<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Franklin Web Technologies</title>
	<atom:link href="https://franklinwebtech.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://franklinwebtech.com</link>
	<description>Cloud Security Hardening for Microsoft 365 and Google Workspace</description>
	<lastBuildDate>Mon, 07 Sep 2026 10:18:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://franklinwebtech.com/wp-content/uploads/2025/12/cropped-Franklin_Web_Technologies-512x512-Logo-32x32.png</url>
	<title>Franklin Web Technologies</title>
	<link>https://franklinwebtech.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cloud Security for Small Business: 20 Security Gaps Attackers Look For First</title>
		<link>https://franklinwebtech.com/cloud-security-for-small-business-20-security-gaps-attackers-look-for-first/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[cloud security for small business]]></category>
		<category><![CDATA[cloud security misconfigurations]]></category>
		<category><![CDATA[Google Workspace security]]></category>
		<category><![CDATA[Google Workspace Security Checklist]]></category>
		<category><![CDATA[small business cloud security]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2138</guid>

					<description><![CDATA[Cloud security for small business often fails because of small configuration mistakes rather than a lack of expensive security tools. Unused accounts, weak sign-in settings, excessive permissions, exposed files, and neglected administrator accounts can give attackers an opening. Franklin Web Technologies helps businesses identify these overlooked settings and tighten them before they become entry points. [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/cloud-security-for-small-business-20-security-gaps-attackers-look-for-first/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a target="_blank" rel="noopener" href="https://franklinwebtech.com/">Cloud security for small business</a> often fails because of small configuration mistakes rather than a lack of expensive security tools. Unused accounts, weak sign-in settings, excessive permissions, exposed files, and neglected administrator accounts can give attackers an opening. Franklin Web Technologies helps businesses identify these overlooked settings and tighten them before they become entry points. The 20 gaps below form a practical starting point for reviewing your cloud environment.</p>



<h2 class="wp-block-heading">Why Small Businesses Should Look Beyond the Login Screen</h2>



<p class="wp-block-paragraph">Cloud platforms such as <a target="_blank" rel="noopener" href="https://franklinwebtech.com/microsoft-365-security-checklist/"><strong>Microsoft 365 Security</strong></a> and Google Workspace give small companies access to email, documents, calendars, collaboration tools, customer information, and business records from almost anywhere. That convenience also means a single poorly configured account can expose far more than an employee&#8217;s inbox.</p>



<p class="wp-block-paragraph">Small business cloud security is not only about adding another security product. It starts with checking how accounts, permissions, applications, sharing settings, devices, and recovery options are configured. Many dangerous gaps are created during setup and then forgotten as the business grows.</p>



<p class="wp-block-paragraph">The following issues are among the first areas worth reviewing.</p>



<h2 class="wp-block-heading">1. Multi Factor Authentication Is Not Enabled</h2>



<p class="wp-block-paragraph">Passwords alone provide limited protection against stolen credentials. Multi factor authentication requires an additional verification method, making unauthorized access harder even when a password has been compromised.</p>



<p class="wp-block-paragraph">Review every user account, especially administrators, finance staff, executives, and anyone with access to sensitive files.</p>



<h2 class="wp-block-heading">2. Administrator Accounts Are Overused</h2>



<p class="wp-block-paragraph">Administrator accounts can change settings, create users, assign permissions, and access important information. Giving administrative privileges to too many people increases the impact of a compromised account.</p>



<p class="wp-block-paragraph">Keep administrator access limited and use standard accounts for everyday work.</p>



<h2 class="wp-block-heading">3. Former Employee Accounts Remain Active</h2>



<p class="wp-block-paragraph">An employee leaving the company should trigger an immediate account review. An active account that no longer has a legitimate owner can become an easy route into business systems.</p>



<p class="wp-block-paragraph">Disable accounts promptly and review their licenses, file ownership, email forwarding, application access, and delegated permissions.</p>



<h2 class="wp-block-heading">4. Shared Accounts Have No Clear Owner</h2>



<p class="wp-block-paragraph">Accounts such as sales@, support@, or billing@ can become difficult to manage when several people share one password. It may also be unclear who has access or when that access should end.</p>



<p class="wp-block-paragraph">Use delegated access, groups, or role-based permissions where the platform supports them instead of relying on shared credentials.</p>



<h2 class="wp-block-heading">5. External File Sharing Is Too Broad</h2>



<p class="wp-block-paragraph">Cloud storage makes it easy to share documents with customers, contractors, and suppliers. A broad sharing setting can also make sensitive information available to people who do not need it.</p>



<p class="wp-block-paragraph">Review public links, external collaborators, shared folders, and anonymous access. Set sharing rules according to the sensitivity of the information.</p>



<h2 class="wp-block-heading">6. Users Have More Permissions Than They Need</h2>



<p class="wp-block-paragraph">A user does not need access to every folder, application, or business record simply because the technology makes it possible.</p>



<p class="wp-block-paragraph">Apply least-privilege access. Give employees the permissions required for their responsibilities and remove access that no longer serves a business purpose.</p>



<h2 class="wp-block-heading">7. Old Applications Still Have Account Access</h2>



<p class="wp-block-paragraph">Employees often connect cloud accounts to applications for scheduling, file management, productivity, or other tasks. Some of those applications may remain connected long after they are no longer used.</p>



<p class="wp-block-paragraph">Review connected applications and revoke access for tools that are outdated, unnecessary, or unfamiliar.</p>



<h2 class="wp-block-heading">8. Security Defaults Were Never Reviewed</h2>



<p class="wp-block-paragraph">Cloud platforms frequently provide protective settings that can be enabled or adjusted during setup. Businesses sometimes accept the initial configuration and never return to review it.</p>



<p class="wp-block-paragraph">A cloud configuration security review should examine authentication, account recovery, application permissions, sharing controls, administrator roles, logging, and other available safeguards.</p>



<h2 class="wp-block-heading">9. Conditional Access Rules Are Missing or Too Basic</h2>



<p class="wp-block-paragraph">Businesses using Microsoft 365 can use Conditional Access to apply access requirements based on factors such as user identity, device status, application, location, and risk signals.</p>



<p class="wp-block-paragraph">For example, administrators may require stronger verification for sensitive applications or restrict access from devices that do not meet company requirements.</p>



<h2 class="wp-block-heading">10. Email Forwarding Rules Go Unnoticed</h2>



<p class="wp-block-paragraph">Unexpected forwarding rules can redirect business email to external addresses. This is particularly concerning for accounts handling invoices, customer information, payment instructions, or confidential conversations.</p>



<p class="wp-block-paragraph">Review mailbox forwarding and automatic rules regularly, especially after an unusual account event.</p>



<h2 class="wp-block-heading">11. Password Recovery Options Are Outdated</h2>



<p class="wp-block-paragraph">Recovery information can quietly become inaccurate. An old phone number, former employee&#8217;s email address, or unmonitored recovery method can create problems when an account needs to be secured or restored.</p>



<p class="wp-block-paragraph">Confirm that recovery methods belong to the appropriate employee or organization and are protected appropriately.</p>



<h2 class="wp-block-heading">12. No Clear Process Exists for Lost Devices</h2>



<p class="wp-block-paragraph">A lost laptop or phone can create access concerns if the device still has active sessions, stored credentials, or synchronized business files.</p>



<p class="wp-block-paragraph">Businesses should know how to revoke sessions, remove company access, disable accounts, and manage business information on lost or retired devices.</p>



<h2 class="wp-block-heading">13. Devices Are Not Part of Access Decisions</h2>



<p class="wp-block-paragraph">A valid username and password do not automatically mean the device accessing company data should be trusted.</p>



<p class="wp-block-paragraph">Where available, device-based controls can help distinguish managed business devices from unknown or unmanaged equipment.</p>



<h2 class="wp-block-heading">14. Google Workspace Settings Are Left at Their Defaults</h2>



<p class="wp-block-paragraph"><a target="_blank" rel="noopener" href="https://franklinwebtech.com/google-workspace-security-checklist/"><strong>Google Workspace security</strong></a> should include a review of administrator roles, two-step verification, external sharing, connected applications, mobile access, account recovery, and audit information.</p>



<p class="wp-block-paragraph">Small companies often configure Google Workspace quickly and move on to other priorities. A later review can reveal settings that no longer match how the business operates.</p>



<h2 class="wp-block-heading">15. Microsoft 365 Security Settings Are Not Reviewed Regularly</h2>



<p class="wp-block-paragraph">Microsoft 365 environments can change as employees, applications, licenses, devices, and business processes change. A configuration that made sense two years ago may no longer be appropriate.</p>



<p class="wp-block-paragraph">Review identity settings, administrator roles, mailbox rules, application access, sharing policies, Conditional Access policies, and audit capabilities on a scheduled basis.</p>



<h2 class="wp-block-heading">16. Security Logs Are Ignored</h2>



<p class="wp-block-paragraph">Cloud platforms can record valuable information about sign-ins, administrative changes, application activity, file access, and other events. Logs are far less useful if nobody reviews them.</p>



<p class="wp-block-paragraph">Define which events deserve attention and establish a process for investigating unusual activity.</p>



<h2 class="wp-block-heading">17. Unusual Sign-Ins Do Not Trigger Investigation</h2>



<p class="wp-block-paragraph">A login from an unfamiliar location, device, or application may have a legitimate explanation. It can also indicate that an account has been accessed by someone else.</p>



<p class="wp-block-paragraph">Set appropriate alerts and investigate unusual sign-in activity instead of treating every notification as routine background noise.</p>



<h2 class="wp-block-heading">18. Business Data Is Stored Without Clear Classification</h2>



<p class="wp-block-paragraph">Not every document requires the same level of protection. Payroll records, contracts, customer information, intellectual property, and general marketing material have different access requirements.</p>



<p class="wp-block-paragraph">Classify important information and use that classification to guide permissions, sharing, retention, and access policies.</p>



<h2 class="wp-block-heading">19. Backup and Recovery Assumptions Are Never Tested</h2>



<p class="wp-block-paragraph">Many businesses assume their cloud provider automatically protects everything they may need to recover. Cloud platforms provide important availability and recovery features, but businesses still need to understand what is covered, how long information is retained, and what recovery options are available.</p>



<p class="wp-block-paragraph">Test critical recovery procedures rather than relying on assumptions.</p>



<h2 class="wp-block-heading">20. No One Owns the Configuration Review</h2>



<p class="wp-block-paragraph">Perhaps the most overlooked gap is responsibility. If nobody owns the cloud environment, small configuration problems can remain unnoticed for months or years.</p>



<p class="wp-block-paragraph">Assign an owner for reviewing accounts, permissions, applications, sharing settings, administrator access, alerts, and recovery controls. A documented cloud security checklist makes recurring reviews easier to manage.</p>



