BEC particularly dangerous in Microsoft 365 and Google Workspace environments.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/easydmarc.com\/blog\/what-is-business-email-compromise-bec\/\">What is Business Email Compromise (BEC)?<\/a><\/p>\n<h2>Not All BEC Attacks Begin Alike<\/h2>\n<p>To the email recipient, most BEC messages may appear nearly identical. For example: the company CEO asks to wire money urgently, a vendor requests updated bank account information, or HR wants personal data about an employee.<\/p>\n<p>But what happened behind the scenes to make these emails possible could be vastly different.<\/p>\n<p>Attackers may have <strong>spoofed your domain<\/strong>, sent an email from a <strong>lookalike domain<\/strong>, <strong>compromised<\/strong> a trusted supplier\u2019s email account, or simply logged into a legitimate Microsoft 365 or Google Workspace account. Each approach circumvents trust differently, and each can be stopped in its tracks with different security measures in place. This is why there\u2019s no silver bullet technology to prevent all forms of BEC.<\/p>\n<p>Let\u2019s break down the following methods: setting DMARC can prevent domain spoofing, identity verification prevents account compromise, and independent verification is critical for high-value business transactions.<\/p>\n<h2>Close the Direct-Spoofing Route With DMARC Enforcement<\/h2>\n<p>The first line of defense against someone spoofing your organization's domain is <strong>email authentication<\/strong>.<\/p>\n<p>SPF, DKIM and DMARC protect your domain by helping receiving mail servers identify legitimate emails from ones that simply look like they come from your domain.<\/p>\n<p>Enabling DMARC isn\u2019t the hard part. The real challenge is that most organizations using Microsoft 365 or Google Workspace also send email through <strong>multiple third-party services<\/strong>. Marketing automation platforms, CRM systems, customer support tools, billing platforms, and dozens of other business applications can relay mail from your domain. Until these services are identified and configured, jumping to a DMARC policy that enforces quarantine or rejection will cause any messages they send to fail authentication.<\/p>\n<p>Monitoring lets most organizations safely learn which messages are legitimate before enforcing a DMARC policy. This is where a DMARC management platform such as <a href=\"https:\/\/easydmarc.com\/dmarc\">EasyDMARC<\/a> becomes useful. It turns aggregate reporting into a clearer view of sending sources, authentication failures, and the changes needed to progress safely toward enforcement.<\/p>\n<p>DMARC is a great first layer of defense because it will stop attackers from sending email impersonating your domain straight to your customers. But it won\u2019t protect you against all other approaches of BEC.<\/p>\n<h2>Prevent Account Takeover<\/h2>\n<p>Inside an authenticated user\u2019s account, an attacker can search through existing email threads to learn how and who approves invoices. Then, they can forward payment emails to themselves, move replies to a hidden folder, share OAuth app access with a partner, or delete any incriminating email. Now we focus on different methods to prevent it.<\/p>\n<h3>Use Phishing-Resistant Authentication<\/h3>\n<p>Requiring MFA is a great baseline, but think about requiring stronger levels of authentication for higher-risk accounts. Administrator, finance, and HR accounts are good examples.<\/p>\n<p>Passkeys and hardware-backed security keys help prevent credential phishing better than passwords and OTPs. <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/authentication\/how-to-plan-prerequisites-phishing-resistant-passwordless-authentication\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Entra ID<\/a> allows you to enroll phishing-resistant authentication methods like passkeys, Windows Hello for Business, FIDO2 security keys, and certificate-based authentication. <a href=\"https:\/\/www.google.com\/account\/about\/passkeys\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> refers to security keys as the \u201cstrongest\u201d 2-Step Verification option and also allows passkey-based login.<\/p>\n<p>Additionally, if licensing allows, context-aware access policies can inform the decision. Microsoft Entra ID <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/policy-admin-phish-resistant-mfa\" target=\"_blank\" rel=\"noopener noreferrer\">Conditional Access<\/a> can enforce specific authentication strengths and assess access conditions. Google Workspace <a href=\"https:\/\/knowledge.workspace.google.com\/admin\/security\/protect-your-business-with-context-aware-access\" target=\"_blank\" rel=\"noopener noreferrer\">Context-Aware Access<\/a> can limit app usage based on the user, location, IP address, and device security state.