GreenLoop IT Solutions : Article

365 Best-Practices: Requiring Admin Approval for Entra Application Consent

Executive Summary What it is: Application consent is the permission an employee grants when they click “Accept” to let a third-party app access Microsoft 365 data — email, files, calendar, or in some cases, company-wide directory data. The risk: Left unrestricted, this becomes a way for attackers to gain lasting access to company data without…
Read More

365 Best-Practices: Entra ID Password Protection

Why Passwords Still Matter—and Why Traditional Rules Aren’t Enough Passwords remain the first line of defense against cyber threats, but attackers have become experts at exploiting weak or predictable choices. Attackers increasingly collect huge numbers of known passwords, including “informed guesses” based on password breaches or even leaked personally-identifiable information. Password spray and password stuffing…
Read More

365 Best-Practices: Blocking New Registrations of Insecure Authentication Methods

Cybersecurity threats are becoming increasingly sophisticated, and organizations must stay ahead of attackers by strengthening how users prove their identity. This article explains why GreenLoop is taking steps to phase out lower-security authentication methods while at the same time guiding clients toward stronger, phishing-resistant options. It is written for business and technology decision makers who…
Read More

Recommendation: Microsoft 365 Backup

Your data is one of your business’s most valuable assets. Microsoft 365 has become a popular choice for many businesses, as it provides a range of tools and services for communication, collaboration, and productivity. However, relying solely on Microsoft 365 to store and backup your data can be risky. This is where third-party backup solutions…
Read More

What to expect when using Microsoft Authenticator with Number Matching

Microsoft Authenticator with Number Matching is a new, security-enhanced experience for Multi-Factor Authentication. It helps address emerging “MFA fatigue” attacks—attackers can gain access when users reflexively hit “Approve” on an authentication prompt that an attacker generated. GreenLoop recommends enabling this as the default option for Microsoft Authenticator. Here’s an overview of the experience. This assumes…
Read More

What to expect when automatic Message Encryption via Office 365 Data Loss Prevention (DLP) is enabled

If you are reading this, your organization is likely using Microsoft’s Data Loss Prevention capability to automatically encrypt outgoing emails when contents of a sensitive nature are detected. If you’re not currently using this and you’d like to learn more, please contact your GreenLoop Account Manager. Depending on your company/industry and the rules your organization…
Read More

How to prepare your account for Office 365 Multi-Factor Authentication

What: This document walks you through the process of preparing your account for Multi-Factor Authentication (“MFA”) deployment with your organization. Why: Multi-Factor Authentication is a best-practice against emerging security threats and is strongly recommended as a preventative measure against phishing and various other scamming attempts. MFA requires both the traditional username/password and another authentication method that a…
Read More

Microsoft 365 Mailbox Size Troubleshooting

Introduction Microsoft Office 365 includes a large amount of mailbox storage per user, especially relative to legacy and prior-generation email systems. However, you may still find yourself running low on available mailbox space.  Outlook has built-in tools to search and clean up old or large content. However, this is often undesirable: time-consuming requires deleting content…
Read More

Microsoft 365 Sharing Governance Guide

This document is intended to be an overview of the most commonly used settings available for Sharing and Collaboration in the Microsoft 365 platform. For brevity and clarity, there are many options not covered here. Where further detail might be desired, we’ve provided links to Microsoft’s documentation for further reference. GreenLoop is glad to consult…
Read More

Email Retention Best Practices

What do you do with email mailboxes associated with prior or terminated employees? There’s often critical data in them, and depending on your industry, you may be required by law to retain the data for some period of time. Some regulations that may apply include: Internal Revenue Service (US IRS): seven (7) years Payment Card (PCI…
Read More