<h2 class="wp-block-heading">The 20 Gaps at a Glance</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Security gap</th><th>Why it matters</th><th>Practical action</th></tr><tr><td>MFA not enabled</td><td>Stolen passwords may be enough for access</td><td>Require MFA</td></tr><tr><td>Excessive admin access</td><td>Increases the impact of account compromise</td><td>Limit admin roles</td></tr><tr><td>Former employee accounts</td><td>Unused accounts can remain accessible</td><td>Disable promptly</td></tr><tr><td>Shared accounts</td><td>Access becomes difficult to track</td><td>Use delegated access</td></tr><tr><td>Broad file sharing</td><td>Sensitive files may reach outsiders</td><td>Restrict sharing</td></tr><tr><td>Excess permissions</td><td>Users may access unnecessary data</td><td>Apply least privilege</td></tr><tr><td>Old applications</td><td>Connected tools may retain access</td><td>Revoke unused access</td></tr><tr><td>Unreviewed defaults</td><td>Weak settings can go unnoticed</td><td>Conduct regular reviews</td></tr><tr><td>Missing access policies</td><td>Risky access may go unchecked</td><td>Configure appropriate rules</td></tr><tr><td>Email forwarding</td><td>Messages may be redirected externally</td><td>Review forwarding rules</td></tr><tr><td>Outdated recovery details</td><td>Recovery channels may be misused</td><td>Update recovery methods</td></tr><tr><td>Lost-device gaps</td><td>Active sessions may remain open</td><td>Revoke access quickly</td></tr><tr><td>Unmanaged devices</td><td>Business data may be accessed from unknown devices</td><td>Apply device controls</td></tr><tr><td>Google Workspace gaps</td><td>Important controls may remain unused</td><td>Review admin settings</td></tr><tr><td>Microsoft 365 gaps</td><td>Changes can create new openings</td><td>Schedule configuration reviews</td></tr><tr><td>Ignored logs</td><td>Suspicious activity can go unnoticed</td><td>Monitor relevant events</td></tr><tr><td>Unusual sign-ins</td><td>May indicate unauthorized access</td><td>Investigate anomalies</td></tr><tr><td>Unclassified data</td><td>Sensitive information may be overexposed</td><td>Classify important data</td></tr><tr><td>Untested recovery</td><td>Recovery may fail when needed</td><td>Test procedures</td></tr><tr><td>No assigned owner</td><td>Problems remain unresolved</td><td>Assign responsibility</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">A Practical Review Schedule for Small Businesses</h2>



<p class="wp-block-paragraph">A useful cloud security checklist should not sit in a document that nobody opens after the initial setup. Reviews should match the pace of the business.</p>



<p class="wp-block-paragraph"><strong>Monthly:</strong> Check administrator accounts, former employee accounts, unusual sign-ins, external sharing, forwarding rules, and newly connected applications.</p>



<p class="wp-block-paragraph"><strong>Quarterly:</strong> Review permissions, <a target="_blank" rel="noopener" href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/"><strong>Conditional Access</strong></a> policies, recovery information, device access, cloud storage sharing, and important administrative changes.</p>



<p class="wp-block-paragraph"><strong>After major changes:</strong> Review access whenever someone joins or leaves, a major application is introduced, a department changes responsibilities, or business-critical data moves between systems.</p>



<p class="wp-block-paragraph">This approach makes configuration security part of normal IT administration instead of a once-a-year exercise.</p>



<h2 class="wp-block-heading">What Should Small Businesses Prioritize First?</h2>



<p class="wp-block-paragraph">Not every business has the same exposure. A 10-person professional services firm, an online retailer, and a construction company may use different applications and store different types of information. Still, several controls deserve early attention.</p>



<p class="wp-block-paragraph">Start with administrator accounts and MFA. Then review former employees, excessive permissions, external file sharing, connected applications, email forwarding, and recovery settings. After those areas are addressed, examine device access, logging, Conditional Access, and data handling.</p>



<p class="wp-block-paragraph">This order helps businesses address high-impact configuration issues before spending time on less urgent improvements.</p>



<h2 class="wp-block-heading">FAQ About Cloud Security for Small Businesses</h2>



<h3 class="wp-block-heading">What is cloud security for small business?</h3>



<p class="wp-block-paragraph">It is the process of protecting cloud accounts, applications, business data, devices, permissions, and configurations from unauthorized access or misuse. It includes identity controls, sharing settings, administrative permissions, monitoring, and recovery planning.</p>



<h3 class="wp-block-heading">What are the biggest cloud security risks for small businesses?</h3>



<p class="wp-block-paragraph">Common risks include stolen credentials, excessive permissions, inactive employee accounts, broad file sharing, unauthorized application access, weak administrator controls, poor recovery settings, and overlooked cloud configurations.</p>



<h3 class="wp-block-heading">How often should a small business review its cloud settings?</h3>



<p class="wp-block-paragraph">A basic review should happen regularly, with monthly checks for important account and access changes and deeper quarterly reviews. Major employee, application, or system changes should also trigger an immediate review.</p>



<h3 class="wp-block-heading">Is Microsoft 365 secure for a small business?</h3>



<p class="wp-block-paragraph">Microsoft 365 provides many built-in controls, but the security of an environment also depends on how those controls are configured and maintained. Administrator roles, MFA, Conditional Access, sharing policies, application permissions, and audit settings deserve regular review.</p>



<h3 class="wp-block-heading">Does Google Workspace need a security review?</h3>



<p class="wp-block-paragraph">Yes. Google Workspace security depends partly on how administrators configure accounts, verification requirements, sharing, connected applications, recovery options, and other controls. A review can identify settings that no longer fit the organization&#8217;s needs.</p>



<h2 class="wp-block-heading">Close the Gaps Before They Become Openings</h2>



<p class="wp-block-paragraph">Attackers do not always need a sophisticated route into a business. An overlooked administrator account, an old application permission, an unrestricted sharing link, or a forgotten mailbox rule can create the opening they need.</p>



<p class="wp-block-paragraph">A strong small business cloud security program starts with visibility. Know which accounts exist, who can access sensitive information, which applications are connected, what external parties can access, and which settings control those permissions. Then review those configurations consistently as the business changes.</p>



<p class="wp-block-paragraph"><strong>Franklin Web Technologies</strong> can help businesses assess overlooked cloud configurations and identify practical areas for improvement. If your company relies on Microsoft 365, Google Workspace, or other cloud platforms, a focused configuration review can provide a clear picture of where access controls need attention and what should be addressed first.</p>



<p class="wp-block-paragraph">Do not wait for an unusual login or unexpected data exposure to reveal a forgotten setting. Use the 20-point review above as a starting point, assign ownership, and make cloud configuration checks part of your regular IT routine.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [{
    "@type": "Question",
    "name": "What is cloud security for small business?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "It is the process of protecting cloud accounts, applications, business data, devices, permissions, and configurations from unauthorized access or misuse. It includes identity controls, sharing settings, administrative permissions, monitoring, and recovery planning."
    }
  },{
    "@type": "Question",
    "name": "What are the biggest cloud security risks for small businesses?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Common risks include stolen credentials, excessive permissions, inactive employee accounts, broad file sharing, unauthorized application access, weak administrator controls, poor recovery settings, and overlooked cloud configurations."
    }
  },{
    "@type": "Question",
    "name": "How often should a small business review its cloud settings?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "A basic review should happen regularly, with monthly checks for important account and access changes and deeper quarterly reviews. Major employee, application, or system changes should also trigger an immediate review."
    }
  },{
    "@type": "Question",
    "name": "Is Microsoft 365 secure for a small business?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Microsoft 365 provides many built-in controls, but the security of an environment also depends on how those controls are configured and maintained. Administrator roles, MFA, Conditional Access, sharing policies, application permissions, and audit settings deserve regular review."
    }
  },{
    "@type": "Question",
    "name": "Does Google Workspace need a security review?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Yes. Google Workspace security depends partly on how administrators configure accounts, verification requirements, sharing, connected applications, recovery options, and other controls. A review can identify settings that no longer fit the organization's needs."
    }
  }]
}
</script>



<p class="wp-block-paragraph"></p>
<p>Read more at <a href="https://franklinwebtech.com/cloud-security-for-small-business-20-security-gaps-attackers-look-for-first/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MFA vs Conditional Access: What Does Your Small Business Actually Need?</title>
		<link>https://franklinwebtech.com/mfa-vs-conditional-access-what-does-your-small-business-actually-need/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Conditional Access]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[account takeover prevention]]></category>
		<category><![CDATA[MFA vs Conditional Access]]></category>
		<category><![CDATA[Microsoft 365 login security]]></category>
		<category><![CDATA[Microsoft 365 MFA]]></category>
		<category><![CDATA[Microsoft Entra Conditional Access]]></category>
		<category><![CDATA[small business cybersecurity]]></category>
		<category><![CDATA[Zero Trust access control]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2137</guid>

					<description><![CDATA[Small businesses often need more than a simple password to protect Microsoft 365 accounts, but adding every available control can create unnecessary cost and complexity. The practical answer to MFA vs Conditional Access is that they serve different purposes: multi factor authentication verifies a user&#8217;s identity with an additional factor, while Conditional Access decides when [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/mfa-vs-conditional-access-what-does-your-small-business-actually-need/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Small businesses often need more than a simple password to protect Microsoft 365 accounts, but adding every available control can create unnecessary cost and complexity. The practical answer to <strong>MFA vs Conditional Access</strong> is that they serve different purposes: multi factor authentication verifies a user&#8217;s identity with an additional factor, while Conditional Access decides when and under what conditions that user can access a resource. Many businesses should start with MFA and add Conditional Access as their access rules become more specific. <a target="_blank" rel="noopener" href="https://franklinwebtech.com/"><strong>Franklin Web Technologies</strong></a> can help businesses assess which controls fit their Microsoft 365 environment and day-to-day access needs.</p>



<h2 class="wp-block-heading">MFA and Conditional Access Solve Different Problems</h2>



<p class="wp-block-paragraph">MFA and Conditional Access are sometimes treated as competing options, but they are better understood as two layers of access control.</p>



<p class="wp-block-paragraph">MFA asks, &#8220;Can this person prove they are the account owner?&#8221; A user may enter a password and then approve a sign-in through an authenticator app, use a security key, or provide another approved verification method. The additional step makes a stolen password less useful on its own.</p>



<p class="wp-block-paragraph">Conditional Access asks, &#8220;Should this person be allowed to sign in under these specific circumstances?&#8221; It can evaluate signals such as the user, application, device, location, and sign-in risk before applying an access decision.</p>



<p class="wp-block-paragraph">That distinction matters for small businesses. MFA provides a strong baseline for account protection. Conditional Access gives administrators more control over the circumstances in which access is permitted, blocked, or subject to an additional requirement.</p>



<h2 class="wp-block-heading">What Does MFA Actually Do?</h2>



<p class="wp-block-paragraph">Multi factor authentication adds another verification requirement to the login process. Instead of relying only on a password, the user must provide another approved factor.</p>



<p class="wp-block-paragraph">For example, an employee might enter their password and then approve a notification in Microsoft Authenticator. If someone obtains the password but cannot complete the second verification step, the login attempt can be stopped.</p>



<p class="wp-block-paragraph">MFA is especially useful for businesses that want a practical improvement without creating a large set of access rules. It can help with:</p>



<ul class="wp-block-list">
<li>Reducing the value of stolen passwords</li>



<li>Improving Microsoft 365 login protection</li>



<li>Supporting account takeover prevention</li>



<li>Adding an extra identity check for employees and administrators</li>
</ul>



<p class="wp-block-paragraph">MFA should generally be considered a baseline control for Microsoft 365 accounts, particularly for accounts with access to email, files, financial information, customer records, or administrative settings.</p>



