Skip to content

Commit

Permalink
Update secure-configuration.md
Browse files Browse the repository at this point in the history
added acsc link
  • Loading branch information
adonm authored May 3, 2024
1 parent ee47482 commit 6ece316
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/guidelines/secure-configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -90,7 +90,7 @@ Migrate from legacy macros to [Office Scripts and Power Automate](https://learn.

Once Azure AD MFA configured, below migrations will get identities and data into compliant states and locations

- Enable [DKIM/DMARC/SPF](https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/email-authentication-about?view=o365-worldwide#how-to-avoid-email-authentication-failures-when-sending-mail-to-microsoft-36) across all registered domains belonging to the organisation
- [Combat fake emails (ACSC)](https://www.cyber.gov.au/resources-business-and-government/maintaining-devices-and-systems/system-hardening-and-administration/email-hardening/how-combat-fake-emails) by enabling [DKIM/DMARC/SPF](https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/email-authentication-about?view=o365-worldwide#how-to-avoid-email-authentication-failures-when-sending-mail-to-microsoft-36) across all registered domains belonging to the organisation
- If legacy systems/applications dependent on SMTP exist, migrate them to separate subdomains on transactional email platforms such as [mailchimp](https://mailchimp.com/developer/transactional/docs/smtp-integration/)[postmarkapp](https://postmarkapp.com/developer/user-guide/send-email-with-smtp) or [sendgrid](https://docs.sendgrid.com/for-developers/sending-email/getting-started-smtp) to avoid reducing the security of the primary identity domains
- [Disable SMTP Auth for Exchange Online](https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission#disable-smtp-auth-in-your-organization) to simplify conditional access policies and avoid reconnaisance and exploitation of primary identity domains and mailboxes
- [Migrate file shares to OneDrive, Teams, and SharePoint](https://learn.microsoft.com/en-us/sharepointmigration/fileshare-to-odsp-migration-guide) and enable [Microsoft Purview risk and compliance](https://learn.microsoft.com/en-us/purview/purview-compliance)
Expand Down

0 comments on commit 6ece316

Please sign in to comment.