Microsoft 365  ·  Security  ·  Identity  ·  Charities  ·  SMEs

Phishing has moved beyond email.
Is your Microsoft 365 ready?

July 2026
6 min read
Adjona Technology

For many organisations, phishing is still thought of as a suspicious email asking someone to click a malicious link. That picture is becoming increasingly outdated.

Microsoft recently reported detecting approximately 7.6 billion email-based phishing threats during the second quarter of 2026. While email remains a major attack vector, cybercriminals are increasingly using Microsoft Teams, identity attacks and malicious applications to compromise organisations.

Rather than targeting technology alone, attackers are targeting people and the identities they use every day.

Phishing now extends beyond the inbox

A modern phishing attack may involve any of the following:

Many of these attacks never involve a traditional phishing email. An organisation that has invested in email security but not reviewed its Teams permissions, guest access, or application consent settings may have significant exposure it is not aware of.

Identity is the new security perimeter

As organisations adopt Microsoft 365, the focus of security has shifted. Instead of protecting a network boundary, organisations must protect identities, permissions and access to information.

A compromised Microsoft 365 account can potentially provide access to Exchange Online, Teams, SharePoint, OneDrive, Power Platform and any connected third-party applications. This makes identity protection one of the most important elements of any Microsoft 365 security strategy — and one that smaller organisations often address least systematically.

Practical checks every organisation should consider

Technology alone is not enough. Regular governance reviews can significantly reduce risk. Some practical questions to consider:

Many organisations already own the Microsoft 365 security features needed to improve their security posture. The gap is usually not a missing product — it is configuration and review that has not been completed or maintained.

Governance matters as much as technology

Good cybersecurity is not simply about deploying another security product. It is about ensuring that access is appropriate, permissions are regularly reviewed, sensitive information is protected, administrative actions are monitored, and security controls continue to reflect how people actually work.

Cybersecurity and information governance are increasingly becoming part of the same conversation. An organisation that governs its Microsoft 365 environment well — clear ownership, reviewed permissions, controlled external access — is also better positioned to resist phishing attacks that target identity rather than email.

What this means in practice

Phishing is no longer confined to email. As organisations adopt cloud services and AI-powered tools, protecting identities and governing access to information become just as important as filtering malicious messages.

Preparing Microsoft 365 for today's threat landscape means looking beyond the inbox and reviewing how identities, permissions and information are managed across the entire environment. For most smaller organisations, the starting point is understanding what they currently have — and a structured review is usually the fastest way to find out.

Sources
Microsoft Security Blog: Microsoft Digital Defense Report and threat intelligence updates
Microsoft Learn: Microsoft Defender documentation
Microsoft Learn: Microsoft Entra ID security documentation
← All Insights
Free Introductory Conversation

Ready to review your Microsoft 365 security?

Adjona Technology helps charities, care providers, CICs and SMEs build practical, governed Microsoft 365 environments. Book a free 30-minute conversation to start.

Get in touch