<p class="wp-block-paragraph">However, MFA does not by itself decide that a familiar user on an unmanaged device should be blocked from accessing sensitive information. That requires additional access policies.</p>



<h2 class="wp-block-heading">What Does Conditional Access Add?</h2>



<p class="wp-block-paragraph"><a target="_blank" rel="noopener" href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/"><strong>Conditional Access</strong></a> provides policy-based control over access to Microsoft cloud resources. Microsoft 365 administrators can create rules that evaluate the circumstances surrounding a sign-in and then apply a requirement.</p>



<p class="wp-block-paragraph">For example, a business could require MFA for administrative accounts, block access from specific locations, or require an approved device for access to certain applications.</p>



<p class="wp-block-paragraph">A Conditional Access policy can be designed around several signals, including:</p>



<p class="wp-block-paragraph"><strong>Users and groups:</strong> Apply different rules to administrators, contractors, executives, or general employees.</p>



<p class="wp-block-paragraph"><strong>Cloud applications:</strong> Apply stricter requirements to selected Microsoft 365 services or applications.</p>



<p class="wp-block-paragraph"><strong>Device conditions:</strong> Require a compliant or managed device for specific resources.</p>



<p class="wp-block-paragraph"><strong>Location:</strong> Apply different controls to trusted and untrusted network locations.</p>



<p class="wp-block-paragraph"><strong>Risk signals:</strong> Use risky login policies to respond to sign-in or user risk signals when the appropriate Microsoft Entra capabilities and licensing are available.</p>



<p class="wp-block-paragraph">This makes Conditional Access particularly useful for businesses with employees working from different locations, using company-managed devices, accessing sensitive resources, or handling different levels of information.</p>



<h2 class="wp-block-heading">MFA vs Conditional Access: A Practical Comparison</h2>



<p class="wp-block-paragraph">The simplest way to distinguish the two is to think of MFA as an <strong>identity verification control</strong> and Conditional Access as an <strong>access decision framework</strong>.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Factor</th><th>MFA</th><th>Conditional Access</th></tr><tr><td>Main purpose</td><td>Verify the user&#8217;s identity with an additional factor</td><td>Apply access rules based on sign-in conditions</td></tr><tr><td>Primary question</td><td>&#8220;Is this really the user?&#8221;</td><td>&#8220;Should access be allowed under these conditions?&#8221;</td></tr><tr><td>Password protection</td><td>Strong</td><td>Strong when combined with MFA</td></tr><tr><td>Device-based rules</td><td>Limited on its own</td><td>Yes</td></tr><tr><td>Location-based rules</td><td>No</td><td>Yes</td></tr><tr><td>Application-specific rules</td><td>Limited</td><td>Yes</td></tr><tr><td>Risk-based policies</td><td>Not the main function</td><td>Yes, with supported Microsoft Entra capabilities</td></tr><tr><td>Ease of deployment</td><td>Generally simpler</td><td>Requires policy planning and testing</td></tr><tr><td>Best starting point</td><td>Most businesses</td><td>Businesses needing more precise access controls</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">The two controls are not normally an either-or decision. Conditional Access can actually be configured to require MFA when certain conditions are met.</p>



<h2 class="wp-block-heading">When Should a Small Business Use MFA?</h2>



<p class="wp-block-paragraph">MFA is the logical starting point for a small business that currently relies heavily on passwords.</p>



<p class="wp-block-paragraph">Consider a 12-person accounting firm where employees use Microsoft 365 email, OneDrive, and Teams. Staff work primarily from company-managed laptops and do not need different access rules for different locations.</p>



<p class="wp-block-paragraph">The business may not need a large collection of access policies immediately. Requiring MFA for user accounts can provide a significant improvement while keeping administration manageable.</p>



<p class="wp-block-paragraph">MFA is also useful when:</p>



<p class="wp-block-paragraph"><strong>Your main concern is stolen passwords.</strong> MFA adds another verification step after the password.</p>



<p class="wp-block-paragraph"><strong>You need a simple baseline.</strong> Businesses without dedicated IT staff may benefit from beginning with a straightforward control.</p>



<p class="wp-block-paragraph"><strong>Most employees have similar access needs.</strong> If users generally access the same services under similar conditions, complex policies may not provide much additional value at first.</p>



<p class="wp-block-paragraph"><strong>You are securing administrative accounts.</strong> Administrator accounts deserve particularly strong login controls because they can affect other users, applications, and settings.</p>



<h2 class="wp-block-heading">When Does Conditional Access Make More Sense?</h2>



<p class="wp-block-paragraph">Conditional Access becomes more valuable as a business needs to distinguish between different access situations.</p>



<p class="wp-block-paragraph">Imagine a 40-person consulting company with employees working from offices, client locations, and home. Staff use company laptops, but contractors occasionally need access to selected Microsoft 365 resources.</p>



<p class="wp-block-paragraph">A single MFA requirement does not address every access scenario. The company may want employees using approved devices to access internal resources normally while applying stricter requirements to unmanaged devices or higher-risk sign-ins.</p>



<p class="wp-block-paragraph">Conditional Access can help create those distinctions.</p>



<p class="wp-block-paragraph">It is a strong fit when your business needs:</p>



<p class="wp-block-paragraph"><strong>Different rules for different users.</strong> Administrators and contractors may require different access conditions.</p>



<p class="wp-block-paragraph"><strong>Device controls.</strong> Access to selected resources can depend on device compliance or management status.</p>



<p class="wp-block-paragraph"><strong>Application-specific requirements.</strong> Sensitive applications can receive stricter policies than general services.</p>



<p class="wp-block-paragraph"><strong>Location controls.</strong> Certain access attempts can receive additional requirements or be blocked based on configured locations.</p>



<p class="wp-block-paragraph"><strong>Risk-based decisions.</strong> Supported Microsoft Entra risk signals can help organizations apply additional controls to suspicious sign-ins.</p>



<p class="wp-block-paragraph">For businesses using Microsoft 365 extensively, Conditional Access Microsoft 365 policies can provide much more precise control than a single MFA requirement.</p>



<h2 class="wp-block-heading">Real SMB Scenarios</h2>



<h3 class="wp-block-heading">A Small Retail Business</h3>



<p class="wp-block-paragraph">A 10-person retailer uses Microsoft 365 for email, calendars, and documents. Employees work from one primary location and use a mix of company and personal devices.</p>



<p class="wp-block-paragraph"><strong>Recommended starting point:</strong> MFA for all users, with stronger protection for administrator accounts.</p>



<p class="wp-block-paragraph">Conditional Access can be considered later if the business needs device restrictions, location rules, or different access requirements.</p>



<h3 class="wp-block-heading">A Professional Services Firm</h3>



<p class="wp-block-paragraph">A 30-person firm has employees working remotely and from client offices. Some users regularly access confidential client documents.</p>



<p class="wp-block-paragraph"><strong>Recommended approach:</strong> MFA plus carefully designed Conditional Access policies.</p>



<p class="wp-block-paragraph">The business could require MFA for users, apply device requirements to sensitive resources, and create additional controls for administrative accounts.</p>



<h3 class="wp-block-heading">A Business With Contractors</h3>



<p class="wp-block-paragraph">A small technology company uses employees and external contractors. Contractors only need access to selected Microsoft 365 resources.</p>



<p class="wp-block-paragraph"><strong>Recommended approach:</strong> MFA combined with Conditional Access.</p>



<p class="wp-block-paragraph">Conditional Access can help apply different access requirements to contractor accounts and restrict access to selected applications.</p>



<h3 class="wp-block-heading">A Business Concerned About Risky Sign-ins</h3>



<p class="wp-block-paragraph">A business has noticed unusual login activity and wants additional controls beyond standard MFA.</p>



<p class="wp-block-paragraph"><strong>Recommended approach:</strong> MFA plus risk-based Conditional Access policies, using supported Microsoft Entra capabilities and appropriate licensing.</p>



<p class="wp-block-paragraph">The objective is not simply to add more prompts. It is to make access decisions based on the conditions surrounding a sign-in.</p>



<h2 class="wp-block-heading">SMB Decision Matrix</h2>



<p class="wp-block-paragraph">Use this matrix to identify the most appropriate starting point:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Business situation</th><th>MFA</th><th>Conditional Access</th><th>Recommended approach</th></tr><tr><td>Password-only Microsoft 365 accounts</td><td>High priority</td><td>Not required initially</td><td>Start with MFA</td></tr><tr><td>Small team with similar access needs</td><td>High priority</td><td>Optional</td><td>MFA may be sufficient</td></tr><tr><td>Remote employees using different devices</td><td>High priority</td><td>High priority</td><td>Use both</td></tr><tr><td>Contractors need limited access</td><td>High priority</td><td>High priority</td><td>Use both</td></tr><tr><td>Sensitive applications need stricter rules</td><td>High priority</td><td>High priority</td><td>Use both</td></tr><tr><td>Device compliance matters</td><td>High priority</td><td>High priority</td><td>Use both</td></tr><tr><td>Risk signals need policy-based responses</td><td>High priority</td><td>High priority</td><td>Use both where supported</td></tr><tr><td>Business has very limited IT administration</td><td>High priority</td><td>Add gradually</td><td>Begin with MFA</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">The matrix points to a useful rule: <strong>MFA is usually the starting control, while Conditional Access becomes valuable when the business needs context-based access decisions.</strong></p>



<h2 class="wp-block-heading">How to Avoid Overcomplicating Conditional Access</h2>



<p class="wp-block-paragraph">Conditional Access can be powerful, but poorly planned policies can create access problems. A business should avoid creating numerous rules simply because the technology allows it.</p>



<p class="wp-block-paragraph">Start by identifying the accounts, applications, devices, and access situations that matter most. Build a small number of clear policies around those needs.</p>



<p class="wp-block-paragraph">Test policies with appropriate users before applying them broadly. Keep emergency administrative access considerations in mind, and document why each policy exists.</p>



<p class="wp-block-paragraph">It also helps to review policies after major changes, such as introducing remote work, allowing contractors, deploying managed devices, or adding sensitive applications.</p>



<p class="wp-block-paragraph">Franklin Web Technologies can support this type of review by helping businesses connect access controls to actual operational requirements instead of adding rules without a clear purpose.</p>



<h2 class="wp-block-heading">Do You Need MFA and Conditional Access Together?</h2>



<p class="wp-block-paragraph">For many businesses, the strongest setup is not MFA <strong>or</strong> Conditional Access. It is MFA <strong>with</strong> Conditional Access.</p>



<p class="wp-block-paragraph">A Conditional Access policy can require MFA only when a particular condition exists. For example, an organization could require MFA for a specific application, apply stronger requirements to administrators, or respond to a higher-risk sign-in.</p>



<p class="wp-block-paragraph">This layered model allows the business to keep MFA as a baseline while using Conditional Access for more precise decisions.</p>



<p class="wp-block-paragraph">The right configuration depends on the organization&#8217;s Microsoft 365 licensing, applications, users, device management, and access requirements. Some Conditional Access and risk-based capabilities require specific Microsoft Entra licensing, so licensing should be checked before planning the final policy set.</p>



