For many organisations, phishing is still thought of as a suspicious email asking someone to click a malicious link. That picture is becoming increasingly outdated.
Microsoft recently reported detecting approximately 7.6 billion email-based phishing threats during the second quarter of 2026. While email remains a major attack vector, cybercriminals are increasingly using Microsoft Teams, identity attacks and malicious applications to compromise organisations.
Rather than targeting technology alone, attackers are targeting people and the identities they use every day.
Phishing now extends beyond the inbox
A modern phishing attack may involve any of the following:
- A convincing Teams message appearing to come from IT support
- An application requesting permission to access a user's Microsoft 365 data
- A fake Microsoft sign-in page designed to steal credentials
- MFA fatigue, where repeated authentication prompts pressure a user into approving a sign-in they did not initiate
- A compromised account sending trusted-looking messages internally
Identity is the new security perimeter
As organisations adopt Microsoft 365, the focus of security has shifted. Instead of protecting a network boundary, organisations must protect identities, permissions and access to information.
A compromised Microsoft 365 account can potentially provide access to Exchange Online, Teams, SharePoint, OneDrive, Power Platform and any connected third-party applications. This makes identity protection one of the most important elements of any Microsoft 365 security strategy — and one that smaller organisations often address least systematically.
Practical checks every organisation should consider
Technology alone is not enough. Regular governance reviews can significantly reduce risk. Some practical questions to consider:
- Is multi-factor authentication enabled for all users, including shared and service accounts?
- Are privileged accounts — Global Administrators in particular — regularly reviewed and kept to a minimum?
- Are users allowed to consent to third-party applications without administrator approval?
- Are obsolete guest accounts removed promptly?
- Are suspicious inbox rules monitored — particularly rules that forward email externally?
- Are external Teams communications appropriately controlled?
- Is Conditional Access configured to protect high-risk sign-ins?
Governance matters as much as technology
Good cybersecurity is not simply about deploying another security product. It is about ensuring that access is appropriate, permissions are regularly reviewed, sensitive information is protected, administrative actions are monitored, and security controls continue to reflect how people actually work.
Cybersecurity and information governance are increasingly becoming part of the same conversation. An organisation that governs its Microsoft 365 environment well — clear ownership, reviewed permissions, controlled external access — is also better positioned to resist phishing attacks that target identity rather than email.
What this means in practice
Phishing is no longer confined to email. As organisations adopt cloud services and AI-powered tools, protecting identities and governing access to information become just as important as filtering malicious messages.
Preparing Microsoft 365 for today's threat landscape means looking beyond the inbox and reviewing how identities, permissions and information are managed across the entire environment. For most smaller organisations, the starting point is understanding what they currently have — and a structured review is usually the fastest way to find out.
Microsoft Security Blog: Microsoft Digital Defense Report and threat intelligence updates
Microsoft Learn: Microsoft Defender documentation
Microsoft Learn: Microsoft Entra ID security documentation