No, It’s Not You. It’s Microsoft. Microsoft 365’s impersonation and spoofing controls are frustratingly bad. But you’re not alone in this struggle.
If you can relate to that Reddit post, at some point in time you’ve probably found yourself saying, “There has to be a better way,” you’re not alone.
Let’s break down the most common ways MDO falls short:
Microsoft Defender’s impersonation protection caps out at 350 users and 50 domains per policy. For small organizations, this might work. But if you’re managing a mid-sized business or a growing enterprise, you’ll quickly hit this ceiling.
And when every VIP and external partner can’t fit into a single policy, you’re forced to make tough (and risky) decisions about who gets covered.
Here’s the kicker: Microsoft doesn’t proactively suggest domains or users to add to your protection policies. It’s on you to manually identify and include them. Have a new vendor? You’d better remember to update your list.
Did a phishing attempt slip through because you didn’t know to add a specific partner domain? That’s on you too. This creates a game of constant catch-up that most admins don’t have time to play.
Even with everything configured “correctly,” attackers can still slip through by mimicking display names. For example, an email might appear to come from your CEO, even though the actual email address is a random Gmail account. This basic (and maddening) loophole remains one of the most exploited vulnerabilities.
With these limitations in mind, let’s focus on how to make the most of what Microsoft offers, because if you’re stuck with these tools, giving up isn’t an option.
If you’ve ever found yourself scrolling through Microsoft’s endless help documentation on configuring anti-phishing policies (this one is a 20-minute read—if you don’t get distracted), you already know what you’re up against.
I can‘t imagine doing some of these steps regularly—just to keep up with evolving threats.
For example:
[Wait. It’s 2024. Are we seriously running PowerShell scripts just to stop spoofed emails landing in our executives’ inboxes?]
Okay, if you’re stuck with Microsoft’s tools, here’s how to make them slightly less frustrating.
Even with perfect configuration, MDO impersonation controls leave gaps. If you’re spending more time managing policies than protecting users, it's time to look beyond built-in tools.
Third-party solutions, (ahem, like IRONSCALES), don’t just fill the gaps, they remove all the hassle entirely:
Microsoft 365’s impersonation protection isn’t perfect (it’s actually really…bad), but it’s what you’ve got. With the right strategies, you can make it work better and minimize your risk.
That said, if you’re ready to eliminate the headaches entirely, it’s worth exploring solutions that let you focus on what matters: protecting your users, not managing your tools.
Stay alert. Stay informed. Keep your inbox clean.