<h2 class="wp-block-heading">Common Mistakes Small Businesses Should Avoid</h2>



<p class="wp-block-paragraph">The biggest mistake is treating MFA as a complete answer to every access problem. MFA improves identity verification, but it does not replace access policies.</p>



<p class="wp-block-paragraph">Another mistake is creating Conditional Access rules without first documenting the business requirement behind each one. A policy should have a clear purpose, such as requiring MFA for administrators or restricting access from unmanaged devices.</p>



<p class="wp-block-paragraph">Businesses should also avoid changing multiple policies at once without testing. A single poorly configured rule can affect many users.</p>



<p class="wp-block-paragraph">Finally, do not overlook administrator accounts. A small number of highly privileged accounts can have a much greater impact than ordinary user accounts, so they deserve careful access controls and monitoring.</p>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h3 class="wp-block-heading">Is MFA better than Conditional Access?</h3>



<p class="wp-block-paragraph">Neither control is a direct replacement for the other. MFA verifies identity using an additional factor, while Conditional Access determines access based on configured conditions. Most businesses should consider MFA a baseline and add Conditional Access when they need more precise rules.</p>



<h3 class="wp-block-heading">Can Conditional Access require MFA?</h3>



<p class="wp-block-paragraph">Yes. Conditional Access policies can require MFA as a condition for accessing selected Microsoft resources or under specified sign-in circumstances. This is one reason the two controls often work together.</p>



<h3 class="wp-block-heading">Does Conditional Access replace MFA?</h3>



<p class="wp-block-paragraph">No. Conditional Access can use MFA as one of its requirements, but it does not replace the authentication method itself. A business can use Conditional Access to determine when MFA should be required.</p>



<h3 class="wp-block-heading">Is Conditional Access necessary for a small business?</h3>



<p class="wp-block-paragraph">Not every small business needs a complex Conditional Access setup. A small company with straightforward access requirements may begin with MFA. Conditional Access becomes more useful as the organization needs device, location, application, user, or risk-based access rules.</p>



<h3 class="wp-block-heading">What is the difference between MFA and identity access management?</h3>



<p class="wp-block-paragraph">MFA is one type of identity and access control focused on verifying users through multiple factors. Identity access management is a broader discipline covering how users are identified, authenticated, authorized, and managed across systems and resources.</p>



<h3 class="wp-block-heading">Can MFA prevent account takeover?</h3>



<p class="wp-block-paragraph">MFA can significantly reduce the usefulness of a stolen password because an attacker may still need the additional authentication factor. It should be combined with appropriate account, device, and access controls for stronger protection.</p>



<h2 class="wp-block-heading">Choose the Control That Matches the Business Need</h2>



<p class="wp-block-paragraph">MFA and Conditional Access should not be viewed as competing products. They address different parts of the login and access process. MFA confirms more strongly that the person signing in is the legitimate account holder. Conditional Access determines what should happen based on the circumstances of that sign-in.</p>



<p class="wp-block-paragraph">For a small business starting with basic Microsoft 365 protection, MFA is usually the first practical step. Businesses with remote workers, contractors, managed devices, sensitive applications, or more complex access requirements can add Conditional Access to create more specific rules.</p>



<p class="wp-block-paragraph">A focused policy set is usually more useful than a large collection of rules that nobody fully understands. Review the business&#8217;s users, devices, applications, and access patterns first, then build controls around those real requirements. If you need help assessing your Microsoft 365 environment or planning an access policy structure, <a target="_blank" rel="noopener" href="https://franklinwebtech.com/contact/"><strong>contact us for guidance</strong></a> on choosing an approach that fits your organization.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [{
    "@type": "Question",
    "name": "Is MFA better than Conditional Access?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Neither control is a direct replacement for the other. MFA verifies identity using an additional factor, while Conditional Access determines access based on configured conditions. Most businesses should consider MFA a baseline and add Conditional Access when they need more precise rules."
    }
  },{
    "@type": "Question",
    "name": "Can Conditional Access require MFA?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Yes. Conditional Access policies can require MFA as a condition for accessing selected Microsoft resources or under specified sign-in circumstances. This is one reason the two controls often work together."
    }
  },{
    "@type": "Question",
    "name": "Does Conditional Access replace MFA?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "No. Conditional Access can use MFA as one of its requirements, but it does not replace the authentication method itself. A business can use Conditional Access to determine when MFA should be required."
    }
  },{
    "@type": "Question",
    "name": "Is Conditional Access necessary for a small business?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Not every small business needs a complex Conditional Access setup. A small company with straightforward access requirements may begin with MFA. Conditional Access becomes more useful as the organization needs device, location, application, user, or risk-based access rules."
    }
  },{
    "@type": "Question",
    "name": "What is the difference between MFA and identity access management?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "MFA is one type of identity and access control focused on verifying users through multiple factors. Identity access management is a broader discipline covering how users are identified, authenticated, authorized, and managed across systems and resources."
    }
  },{
    "@type": "Question",
    "name": "Can MFA prevent account takeover?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "MFA can significantly reduce the usefulness of a stolen password because an attacker may still need the additional authentication factor. It should be combined with appropriate account, device, and access controls for stronger protection."
    }
  }]
}
</script>
<p>Read more at <a href="https://franklinwebtech.com/mfa-vs-conditional-access-what-does-your-small-business-actually-need/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DMARC, SPF and DKIM Explained: How to Protect Your Business Email From Spoofing</title>
		<link>https://franklinwebtech.com/dmarc-spf-and-dkim-explained/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 09:51:40 +0000</pubDate>
				<category><![CDATA[DKIM and DMARC for Google]]></category>
		<category><![CDATA[business email security]]></category>
		<category><![CDATA[DKIM signature]]></category>
		<category><![CDATA[DMARC policy]]></category>
		<category><![CDATA[DMARC SPF DKIM]]></category>
		<category><![CDATA[email authentication]]></category>
		<category><![CDATA[email spoofing prevention]]></category>
		<category><![CDATA[SPF]]></category>
		<category><![CDATA[SPF record]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2136</guid>

					<description><![CDATA[How Do DMARC, SPF and DKIM Protect Business Email? DMARC, SPF and DKIM help receiving email systems confirm whether a message claiming to come from your business domain is properly authenticated. Together, they can reduce domain spoofing, support email deliverability, and give businesses more control over how their domains are used for email. This guide [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/dmarc-spf-and-dkim-explained/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">How Do DMARC, SPF and DKIM Protect Business Email?</h2>



<p class="wp-block-paragraph">DMARC, SPF and DKIM help receiving email systems confirm whether a message claiming to come from your business domain is properly authenticated. Together, they can reduce domain spoofing, support email deliverability, and give businesses more control over how their domains are used for email.</p>



<p class="wp-block-paragraph">This guide explains <strong>DMARC, SPF and DKIM</strong>, what each email authentication standard does, how they work together, common DNS setup mistakes, and practical steps businesses can take to improve their email security.</p>



<p class="wp-block-paragraph">For an SMB owner, marketing team, or IT administrator, these records are more than technical DNS settings. They can affect email delivery, brand trust, and protection against messages that try to impersonate your company.</p>



<p class="wp-block-paragraph">When managing several email systems becomes difficult, <a target="_blank" rel="noopener" href="https://franklinwebtech.com/"><strong>Franklin Web Technologies</strong></a> can help businesses review their domain and email configuration and identify authentication gaps.</p>



<h2 class="wp-block-heading">What Are SPF, DKIM and DMARC?</h2>



<p class="wp-block-paragraph">SPF, DKIM and DMARC solve different parts of the email authentication process.</p>



<p class="wp-block-paragraph">SPF helps identify which systems are allowed to send email for a domain. DKIM adds a digital signature that receiving systems can verify. DMARC connects those authentication results to the domain shown in the visible From address and provides a policy for handling authentication failures.</p>



<p class="wp-block-paragraph">Using all three provides a stronger foundation than relying on only one authentication method.</p>



<h3 class="wp-block-heading">What Is SPF?</h3>



<p class="wp-block-paragraph"><strong>SPF, or Sender Policy Framework,</strong> is a DNS-based email authentication method that lists the systems allowed to send email for a domain.</p>



<p class="wp-block-paragraph">For example, a business may send email through Microsoft 365, a CRM, and a marketing platform. The SPF record should include the approved services that are allowed to send messages for that domain.</p>



<p class="wp-block-paragraph">A simplified SPF record might look like:</p>



<pre class="wp-block-code"><code>v=spf1 include:spf.protection.outlook.com include:mail.example.com -all</code></pre>



<p class="wp-block-paragraph">When a message reaches a receiving mail server, the server checks the sending IP address against the SPF policy for the email&#8217;s envelope sender domain.</p>



<p class="wp-block-paragraph">The <code>-all</code> part means that sending sources not included in the SPF policy should fail the SPF check.</p>



<p class="wp-block-paragraph">The exact SPF record will depend on the services your business uses.</p>



<p class="wp-block-paragraph">SPF is useful, but it has an important limitation. It does not directly authenticate the visible From address that a person normally sees in their inbox. Email forwarding can also cause SPF authentication problems.</p>



<p class="wp-block-paragraph">This is one reason DKIM and DMARC are important.</p>



<h3 class="wp-block-heading">What Is DKIM?</h3>



<p class="wp-block-paragraph"><strong>DKIM, or DomainKeys Identified Mail,</strong> adds a digital signature to outgoing email.</p>



<p class="wp-block-paragraph">The sending email service uses a private key to create the signature. A matching public key is published in your domain&#8217;s DNS records.</p>



<p class="wp-block-paragraph">A simplified DKIM DNS record may look like:</p>



<pre class="wp-block-code"><code>Host: selector1._domainkey.example.com
Type: TXT

Value: v=DKIM1; k=rsa; p=PUBLIC_KEY_VALUE</code></pre>



<p class="wp-block-paragraph">When the message reaches another email provider, the receiving system finds the public key in DNS and uses it to verify the DKIM signature.</p>



<p class="wp-block-paragraph">A valid DKIM result shows that the email contains a valid signature connected to the signing domain. It also helps confirm that the signed parts of the message have not been changed in a way that breaks the signature.</p>



<p class="wp-block-paragraph">Your email provider normally creates the DKIM keys and provides the DNS information you need to publish.</p>



<p class="wp-block-paragraph">The selector, key length, hostname, and exact DNS value will depend on your provider.</p>



<h3 class="wp-block-heading">What Is DMARC?</h3>



<p class="wp-block-paragraph"><strong>DMARC, or Domain-based Message Authentication, Reporting and Conformance,</strong> connects SPF and DKIM authentication with the domain shown in the visible From address.</p>



<p class="wp-block-paragraph">For DMARC to pass, at least one supported authentication method must pass with proper domain alignment.</p>



<p class="wp-block-paragraph">In simple terms:</p>



<ul class="wp-block-list">
<li>SPF can pass and align with the From domain.</li>



<li>DKIM can pass and align with the From domain.</li>



<li>If the required authentication and alignment conditions are met, DMARC can pass.</li>
</ul>



<p class="wp-block-paragraph">DMARC also allows the domain owner to publish a policy requesting how receiving email systems should treat messages that fail DMARC.</p>



