What Exchange Online means in practice
Email remains the primary attack surface for most organisations and the primary record of what was agreed, which makes Exchange Online both a security control point and a compliance obligation rather than just a mail server.
Core capabilities include user mailboxes, shared mailboxes that do not consume a licence, resource mailboxes for rooms and equipment, distribution and dynamic distribution groups, and Microsoft 365 groups. Mail flow rules apply organisation-wide handling — external sender warnings, disclaimers, conditional routing. Retention policies and litigation hold preserve content for legal and record-keeping purposes independently of what users delete.
Security configuration is where most environments have gaps. Domain authentication with SPF, DKIM and DMARC should be complete and DMARC eventually moved from monitoring to enforcement, or the domain remains spoofable regardless of inbound filtering. Defender for Office 365 adds safe links, safe attachments and impersonation protection for executives and the domain itself. Auto-forwarding to external addresses should be blocked by policy, because mailbox forwarding rules are the standard persistence mechanism after a business email compromise.
Business email compromise is the incident type that costs Australian organisations the most money, usually through an invoice redirected to an attacker-controlled account. The technical controls that prevent it — MFA, blocking legacy authentication, alerting on mailbox rule creation and impossible-travel sign-ins — are all available in the platform. The process control that prevents the loss is verbal verification of bank detail changes, which sits with finance rather than IT.
Migration from on-premises Exchange or from another provider is a well-trodden path with hybrid, cutover and staged approaches. The variables that determine effort are mailbox count and size, public folders, shared calendar dependencies, and any line-of-business application that sends mail through the old server and will keep doing so until somebody finds it.
How we help with this
Related terms
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
- Microsoft 365 TenantA Microsoft 365 tenant is a dedicated instance of Microsoft's cloud services created for one organisation.
- Microsoft Entra IDMicrosoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity and access management service.
- Microsoft IntuneMicrosoft Intune is the cloud endpoint management service in Microsoft 365.
