



Microsoft 365 has become the operational backbone of the Indian enterprise. Email, Teams, SharePoint, OneDrive, and Power Platform now host some of the most sensitive information in the organisation—customer contracts, financial projections, engineering IP, and personal data covered by India’s Digital Personal Data Protection (DPDP) Act. Yet in our experience running 24/7 SOC operations for mid-market and enterprise clients across India, M365 misconfigurations and cloud-identity attacks remain among the most frequently exploited initial-access vectors we respond to.
This guide is written for Indian CISOs and IT leaders who have already deployed M365 but have not yet hardened it systematically. We cover the threat patterns we see most often, the controls that stop them, and how to align your posture with CERT-In and DPDP obligations.
The value density of M365 is extraordinary. A single compromised administrator account can expose all email inboxes via eDiscovery, exfiltrate OneDrive files across the entire organisation, and grant attacker-controlled OAuth applications persistent access—even after the user changes their password. This is why adversaries treat M365 as a high-value objective rather than a stepping stone.
Three threat patterns dominate the Indian enterprise landscape in 2026:
OAuth consent-phishing attacks trick a user into authorising a malicious third-party application with broad Microsoft Graph API permissions—often Mail.Read, Files.ReadWrite.All, or Contacts.Read. Because OAuth tokens are long-lived and tied to the application rather than the user’s session, resetting the user’s password does not revoke the attacker’s access. We have responded to incidents where an attacker maintained read access to a CFO’s inbox for four months through an illicit OAuth grant that nobody noticed.
In India specifically, many organisations have never audited the third-party applications registered in their Azure AD tenant. The Microsoft Entra ID enterprise applications blade is often a graveyard of forgotten integrations—some legitimate, some not.
Conditional Access (CA) is M365’s primary access-control layer, but the default configuration in most Indian tenants we assess has significant gaps. Common weaknesses include: policies that exclude service accounts or break-glass accounts without compensating controls; no device-compliance enforcement for BYOD endpoints common in hybrid workforces; and—critically—legacy authentication protocols (SMTP AUTH, IMAP, POP3) left enabled, which bypass modern MFA entirely. Attackers with a credential list will spray these legacy endpoints first because they reliably bypass conditional access.
Attackers who have compromised one M365 account increasingly pivot to Teams to target other users inside the organisation. Malicious file links sent via Teams inherit the implicit trust of an internal message—users are far less suspicious than they would be of an external email. SharePoint sharing links misconfigured as “anyone with the link” have also been used to distribute weaponised documents in spear-phishing campaigns that originate inside the tenant.
The following controls address the most common gaps we identify during M365 security assessments. Treat this as a baseline, not a ceiling.
M365 controls the cloud layer, but FortiGate and FortiMail defend the network perimeter through which email traffic and user sessions flow. PJ Networks deploys and manages FortiGate next-generation firewalls and FortiMail email security gateways as a coordinated defence for M365 environments.
FortiGate: By routing outbound internet traffic from M365-connected endpoints through FortiGate, you gain SSL inspection of Teams and OneDrive traffic, application control to block rogue cloud storage services that could be used for data exfiltration, and DNS filtering via FortiGuard to block domains associated with OAuth phishing kits and M365-themed credential harvesting pages. FortiGate’s ZTNA capabilities allow you to enforce device posture checks before granting access to M365—ensuring that only managed, compliant devices can authenticate, regardless of whether the user is in office or remote.
FortiMail: For organisations that route email through an on-premise or cloud-hosted mail gateway before M365, FortiMail adds a critical pre-delivery inspection layer. FortiMail performs sender authentication verification, advanced attachment sandboxing, URL rewriting for time-of-click protection, and impersonation detection using AI-based analysis of display names and domain lookalikes—capabilities that complement rather than duplicate Microsoft Defender for Office 365.
A hardened M365 tenant still generates thousands of security-relevant events daily—sign-in anomalies, mailbox access by unusual actors, suspicious OAuth consent events, bulk file downloads. Making sense of these signals at speed is where unified SecOps platform capability becomes essential.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner—the platform we deploy and operate for clients who need integrated visibility across their security and network estate.
SIEM: Ora’s SIEM ingests M365 Unified Audit Log events alongside logs from FortiGate, FortiMail, endpoint agents, and other sources in your environment. Correlation rules mapped to MITRE ATT&CK techniques fire alerts on patterns that individual products cannot detect in isolation—for example, a sign-in anomaly followed by an OAuth application consent event followed by a bulk mail export, which is the hallmark of an attacker establishing persistent access. Graph-based attack storyline reconstruction allows our SOC analysts to visualise the full kill chain rather than triaging individual alerts. Critically, Ora supports tiered retention (hot, cold, and archive tiers) that helps Indian enterprises evidence compliance with CERT-In’s direction on 180-day in-country log retention—a requirement that Microsoft’s own UAL retention settings may not satisfy without deliberate export and storage architecture.