<p class="wp-block-paragraph">A basic DMARC record could look like:</p>



<pre class="wp-block-code"><code>Host: _dmarc.example.com
Type: TXT

Value: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com</code></pre>



<p class="wp-block-paragraph">Common DMARC policies include:</p>



<ul class="wp-block-list">
<li><code>p=none</code> — Used mainly for monitoring. No quarantine or rejection action is requested by the DMARC policy.</li>



<li><code>p=quarantine</code> — Requests that messages failing DMARC be treated as suspicious.</li>



<li><code>p=reject</code> — Requests the strongest handling for messages that fail DMARC.</li>
</ul>



<p class="wp-block-paragraph">Receiving providers can still use their own spam, security, reputation, and filtering systems when deciding what to do with a message.</p>



<p class="wp-block-paragraph">DMARC reports can also give domain administrators useful information about which systems are sending email using their domain and where authentication problems may exist.</p>



<h2 class="wp-block-heading">What Changed With DMARC in 2026?</h2>



<p class="wp-block-paragraph">DMARC guidance was updated in 2026 with the publication of <strong>RFC 9989</strong>, the current Standards Track specification for DMARC.</p>



<p class="wp-block-paragraph">One important point is that businesses should not think of <code>p=reject</code> as the automatic final step for every domain.</p>



<p class="wp-block-paragraph">Strict rejection can create problems with some legitimate email flows, including forwarded messages and mailing lists. For this reason, a business should understand how its email is being sent and forwarded before using a strict DMARC policy.</p>



<p class="wp-block-paragraph">The safest approach is to review legitimate sending systems, monitor authentication results, fix alignment problems, and then decide which DMARC policy makes sense for the domain.</p>



<p class="wp-block-paragraph">This is especially important for businesses using several email platforms, third-party senders, automated systems, forwarding services, or mailing lists.</p>



<h2 class="wp-block-heading">How SPF, DKIM and DMARC Work Together</h2>



<p class="wp-block-paragraph">SPF, DKIM and DMARC are connected email authentication methods rather than competing technologies.</p>



<p class="wp-block-paragraph">A simplified process looks like this:</p>



<pre class="wp-block-code"><code>Business sends email
        |
        v
Receiving mail server receives message
        |
        +----------------------+
        |                      |
        v                      v
     SPF check             DKIM check
        |                      |
        +----------+-----------+
                   |
                   v
            DMARC alignment
                   |
                   v
       Does SPF or DKIM pass
         with proper alignment?
                   |
          +--------+--------+
          |                 |
         YES                NO
          |                 |
          v                 v
 Authentication passes   Review DMARC policy
                         and receiver security
                              rules</code></pre>



<p class="wp-block-paragraph">The key point is that DMARC does not replace SPF or DKIM.</p>



<p class="wp-block-paragraph">Instead, DMARC uses authentication results and checks whether the authenticated domain properly aligns with the domain shown in the From address.</p>



<p class="wp-block-paragraph">Together, these technologies provide stronger <strong>email spoofing protection</strong> for domains used by employees, sales teams, customer service departments, marketing systems, and automated business applications.</p>



<h2 class="wp-block-heading">A Practical SPF, DKIM and DMARC DNS Example</h2>



<p class="wp-block-paragraph">Consider a business using <code>example.com</code> for employee email while also using a separate provider to send newsletters.</p>



<p class="wp-block-paragraph">Its DNS configuration might include the following records.</p>



<p class="wp-block-paragraph"><strong>SPF</strong></p>



<pre class="wp-block-code"><code>example.com TXT
v=spf1 include:spf.protection.outlook.com include:newsletter-provider.com -all</code></pre>



<p class="wp-block-paragraph">The SPF record identifies the approved sending services.</p>



<p class="wp-block-paragraph"><strong>DKIM</strong></p>



<pre class="wp-block-code"><code>selector1._domainkey.example.com TXT
v=DKIM1; k=rsa; p=PUBLIC_KEY_VALUE</code></pre>



<p class="wp-block-paragraph">The DKIM record provides the public key that receiving systems can use to verify signed email.</p>



<p class="wp-block-paragraph"><strong>DMARC</strong></p>



<pre class="wp-block-code"><code>_dmarc.example.com TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com</code></pre>



<p class="wp-block-paragraph">The DMARC record publishes the domain&#8217;s policy and provides an address where supported aggregate reports may be sent.</p>



<p class="wp-block-paragraph">These are simplified examples only.</p>



<p class="wp-block-paragraph">The actual DNS values should come from your email provider, CRM, marketing platform, or other sending service. Copying an SPF, DKIM, or DMARC record from another company&#8217;s domain can cause authentication or delivery problems.</p>



<h2 class="wp-block-heading">SPF vs DKIM vs DMARC</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>Standard</th><th>Main Purpose</th><th>Published In</th><th>Main Check</th><th>Policy Control</th></tr><tr><td><strong>SPF</strong></td><td>Identifies approved sending infrastructure</td><td>DNS TXT</td><td>Sending IP and envelope sender</td><td>No</td></tr><tr><td><strong>DKIM</strong></td><td>Adds a verifiable domain signature</td><td>DNS TXT</td><td>Digital message signature</td><td>No</td></tr><tr><td><strong>DMARC</strong></td><td>Connects authentication with From-domain alignment</td><td>DNS TXT</td><td>SPF/DKIM alignment</td><td>Yes</td></tr></tbody></table></figure>



<p class="wp-block-paragraph">The three standards perform different jobs.</p>



<p class="wp-block-paragraph">SPF helps answer:</p>



<p class="wp-block-paragraph"><strong>&#8220;Is this sending system authorized?&#8221;</strong></p>



<p class="wp-block-paragraph">DKIM helps answer:</p>



<p class="wp-block-paragraph"><strong>&#8220;Does this message have a valid signature connected to the signing domain?&#8221;</strong></p>



<p class="wp-block-paragraph">DMARC adds another question:</p>



<p class="wp-block-paragraph"><strong>&#8220;Does the authentication align with the domain shown in the From address, and what policy has the domain owner requested if it fails?&#8221;</strong></p>



<p class="wp-block-paragraph">This is why businesses should normally consider SPF, DKIM, and DMARC as parts of one email authentication strategy.</p>



<h2 class="wp-block-heading">Common SPF, DKIM and DMARC Configuration Mistakes</h2>



<p class="wp-block-paragraph">DNS changes may look simple, but small configuration errors can affect legitimate business email.</p>



<p class="wp-block-paragraph">Here are some of the most common problems.</p>



<h3 class="wp-block-heading">Creating Multiple SPF Records</h3>



<p class="wp-block-paragraph">A domain should have one SPF policy record.</p>



<p class="wp-block-paragraph">Creating separate SPF policy records for Microsoft 365, a CRM, a newsletter service, and other providers does not create several policies that automatically work together.</p>



<p class="wp-block-paragraph">Instead, legitimate sending services generally need to be included in one SPF policy.</p>



<p class="wp-block-paragraph">SPF also limits the number of DNS lookups that can be triggered during evaluation. The standard limit is <strong>10 DNS-based lookups</strong>.</p>



<p class="wp-block-paragraph">A complex SPF record that goes beyond this limit can create authentication failures.</p>



<h3 class="wp-block-heading">Forgetting Third-Party Email Platforms</h3>



<p class="wp-block-paragraph">A business may correctly configure authentication for Microsoft 365 or Google Workspace but forget other services that also send email.</p>



<p class="wp-block-paragraph">These may include:</p>



<ul class="wp-block-list">
<li>CRM systems</li>



<li>Newsletter platforms</li>



<li>Website contact forms</li>



<li>Customer support systems</li>



<li>Accounting platforms</li>



<li>Booking software</li>



<li>Ecommerce systems</li>



<li>Automated notification tools</li>
</ul>



<p class="wp-block-paragraph">If these services are not properly configured, legitimate messages may fail authentication.</p>



<p class="wp-block-paragraph">Create a complete list of every system that sends email using your domain before making major DNS changes.</p>



<h3 class="wp-block-heading">Publishing the Wrong DKIM Record</h3>



<p class="wp-block-paragraph">DKIM depends on the correct selector, hostname, and public key.</p>



<p class="wp-block-paragraph">Using the wrong selector, copying an incomplete key, publishing it under the wrong hostname, or missing part of the DNS value can cause DKIM verification to fail.</p>



<p class="wp-block-paragraph">Follow the setup instructions provided by your email or sending provider.</p>



<h3 class="wp-block-heading">Moving Too Quickly to a Strict DMARC Policy</h3>



<p class="wp-block-paragraph">A strict DMARC policy may be useful in some environments, but applying it without understanding your legitimate mail flows can cause delivery problems.</p>



<p class="wp-block-paragraph">Forwarding, mailing lists, and third-party sending platforms can make authentication more complex.</p>



<p class="wp-block-paragraph">Begin by understanding your sending environment and reviewing DMARC data before applying stronger enforcement.</p>



<h3 class="wp-block-heading">Forgetting About Subdomains</h3>



<p class="wp-block-paragraph">Businesses often use subdomains for marketing, support, transactions, and automated email.</p>



<p class="wp-block-paragraph">Examples include:</p>



<pre class="wp-block-code"><code>mail.example.com
support.example.com
news.example.com</code></pre>



<p class="wp-block-paragraph">Review how your DMARC policy applies to these subdomains.</p>



<p class="wp-block-paragraph">Also make sure that every service sending from a subdomain has the correct SPF and DKIM configuration where required.</p>



<h3 class="wp-block-heading">Leaving Old Sending Services in DNS</h3>



<p class="wp-block-paragraph">Businesses often change CRM, newsletter, or email providers but forget to remove the old service from their SPF configuration.</p>



<p class="wp-block-paragraph">Leaving unused sending systems authorized can create unnecessary risk and make your DNS configuration harder to manage.</p>



<p class="wp-block-paragraph">Review your records regularly and remove services you no longer use.</p>



<h2 class="wp-block-heading">How Businesses Can Set Up Email Authentication</h2>



<p class="wp-block-paragraph">Do not start by changing several DNS records at the same time.</p>



<p class="wp-block-paragraph">Start by identifying every system that sends email using your business domain.</p>



<p class="wp-block-paragraph">This may include employee email, website forms, CRMs, newsletters, accounting platforms, booking systems, support tools, ecommerce platforms, and automated notifications.</p>



<p class="wp-block-paragraph">Then work through the following steps.</p>



<ol class="wp-block-list">
<li><strong>Review your SPF record:</strong> Make sure all legitimate sending services are included and remove services you no longer use.</li>



<li><strong>Enable DKIM:</strong> Obtain the correct DKIM settings from each email provider or sending platform that supports domain signing.</li>



<li><strong>Publish DMARC:</strong> For many organizations, a monitoring policy such as <code>p=none</code> can be a useful starting point while legitimate mail sources are reviewed.</li>



<li><strong>Review DMARC reports:</strong> Look for unknown sending systems, SPF failures, DKIM failures, and domain alignment problems.</li>



<li><strong>Fix legitimate sending sources:</strong> Update DNS records or provider settings for systems that should be sending email.</li>



<li><strong>Review forwarding and mailing lists:</strong> Understand whether legitimate messages pass through systems that may change authentication results.</li>