<\/p>\n<h3>Manage Third-Party Application Access<\/h3>\n<p>Just because a password hasn\u2019t been cracked doesn\u2019t mean your Microsoft 365 or Google Workspace accounts are safe from intrusion. By approving a malicious OAuth application or one with overly broad permissions, a user can grant it access to their email, files, and other data stored in the cloud without the need for a password.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/enterprise-apps\/configure-user-consent\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> and <a href=\"https:\/\/support.google.com\/a\/answer\/9262032\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> both advise restricting users\u2019 ability to approve applications and limiting OAuth access wherever possible. Include which users can approve application access in your internal security policy, keep an inventory of approved applications, require admin approval of apps with sensitive access requests, and conduct regular reviews to clean up orphaned apps. If there is no obvious business need, treat all unexpected requests for email or cloud storage access as suspicious.<\/p>\n<h3>Watch for Signs of Account Compromise<\/h3>\n<p>One goal of BEC attackers can be to stay stealthy long enough to learn who is talking to whom and where money is being sent.<\/p>\n<p><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/responding-to-a-compromised-email-account\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> urges you to look for typical mailbox anomalies such as email suddenly going missing or deleted email not existing, suspicious emails appearing in Sent Items or Deleted Items folders, unexpected external forwarding addresses, and inbox rules that automatically move messages to RSS Subscriptions, Notes or Junk Email folders.<\/p>\n<p><a href=\"https:\/\/knowledge.workspace.google.com\/admin\/support\/troubleshooting\/identify-and-secure-compromised-accounts\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> also advises you to look at any Gmail filters you have set up, as well as forwarding settings, account recovery options, missing messages, contacts, and other Gmail-related settings if you suspect an account was compromised.<br \/>\nWait for someone to tell you that an email was there and now it's gone. Unexpected mailbox forwarding rules, filters, and other settings should be considered suspicious, the victims' security events, especially in the case of financial, executive, and administrative accounts.<\/p>\n<h2>Take High-Risk Decisions Outside the Email Trust Chain<\/h2>\n<p>Organizations need technical controls, but they also need additional layers of defense. While a message can initiate a business process, it shouldn\u2019t be sufficient to execute a risky transaction.<\/p>\n<p>Requests to change supplier bank accounts, payment instructions, payroll details, or other sensitive operations should be confirmed by another channel your company trusts. The <a href=\"https:\/\/www.fbi.gov\/how-we-can-help-you\/scams-and-safety\/common-frauds-and-scams\/business-email-compromise\" target=\"_blank\" rel=\"noopener noreferrer\">FBI recommends<\/a> calling the person or company to confirm payment changes and using a phone number you already have on file, not one included in the email. Additional approval steps can also make sense for larger or unusual payments, based on the organization\u2019s volume and workflows.<\/p>\n<p>The guiding principle here is simple:<\/p>\n<blockquote><p><strong>Note: Email can initiate the request. It shouldn\u2019t serve as the only evidence that the request is legitimate.<\/strong><\/p><\/blockquote>\n<h2>Trainings and Internal Company Policy Regulations<\/h2>\n<p>Employee awareness is still a vital safety net. But your people are only as prepared as your processes. Organizations should practice responding to realistic BEC attacks so teams can spot fraud and handle suspicious requests properly. Organizations should document and consistently enforce those plans.<\/p>\n<p>There are also several Microsoft 365 and Google Workspace features you can use to spot BEC. Both platforms display <strong>external sender warnings, first contact alerts, spoofing notifications<\/strong>, and more. These warnings can be helpful cues to pause. But employees should never assume an email request is safe because those warnings are absent.<\/p>\n<h2>What to do after BEC<\/h2>\n<p>Once BEC is verified, the initial response is to take action to remove the attacker\u2019s access.<\/p>\n<p>Microsoft recommends disabling compromised accounts during investigations and checking for ways attackers could maintain access. <a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/responding-to-a-compromised-email-account\" target=\"_blank\" rel=\"noopener noreferrer\">Entra ID<\/a> also provides a process for revoking user access and refresh tokens.<br \/>\nMicrosoft 365 provides its own investigation and remediation capabilities, with the available depth depending on the organization\u2019s licenses.