NMS: For enterprises where M365 sits alongside multi-vendor on-premise infrastructure, Ora’s Network Management System provides unified observability across FortiGate firewalls, switches, access points, and WAN/SD-WAN links. LLDP/CDP topology discovery and network path tracing give our NOC team real-time visibility into how M365 traffic is routing through your network—so a WAN outage or BGP misconfiguration that affects M365 connectivity is caught and correlated in the same console as security events, not in a separate tool that nobody is watching at 3 a.m.
Video Surveillance (VMS): For manufacturing, retail, and multi-site enterprises, Ora’s video surveillance (VMS) module—supporting ONVIF, Hikvision, and Dahua camera management with video analytics—allows physical security events to be correlated with network security events. An after-hours physical access event at a server room can be surfaced alongside a concurrent M365 admin login from an unusual location, giving our SOC a more complete picture of an insider threat or a coordinated physical-digital attack.
SOAR: When a M365 threat is confirmed, response speed is critical—especially given CERT-In’s 6-hour incident reporting window. Ora’s SOAR module provides playbook automation with pre-built connectors that allow automated response actions: disabling a compromised M365 account, revoking OAuth tokens, pushing malicious IP blocklists to FortiGate, and generating a structured CERT-In report draft. Automation does not replace analyst judgment—but it compresses a two-hour manual response into a ten-minute assisted one, which is what makes the CERT-In timeline realistic rather than aspirational.
If your organisation is running M365 without a coordinated SIEM/SOAR layer watching its audit logs, we recommend discussing how Ora can be deployed into your environment. Reach out to our team for an assessment.
Two regulatory frameworks shape how Indian enterprises must manage M365 security incidents in 2026.
CERT-In’s April 2022 directions require organisations to report cybersecurity incidents within six hours of detection. M365 compromise events—including unauthorised access to email, data exfiltration via SharePoint, and account takeover—fall squarely within the mandatory reporting categories. The directions also require:
For M365, this means you must have an architecture that exports UAL events to an India-resident log repository on an ongoing basis. A reactive export after an incident is too late—CERT-In expects continuous log retention, not best-effort recovery.
M365 is almost certainly a processing environment for personal data under the DPDP Act. Email, HR documents, customer records, and Teams communications may all contain personal data of Indian data principals. The DPDP Act requires data fiduciaries to implement appropriate technical and organisational measures to prevent personal data breaches. A compromised M365 tenant that leads to personal data exfiltration is a reportable breach under the Act.
PJ Networks’ managed SOC, operating with PrahiX Ora, helps evidence compliance by providing continuous monitoring of M365 environments, documented incident response procedures, and structured reporting workflows—supporting compliance with both CERT-In and DPDP obligations. We do not claim that any specific control set makes an organisation “DPDP compliant”—compliance is a programme, not a product—but we can significantly reduce both your risk exposure and your ability to demonstrate due diligence if an incident occurs.
In our assessments, the gaps we encounter most consistently are not exotic vulnerabilities—they are configuration decisions made at deployment time that were never revisited as the threat landscape evolved.
The most common: legacy authentication never blocked (because “we have a printer that uses SMTP AUTH”), Conditional Access policies never extended to cover the mobile and BYOD devices that 60% of employees actually use, the Unified Audit Log enabled but logs never exported and monitored, and third-party OAuth applications accreted over years with nobody maintaining an approved-application register.
These are not difficult problems to solve. They require a structured assessment, a prioritised remediation plan, and ongoing monitoring—all of which are operational rather than technical challenges.
PJ Networks offers a structured Microsoft 365 Security Assessment for Indian enterprises. Over three to five days, our team reviews your tenant configuration against a 60-point control framework, identifies the highest-risk gaps, and produces a prioritised remediation roadmap with effort estimates and quick wins you can address immediately.
We also offer ongoing managed M365 security monitoring as part of our 24/7 NOC/SOC service—integrating your M365 audit logs, FortiGate, and FortiMail telemetry into PrahiX Ora for continuous visibility and rapid incident response.
If your organisation is running Microsoft 365 for critical business functions and has not conducted a formal security review in the past 12 months, the risk exposure is significant. India’s regulatory environment—CERT-In’s 6-hour reporting obligation and the DPDP Act’s breach notification requirements—means that an undetected M365 compromise carries consequences beyond the immediate operational impact.
Contact PJ Networks to discuss an M365 security assessment or to explore how our managed security services can protect your cloud collaboration environment.