<li><strong>Choose the appropriate DMARC policy:</strong> After testing and reviewing your email environment, determine whether <code>none</code>, <code>quarantine</code>, or <code>reject</code> is suitable for your domain.</li>



<li><strong>Continue monitoring:</strong> Email systems change over time. Review your authentication configuration whenever you add or remove a sending platform.</li>
</ol>



<p class="wp-block-paragraph">For businesses without dedicated DNS or email expertise, <strong>Franklin Web Technologies</strong> can help review existing records, identify configuration gaps, and plan changes carefully.</p>



<h2 class="wp-block-heading">Why Email Authentication Matters More for Businesses Today</h2>



<p class="wp-block-paragraph">A spoofed email may appear to come from a company executive, finance department, sales representative, support team, or trusted supplier.</p>



<p class="wp-block-paragraph">A recipient may see a familiar company domain and assume the message is legitimate.</p>



<p class="wp-block-paragraph">SPF, DKIM and DMARC give receiving email systems more information to determine whether a message claiming to come from your domain has been properly authenticated.</p>



<p class="wp-block-paragraph">These controls are also increasingly important for email delivery.</p>



<p class="wp-block-paragraph">Google requires senders to personal Gmail accounts to use SPF or DKIM authentication. Senders that send more than 5,000 messages per day to Gmail accounts must meet stronger requirements, including SPF, DKIM, and DMARC.</p>



<p class="wp-block-paragraph">Yahoo also requires stronger authentication practices for bulk senders, including SPF, DKIM, and a valid DMARC policy.</p>



<p class="wp-block-paragraph">For businesses sending newsletters, customer updates, promotions, automated messages, or large volumes of email, authentication is now an important part of both <strong>business email security</strong> and reliable email delivery.</p>



<h2 class="wp-block-heading">What SPF, DKIM and DMARC Cannot Protect Against</h2>



<p class="wp-block-paragraph">Email authentication is important, but it does not stop every email threat.</p>



<p class="wp-block-paragraph">SPF, DKIM and DMARC mainly help protect your actual domain from certain types of unauthorized use.</p>



<p class="wp-block-paragraph">They do not automatically stop attacks involving:</p>



<ul class="wp-block-list">
<li>Lookalike or newly registered domains</li>



<li>Display-name impersonation</li>



<li>Compromised legitimate email accounts</li>



<li>Malicious links inside authenticated messages</li>



<li>Malware sent from an authorized account</li>



<li>Social engineering attacks</li>



<li>Every type of business email compromise</li>
</ul>



<p class="wp-block-paragraph">For example, an attacker may register a domain that looks similar to your real business domain and send properly authenticated email from that domain.</p>



<p class="wp-block-paragraph">DMARC for your real domain cannot directly control another independently registered domain.</p>



<p class="wp-block-paragraph">This is why authentication should be one part of a wider <strong>phishing protection</strong> and email security strategy.</p>



<h2 class="wp-block-heading">SPF, DKIM and DMARC Are Not the Same as Spam Filtering</h2>



<p class="wp-block-paragraph">Email authentication and spam filtering perform different jobs.</p>



<p class="wp-block-paragraph">SPF, DKIM, and DMARC provide information about the identity and authentication of a message.</p>



<p class="wp-block-paragraph">Email providers can combine those signals with many other factors when deciding whether to deliver a message, send it to spam, block it, or apply additional checks.</p>



<p class="wp-block-paragraph">A message that passes DMARC is not automatically safe.</p>



<p class="wp-block-paragraph">An authorized or compromised account can still send unwanted or harmful email.</p>



<p class="wp-block-paragraph">In the same way, an email that fails authentication is not automatically an attack. A legitimate third-party platform or forwarded message may have an authentication or alignment problem.</p>



<p class="wp-block-paragraph">This is why DMARC works best as part of a broader email security strategy rather than as a single security control.</p>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h3 class="wp-block-heading">What is the difference between SPF, DKIM and DMARC?</h3>



<p class="wp-block-paragraph">SPF identifies systems that are allowed to send email for a domain. DKIM adds a digital signature that receiving systems can verify. DMARC checks whether SPF or DKIM authentication aligns with the domain shown in the From address and provides a policy for failed authentication.</p>



<h3 class="wp-block-heading">What happens if a domain does not have DMARC?</h3>



<p class="wp-block-paragraph">Without DMARC, the domain does not provide receiving systems with a DMARC policy or DMARC alignment instructions.</p>



<p class="wp-block-paragraph">SPF and DKIM can still provide authentication results, but DMARC connects those results with the visible From domain and can also provide reporting information.</p>



<h3 class="wp-block-heading">Is SPF enough without DKIM?</h3>



<p class="wp-block-paragraph">SPF alone is generally not the strongest approach for modern business email.</p>



<p class="wp-block-paragraph">Email forwarding and complex third-party sending arrangements can cause SPF problems. DKIM provides a separate authentication method, while DMARC can use properly aligned SPF or DKIM authentication.</p>



<p class="wp-block-paragraph">Using SPF and DKIM together gives businesses more options for successful authentication.</p>



<h3 class="wp-block-heading">Can I use DMARC without SPF?</h3>



<p class="wp-block-paragraph">DMARC can pass through properly aligned DKIM even when SPF does not provide an aligned pass.</p>



<p class="wp-block-paragraph">However, businesses should normally configure both SPF and DKIM when their email systems support them. Using both provides stronger and more flexible authentication.</p>



<h3 class="wp-block-heading">Why can SPF fail when an email is forwarded?</h3>



<p class="wp-block-paragraph">SPF checks the sending IP address against the SPF policy for the envelope sender domain.</p>



<p class="wp-block-paragraph">When an email is forwarded, the system sending the forwarded message may not be listed in the original domain&#8217;s SPF record. This can cause SPF to fail even when the original message was legitimate.</p>



<p class="wp-block-paragraph">DKIM can sometimes continue to verify through forwarding if the signed parts of the message have not been changed.</p>



<h3 class="wp-block-heading">What does <code>p=none</code> mean in DMARC?</h3>



<p class="wp-block-paragraph"><code>p=none</code> means the domain owner is not requesting quarantine or rejection based only on the DMARC policy.</p>



<p class="wp-block-paragraph">It is commonly used while businesses review authentication data and identify legitimate sending services.</p>



<p class="wp-block-paragraph">Receiving email providers can still use their own spam, security, and reputation systems when deciding how to handle the message.</p>



<h3 class="wp-block-heading">Should every business use <code>p=reject</code>?</h3>



<p class="wp-block-paragraph">Not automatically. A <code>p=reject</code> policy requests strict handling of messages that fail DMARC, but it may affect some legitimate forwarded messages, mailing lists, and other indirect email flows.</p>



<p class="wp-block-paragraph">Businesses should review their authentication reports and understand how legitimate email travels before choosing a strict DMARC policy.</p>



<h3 class="wp-block-heading">How long does DMARC take to work?</h3>



<p class="wp-block-paragraph">The DNS record may become available fairly quickly, but the exact timing depends on DNS caching and TTL settings.</p>



<p class="wp-block-paragraph">The larger task is usually monitoring reports, identifying legitimate sending systems, fixing authentication problems, and deciding which policy is appropriate.</p>



<p class="wp-block-paragraph">A complete DMARC rollout may therefore take longer than simply publishing the DNS record.</p>



<h3 class="wp-block-heading">Can DMARC stop every spoofed email?</h3>



<p class="wp-block-paragraph">No. DMARC helps receiving systems deal with messages that falsely claim to use your protected domain.</p>



<p class="wp-block-paragraph">It cannot directly stop attackers from registering similar-looking domains, using compromised legitimate accounts, or impersonating an employee through the display name.</p>



<h3 class="wp-block-heading">Do Google and Yahoo require SPF, DKIM and DMARC?</h3>



<p class="wp-block-paragraph">Google and Yahoo have email authentication requirements for senders. Google requires SPF or DKIM for senders to personal Gmail accounts and stronger requirements for bulk senders. Senders delivering more than 5,000 messages per day to Gmail accounts must use SPF, DKIM, and DMARC. Yahoo also requires SPF or DKIM for general senders and stronger authentication, including SPF, DKIM, and DMARC, for bulk senders. These requirements make proper email authentication important for both security and reliable email delivery.</p>



<h2 class="wp-block-heading">Build a Stronger Email Authentication Foundation</h2>



<p class="wp-block-paragraph">SPF, DKIM and DMARC give businesses practical tools for showing which systems are authorized to send email and helping receiving providers evaluate messages that claim to come from their domains.</p>



<p class="wp-block-paragraph">The best results come from configuring all three carefully, keeping DNS records accurate, and reviewing your setup whenever your business adds or removes an email platform.</p>



<p class="wp-block-paragraph">Start by auditing your current SPF, DKIM, and DMARC records instead of making several DNS changes at once.</p>



<p class="wp-block-paragraph">Identify every legitimate sender, review authentication and alignment problems, remove outdated sending services, and monitor DMARC reports before choosing a stronger policy.</p>



<p class="wp-block-paragraph"><a target="_blank" rel="noopener" href="https://franklinwebtech.com/contact/"><strong>Get in Touch Today</strong></a> if your business needs help reviewing its email authentication setup, identifying DNS configuration problems, or planning a safer DMARC rollout.</p>



<p class="wp-block-paragraph">A properly maintained email authentication setup can support stronger domain protection, more reliable business communication, and better defense against messages that attempt to impersonate your organization.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [{
    "@type": "Question",
    "name": "What is the difference between SPF, DKIM and DMARC?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "SPF identifies systems that are allowed to send email for a domain. DKIM adds a digital signature that receiving systems can verify. DMARC checks whether SPF or DKIM authentication aligns with the domain shown in the From address and provides a policy for failed authentication."
    }
  },{
    "@type": "Question",
    "name": "What happens if a domain does not have DMARC?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Without DMARC, the domain does not provide receiving systems with a DMARC policy or DMARC alignment instructions.
SPF and DKIM can still provide authentication results, but DMARC connects those results with the visible From domain and can also provide reporting information."
    }
  },{
    "@type": "Question",
    "name": "Is SPF enough without DKIM?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "SPF alone is generally not the strongest approach for modern business email.
Email forwarding and complex third-party sending arrangements can cause SPF problems. DKIM provides a separate authentication method, while DMARC can use properly aligned SPF or DKIM authentication.
Using SPF and DKIM together gives businesses more options for successful authentication."
    }
  },{
    "@type": "Question",
    "name": "Can I use DMARC without SPF?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "DMARC can pass through properly aligned DKIM even when SPF does not provide an aligned pass.
However, businesses should normally configure both SPF and DKIM when their email systems support them. Using both provides stronger and more flexible authentication."
    }
  },{
    "@type": "Question",
    "name": "Why can SPF fail when an email is forwarded?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "SPF checks the sending IP address against the SPF policy for the envelope sender domain.
When an email is forwarded, the system sending the forwarded message may not be listed in the original domain's SPF record. This can cause SPF to fail even when the original message was legitimate.
DKIM can sometimes continue to verify through forwarding if the signed parts of the message have not been changed."
    }
  },{
    "@type": "Question",
    "name": "What does p=none mean in DMARC?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "p=none means the domain owner is not requesting quarantine or rejection based only on the DMARC policy.
It is commonly used while businesses review authentication data and identify legitimate sending services.
Receiving email providers can still use their own spam, security, and reputation systems when deciding how to handle the message."
    }
  },{
    "@type": "Question",
    "name": "Should every business use p=reject?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Not automatically. A p=reject policy requests strict handling of messages that fail DMARC, but it may affect some legitimate forwarded messages, mailing lists, and other indirect email flows.
Businesses should review their authentication reports and understand how legitimate email travels before choosing a strict DMARC policy."
    }
  },{
    "@type": "Question",
    "name": "How long does DMARC take to work?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "The DNS record may become available fairly quickly, but the exact timing depends on DNS caching and TTL settings.
The larger task is usually monitoring reports, identifying legitimate sending systems, fixing authentication problems, and deciding which policy is appropriate.
A complete DMARC rollout may therefore take longer than simply publishing the DNS record."
    }
  },{
    "@type": "Question",
    "name": "Can DMARC stop every spoofed email?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "No. DMARC helps receiving systems deal with messages that falsely claim to use your protected domain.
It cannot directly stop attackers from registering similar-looking domains, using compromised legitimate accounts, or impersonating an employee through the display name."
    }
  },{
    "@type": "Question",
    "name": "Do Google and Yahoo require SPF, DKIM and DMARC?",
    "acceptedAnswer": {
      "@type": "Answer",
      "text": "Google and Yahoo have email authentication requirements for senders.
Google requires SPF or DKIM for senders to personal Gmail accounts and stronger requirements for bulk senders. Senders delivering more than 5,000 messages per day to Gmail accounts must use SPF, DKIM, and DMARC.
Yahoo also requires SPF or DKIM for general senders and stronger authentication, including SPF, DKIM, and DMARC, for bulk senders.
These requirements make proper email authentication important for both security and reliable email delivery."
    }
  }]
}
</script>



