As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following protections against Unwanted Access and Shadow Workflows:
Microsoft Entra:
- Ensure sign-in is blocked for member accounts inactive for 90 days
- Ensure sign-in is blocked for guest accounts inactive for 30 days
Microsoft Exchange Online:
- Ensure sign-in to shared mailboxes is blocked
- Ensure outbound spam policies set explicit sending limits and block senders
- Restrict Shared Bookings creation to selected users
These recommended controls may now be scheduled for deployment. Due to potential impact on end users, they will not be rolled out automatically as part of Managed Deployments.