<\/p>\n<p>In <a href=\"https:\/\/knowledge.workspace.google.com\/admin\/support\/troubleshooting\/identify-and-secure-compromised-accounts\" target=\"_blank\" rel=\"noopener noreferrer\">Google Workspace<\/a>, suspending a suspected compromised user resets the user\u2019s sign-in cookies and OAuth tokens. Administrators should then investigate the account, review forwarding and filters, and restore access only after the account has been secured.<br \/>\nOrganizations with supported Google Workspace editions can use the Security Investigation Tool to find and remove malicious messages from inboxes.<\/p>\n<blockquote><p><strong>Note: For incidents involving transferred funds, time matters.<\/strong><\/p><\/blockquote>\n<p>The <a href=\"https:\/\/www.ic3.gov\/CrimeInfo\/BEC\" target=\"_blank\" rel=\"noopener noreferrer\">FBI recommends<\/a> contacting the originating financial institution as soon as the fraud is discovered and filing a detailed IC3 complaint. Businesses outside the United States should follow the equivalent process with their bank and relevant local authorities.<\/p>\n<p>A focused response should follow this order:<\/p>\n<ol>\n<li>Suspend or disable the affected account.<\/li>\n<li>Revoke active sessions and tokens.<\/li>\n<li>Reset credentials and review registered authentication methods.<\/li>\n<li>Remove unauthorized inbox rules, forwarding, delegates, and application grants.<\/li>\n<li>Find messages sent by the attacker and identify internal and external recipients.<\/li>\n<li>Check whether attackers viewed, changed, or deleted email, files, contacts, or other cloud data.<\/li>\n<li>Preserve audit data and other evidence.<\/li>\n<li>Contact the financial institution immediately<\/li>\n<\/ol>\n<h3>Recover What the Attacker Changed or Deleted<\/h3>\n<p>An attacker may delete messages to hide evidence, remove files, alter cloud data, or interfere with normal business operations. Native recovery may help, but an independent backup provides a separate recovery path outside the affected environment.<\/p>\n<p>Here you can look at MSP360 Backup for Microsoft 365 and Google Workspace, which offers automated <a href=\"https:\/\/www.msp360.com\/saas-backup\/m365\/outlook-backup\/\">Outlook backup<\/a> and <a href=\"https:\/\/www.msp360.com\/resources\/blog\/how-to-backup-gmail\/\">Gmail backup<\/a> for data protection. It is a dedicated <a href=\"https:\/\/www.msp360.com\/saas-backup\/\">SaaS backup<\/a> solution with quick and simple recovery options for data alongside other workloads of both platforms. It supports immutable backup (locked copy of your data), item-level restore, which lets administrators select the users and components that need protection, supports the BYOC (Bring Your Own Cloud) option, and offers centralized multi-tenant management for MSPs.<\/p>\n<p><span class=\"further-reading \">Further reading<\/span> <a href=\"https:\/\/www.iplocation.net\/blog\/best-outlook-backup-solutions\">13 Best Outlook Backup Solutions<\/a><\/p>\n<h2>Conclusion<\/h2>\n<p>Business Email Compromise attacks don\u2019t target one vulnerability. They target your users\u2019 trust. That trust can be placed in your domain, a legitimate M365 or GW account, or a normal business workflow. The best defense is to secure each individually instead of putting all of your trust in one technology or policy. Companies that implement email authentication, robust identity security, clear operating procedures, and a proven recovery plan are much better equipped to prevent BEC attacks and limit damage if an attack does happen.<\/p>\n<p>Here\u2019s the recap for your convenience:<\/p>\n<ul>\n<li>Email authentication prevents domain spoofing<\/li>\n<li>Identity security prevents account takeover<\/li>\n<li>Operating procedures prevent fraudulent approval<\/li>\n<li>Backup reduces business impact when attackers compromise cloud data<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>According to the FBI\u2019s Internet Crime Complaint Center\u2019s latest report, in 2025 there were 24,768 BEC complaints, which led to $3.04 billion in losses.<\/p>\n","protected":false},"author":106,"featured_media":63057,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[877,1010],"tags":[944],"class_list":["post-63051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-articles","category-msp360-m365-google-backup","tag-microsoft-365-and-google-g-suite-backup-in-msp360-mbs"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/63051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/users\/106"}],"replies":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/comments?post=63051"}],"version-history":[{"count":10,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/63051\/revisions"}],"predecessor-version":[{"id":63064,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/posts\/63051\/revisions\/63064"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media\/63057"}],"wp:attachment":[{"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/media?parent=63051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/categories?post=63051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.msp360.com\/resources\/wp-json\/wp\/v2\/tags?post=63051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}