<p class="wp-block-paragraph"></p>
<p>Read more at <a href="https://franklinwebtech.com/dmarc-spf-and-dkim-explained/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Workspace Security Checklist: What Should a Small Business Configure First? </title>
		<link>https://franklinwebtech.com/google-workspace-security-checklist/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Google Workspace Security]]></category>
		<category><![CDATA[2-Step Verification]]></category>
		<category><![CDATA[Google Drive sharing controls]]></category>
		<category><![CDATA[Google Workspace Security Checklist]]></category>
		<category><![CDATA[Google Workspace security monitoring]]></category>
		<category><![CDATA[Google Workspace security settings]]></category>
		<category><![CDATA[MFA for Google Workspace]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2125</guid>

					<description><![CDATA[A small business should start with the Google Workspace controls that protect administrator accounts, user sign-ins, business data, and access from unmanaged devices. The highest-priority work is enabling strong authentication, securing super administrator accounts, controlling external sharing, reviewing third-party access, and turning on useful security monitoring. This Google Workspace security checklist puts those controls into [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/google-workspace-security-checklist/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2125" class="elementor elementor-2125">
				<div class="elementor-element elementor-element-d746156 e-flex e-con-boxed e-con e-parent" data-id="d746156" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-e8c9095 elementor-widget elementor-widget-text-editor" data-id="e8c9095" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A small business should start with the Google Workspace controls that protect administrator accounts, user sign-ins, business data, and access from unmanaged devices. The highest-priority work is enabling strong authentication, securing super administrator accounts, controlling external sharing, reviewing third-party access, and turning on useful security monitoring. This Google Workspace security checklist puts those controls into a practical order so founders, office managers, and IT administrators can address the most serious gaps first. </p><p>For businesses that rely on Gmail, Drive, Docs, Meet, Calendar, and other Workspace services, security is largely shaped by configuration. A default setup may not reflect how your business actually operates. <a class="Hyperlink SCXW224474186 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> recommends treating Workspace security as an administrative responsibility, not simply an employee password issue. </p><h2><strong>Start With the Critical Settings</strong> </h2><p>The critical tier contains controls that should be addressed before spending time on lower-priority configuration. These settings reduce the risk of account takeover and limit the damage that can follow a compromised credential. </p><h3><strong>1. Enforce Multi-Factor Authentication</strong> </h3><p>A password alone should not protect an account containing company email, documents, customer information, financial records, and internal communications. Google calls its multi-factor authentication system 2-Step Verification, commonly referred to as MFA. </p><p>Google recommends 2-Step Verification for administrator accounts, particularly super administrators, because those accounts can control organization-wide data and settings. </p><p>For a small business, the practical configuration is to allow employees to enroll first, communicate the requirement clearly, and then enforce the policy across the organization. Administrators should also select authentication methods that provide strong phishing resistance. Passkeys and physical security keys provide stronger protection against phishing than traditional SMS verification codes.  </p><p>Your Google Workspace MFA policy should also account for recovery. Admins should have secure backup methods available before enforcement creates a situation where someone cannot access their account. </p><h3><strong>2. Protect Super Administrator Accounts</strong> </h3><p>A super administrator can make changes that affect every user in the Workspace environment. That makes these accounts particularly attractive to attackers. </p><p>Google recommends having more than one super administrator, with each account assigned to a separate person. It also recommends keeping super administrator accounts separate from everyday accounts.</p><p>Do not use an account such as <strong>admin@company.com </strong>as a shared login for several employees. Individual administrator accounts provide accountability in audit records and make it easier to identify who made a configuration change. </p><p>A sensible small-business setup includes: </p><ul><li><p>Separate admin and daily-use accounts for administrators. </p></li></ul><ul><li><p>At least two independently managed super administrator accounts. </p></li></ul><ul><li><p>More than one registered security key or another secure recovery method for critical admins. </p></li></ul><p>This is one of the most frequently overlooked areas of Google Workspace admin security. Businesses often secure employee accounts while leaving administrator access exposed. </p><h3><strong>3. Review Account Recovery Information</strong> </h3><p>Account recovery deserves attention because a secure authentication policy can still create operational problems if administrators lose access to their recovery methods. </p><p>Check recovery email addresses, phone numbers, security keys, passkeys, and backup codes for administrator accounts. Remove outdated recovery information and make sure backup methods are stored securely. </p><p>Google states that backup codes can help an administrator sign in if a security key or phone is unavailable. </p><p>Recovery details should belong to the correct individual or be managed under a documented business process. Avoid leaving recovery information tied to an employee who no longer works for the company. </p><h3><strong>4. Remove Old and Unused Accounts</strong> </h3><p>Former employees, contractors, temporary accounts, and abandoned test accounts can create unnecessary access to business systems. </p><p>Create a simple offboarding process that disables accounts promptly when someone leaves. Before deleting an account, review ownership of important Drive files, calendars, groups, and other business resources so information is not accidentally lost. </p><p>Also review accounts that have not been used for a long period. An unused account with active access is still an access point that needs attention. </p><p><strong>Important Settings That Limit Data Exposure</strong> </p><p>Once authentication and administrator access are under control, the next priority is reducing unnecessary access to company information. </p><h3><strong>5. Review Google Drive Sharing</strong> </h3><p>Drive makes collaboration easy, but broad sharing can expose sensitive information outside the organization. </p><p>Review your organization&#8217;s external sharing rules and determine who actually needs to share files with external users. Pay particular attention to confidential folders containing financial information, employee records, customer data, contracts, intellectual property, and operational documents. </p><p>Avoid treating &#8220;Anyone with the link&#8221; as a normal sharing method for sensitive material. A link can be forwarded beyond the original recipient, making it harder to control who ultimately sees the file. </p><p>A useful policy is to make internal sharing the normal option and require deliberate approval for sensitive external sharing. </p><h3><strong>6. Control Third-Party Application Access</strong> </h3><p>Employees often connect Workspace accounts to external applications for productivity, project management, document handling, scheduling, and other tasks. </p><p>The risk is not limited to the application itself. A connected application may receive permission to access parts of a user&#8217;s Google data. </p><p>Review third-party application access in the Admin console and remove applications that are unnecessary, outdated, or no longer approved. Establish an internal process for approving applications before employees connect them to company accounts. </p><p>Google has also removed support for less secure apps that authenticate using only a username and password for Google Workspace accounts. Since January 2025, businesses should use more secure authentication methods instead. </p><h3><strong>7. Secure Company Devices</strong> </h3><p>Account security becomes weaker if employees access Workspace from poorly protected computers. </p><p>Consider enabling Endpoint Verification for organizations that need visibility into devices accessing business data. Google says Endpoint Verification can provide administrators with information about devices and help control access based on device and security attributes. </p><p>The appropriate level of device control depends on your workforce. A company handling sensitive customer or financial information may need stricter device requirements than a small team working primarily with low-risk documents. </p><p>At minimum, establish requirements for screen locks, operating system updates, browser updates, device encryption where supported, and removal of company access from lost or retired devices. </p><h3><strong>8. Review External Email and Phishing Protection</strong> </h3><p>Gmail is one of the most valuable targets in a business account because an attacker can use a compromised mailbox to impersonate employees, intercept conversations, and send convincing messages to customers or suppliers. </p><p>Review Gmail security controls that help identify suspicious messages and consider additional protections for high-risk users. </p><p>Employees should also know how to report suspicious messages. Security technology can reduce exposure, but users still need a clear process for reporting unusual login requests, payment instructions, password prompts, and unexpected attachments. </p><p><strong>Recommended Settings for Ongoing Control</strong> </p><p>The recommended tier focuses on visibility, maintenance, and gradual improvement. These controls may not be the first settings you configure, but they help prevent security from becoming a one-time project. </p><h3><strong>9. Monitor the Admin and Security Audit Logs</strong> </h3><p>A Google Workspace security audit should not be limited to the day after an incident. </p><p>Review administrative actions, login activity, suspicious events, and other relevant security records regularly. Look for unusual administrator changes, unexpected sign-ins, unfamiliar applications, and activity involving accounts that should no longer be active. </p><p>The purpose is not to inspect every event manually. Establish a review routine and define which events require investigation. </p><h3><strong>10. Minimize Administrator Permissions</strong> </h3><p>Not every IT employee needs super administrator access. </p><p>Use administrator roles that provide only the permissions required for a person&#8217;s responsibilities. A person managing users may not need access to every security or billing function. </p><p>Reducing administrative privileges limits the number of accounts that can make high-impact changes and makes the environment easier to manage. </p><h3><strong>11. Review Groups and Mailing Lists</strong> </h3><p>Google Groups can quietly become a source of information exposure. </p><p>Review who can join groups, who can post, who can view conversations, and who manages each group. Pay special attention to groups used for finance, human resources, leadership, customer information, and internal operations. </p><p>Remove former employees and inactive accounts from groups during offboarding. </p><h3><strong>12. Establish a Security Alert Process</strong> </h3><p>Security alerts only help if someone reviews and acts on them. </p><p>Assign responsibility for monitoring important alerts and define what happens after an alert is received. A small company does not necessarily need a large security team, but someone should own the process. </p><p>Document escalation steps for suspicious sign-ins, compromised accounts, unauthorized application access, and unexpected administrative changes. </p><h2><strong>A Practical Priority Order for Small Businesses</strong> </h2><p>A security configuration is easier to maintain when administrators know what to do first. Rather than changing dozens of settings at once, use a staged process. </p><p><strong>Critical:</strong> Enforce MFA, protect super administrator accounts, secure account recovery, remove inactive accounts, and review administrator privileges. </p><p><strong>Important:</strong> Tighten Drive sharing, review third-party application access, secure devices, strengthen Gmail protections, and review groups. </p><p><strong>Recommended:</strong> Monitor audit logs, establish alert procedures, document security policies, and schedule recurring reviews. </p><p>This order gives small businesses a sensible starting point without turning security configuration into an overwhelming project. It also provides a useful framework for future Google Workspace security best practices. </p><h2><strong>Common Configuration Mistakes to Avoid</strong> </h2><p>Small businesses often make security harder than it needs to be by focusing on isolated settings instead of access. </p><p>One common mistake is creating a single shared administrator account. Shared credentials remove accountability and make it difficult to investigate administrative activity. </p><p>Another is enforcing MFA without preparing recovery options. Strong authentication is valuable, but administrators should have secure backup methods before a policy becomes mandatory. </p><p>Broad Drive sharing is another recurring issue. Employees may share files externally for convenience without realizing that sensitive information can remain accessible long after the original business need has ended. </p><p>Businesses also sometimes install security tools without reviewing Workspace&#8217;s own administrative controls. Third-party products can have a role, but basic Google Workspace security settings should be properly configured first. </p><p>Finally, avoid treating security as a setup task that ends after implementation. Employee turnover, new applications, device changes, and changes in business operations can all create new access risks. </p><h2><strong>How Often Should a Small Business Review Workspace Security?</strong> </h2><p>A basic review should take place at least quarterly, with more frequent checks for organizations handling sensitive information. </p><p>A recurring review can cover administrator accounts, inactive users, MFA enrollment, recovery methods, external sharing, third-party applications, groups, device access, and security alerts. </p><p>A more detailed review should follow major organizational changes such as acquisitions, leadership changes, large employee departures, new business applications, or a security incident. </p><p>Google&#8217;s administrative guidance also emphasizes ongoing monitoring, administrator account protection, and recovery preparation rather than relying on passwords alone.  </p><h2><strong>Build a Security Baseline That Fits Your Business</strong> </h2><p>There is no single Google Workspace configuration that fits every small business. A company managing public marketing material has different information risks from an accounting firm, healthcare organization, legal practice, or technology company. </p><p>Start by identifying your most sensitive information and the people who can access it. Then work outward through authentication, administrator permissions, data sharing, devices, applications, and monitoring. </p><p>That approach makes a secure Google Workspace environment easier to maintain because each control has a clear business purpose. </p><p>A well-configured Workspace environment should make the secure choice the normal choice. Employees should not need to understand every technical control, but administrators should know why access is granted, who can change it, and how suspicious activity will be handled. </p><h3><strong>Final Thoughts</strong> </h3><p>Small businesses do not need to configure every Google Workspace security feature on the first day. They need to address the controls that have the greatest effect on account access and business data first. </p><p>Start with MFA and administrator protection. Then tighten sharing, application access, device controls, and monitoring. Keep recovery methods current and review the environment on a recurring schedule. </p><p>For organizations that want an expert review, Franklin Web Technologies can help assess the current configuration, identify gaps, and prioritize practical improvements. A focused review can provide a clearer picture of your current security posture and the changes that deserve attention first. </p><p>If your business has not reviewed its Workspace configuration recently, <a class="Hyperlink SCXW224474186 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Request a Security Consultation</u></strong></a> and turn your security settings into a documented, repeatable baseline. </p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/google-workspace-security-checklist/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Is Conditional Access? A Small Business Guide to Microsoft 365 Login Security </title>
		<link>https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Conditional Access]]></category>
		<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Microsoft 365 Conditional Access]]></category>
		<category><![CDATA[multi-factor authentication (MFA)]]></category>
		<category><![CDATA[What Is Conditional Access]]></category>
		<category><![CDATA[Zero Trust security]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2119</guid>

					<description><![CDATA[A stolen password should not automatically give someone access to Microsoft 365. What is Conditional Access is a question about how Microsoft can evaluate the circumstances around a sign-in and apply additional access requirements before allowing entry. Microsoft Conditional Access uses signals such as the user, device, location, application, and sign-in risk to determine what [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2119" class="elementor elementor-2119">
				<div class="elementor-element elementor-element-2da8daa e-flex e-con-boxed e-con e-parent" data-id="2da8daa" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-f458740 elementor-widget elementor-widget-text-editor" data-id="f458740" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A stolen password should not automatically give someone access to Microsoft 365. What is Conditional Access is a question about how Microsoft can evaluate the circumstances around a sign-in and apply additional access requirements before allowing entry. Microsoft Conditional Access uses signals such as the user, device, location, application, and sign-in risk to determine what access should be allowed. </p><p>For a small business, this can mean requiring MFA for administrators, blocking access from untrusted locations, requiring managed devices for sensitive resources, or responding differently to risky sign-ins. <a class="Hyperlink SCXW138293303 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> helps businesses understand and configure these Microsoft 365 login security controls around their actual working environment. </p><h2><strong>What Is Conditional Access in Microsoft 365?</strong> </h2><p>Conditional Access is a policy-based access control feature in Microsoft Entra ID. It works through an &#8220;if-then&#8221; model: if specific conditions are present during a sign-in, then Microsoft applies a defined access requirement. </p><p>For example, a business could create a policy that says: if an employee signs in to Microsoft 365 from an unfamiliar device, require MFA before granting access. Another policy could require a company-managed device before someone can access sensitive business information. </p><p>Microsoft describes Conditional Access as its Zero Trust policy engine because it uses multiple signals to make access decisions instead of treating every successful password authentication as sufficient. </p><p>The policies can grant access, require additional controls, or block access altogether. Administrators can also apply session controls that influence how a user remains signed in or interacts with selected cloud applications. </p><h2><strong>Why Does Conditional Access Matter for Small Businesses?</strong> </h2><p>Many small businesses start with a basic combination of usernames, passwords, and MFA. MFA is an essential layer, but it does not answer every access question. </p><p>A valid username and password can still be used from an unmanaged computer. A compromised account can still be accessed from an unusual location. An administrator might sign in from a device that does not meet the organization&#8217;s requirements. </p><p>Conditional Access adds context to the login decision. </p><p>Instead of asking only, &#8220;Did this person provide the correct credentials?&#8221; an access policy can consider questions such as: </p><ul><li><p>Who is signing in? </p></li></ul><ul><li><p>What application or resource are they trying to access? </p></li></ul><ul><li><p>What device are they using? </p></li></ul><ul><li><p>Where is the sign-in coming from? </p></li></ul><ul><li><p>Is the sign-in showing elevated risk? </p></li></ul><ul><li><p>What additional authentication or device requirement should apply? </p></li></ul><p>This approach supports identity security by making access decisions based on the circumstances surrounding each request. </p><h2><strong>How Do Conditional Access Policies Work?</strong> </h2><p>Conditional Access policies contain assignments and access controls. Assignments establish the circumstances under which a policy applies, while access controls determine what happens when those circumstances are met. </p><p>An administrator can target specific users or groups, applications, device platforms, locations, and other conditions. The policy can then require MFA, require a compliant device, block access, or apply another supported control. </p><p>For example: </p><p><strong>Condition:</strong> An employee accesses Microsoft 365 from an unmanaged device. </p><p><strong>Action:</strong> Require MFA and a compliant device before granting access. </p><p>Several Conditional Access policies can apply to the same sign-in. Microsoft evaluates the applicable requirements, so a user may need to satisfy more than one condition before access is granted. </p><p>This is useful for businesses that need different rules for administrators, office staff, contractors, remote workers, and users accessing sensitive applications. </p><h2><strong>Conditional Access vs MFA: What Is the Difference?</strong> </h2><p>The distinction in MFA vs Conditional Access is straightforward. </p><p>MFA verifies that the person signing in can provide an additional authentication factor. Conditional Access determines when that additional requirement, or another access control, should be applied. </p><p>MFA can be viewed as an authentication method. Conditional Access is the policy layer that decides how and when access requirements are enforced. </p><p>For example, a company could require MFA for every user. It could then use Conditional Access to add another rule requiring administrators to use MFA when accessing administrative resources or requiring a compliant device for sensitive applications. </p><p>Microsoft&#8217;s Conditional Access grant controls include requirements such as MFA, authentication strength, device compliance, an approved client application, an app protection policy, or a password change. Administrators can also choose to block access. </p><p>That makes Conditional Access broader than simply turning on MFA. </p><h2><strong>Practical Conditional Access Policies for a Small Business</strong> </h2><p>A small business does not need dozens of complicated access policies to establish a stronger baseline. The useful starting point is a small set of policies that address common access risks. </p><h3><strong>Require MFA for Administrators</strong> </h3><p>Administrator accounts can change settings, manage users, and control business resources. Requiring MFA for these accounts creates an additional verification step before privileged access is granted. </p><p>Microsoft lists requiring MFA for administrators among its common Conditional Access policies. </p><p>For organizations with stronger authentication requirements, authentication strength policies can also be used to define the type of authentication required. </p><h3><strong>Block Legacy Authentication</strong> </h3><p>Older authentication protocols may not support modern authentication requirements. Blocking legacy authentication prevents users from accessing Microsoft 365 through methods that cannot properly satisfy modern controls. </p><p>Microsoft identifies blocking legacy authentication as a common Conditional Access policy and includes it in its recommended policy templates. </p><p>This is especially useful during Microsoft 365 hardening because a business can remove an older access path instead of relying only on passwords and MFA. </p><h3><strong>Require Managed or Compliant Devices</strong> </h3><p>A password and MFA do not tell an organization if the device being used is managed or meets its device requirements. </p><p>Conditional Access can require a device to be marked compliant before granting access. This can be useful for employees accessing sensitive Microsoft 365 resources from company-managed computers. </p><p>The exact device requirement depends on how the organization manages its endpoints and which Microsoft services and licenses it uses. </p><h3><strong>Respond to Risky Sign-Ins</strong> </h3><p>Microsoft Entra ID can provide risk signals that Conditional Access policies use to respond to suspicious authentication activity. For organizations with the required licensing, risk-based policies can require MFA for elevated sign-in risk or take other corrective action. </p><p>This creates a more responsive access policy. A familiar sign-in may follow the normal authentication process, while a sign-in presenting elevated risk can trigger an additional requirement. </p><h2><strong>Can Conditional Access Block Access?</strong> </h2><p>Yes. Conditional Access can block access when a defined condition is met. </p><p>For example, an organization could create a policy that blocks access from selected locations. Microsoft supports location-based policies that can use network location information to control access to cloud applications. </p><p>Blocking access requires careful testing because an overly broad policy can prevent legitimate users from reaching Microsoft 365. Microsoft recommends using report-only mode and testing policy impact before enabling restrictive policies. </p><p>Businesses should also maintain emergency access accounts that are excluded appropriately from policies to reduce the chance of administrators being locked out after a configuration mistake. </p><h2><strong>Conditional Access and Zero Trust</strong> </h2><p>Zero Trust is based on verifying access rather than assuming that a user should be trusted simply because they have valid credentials or are connecting from a familiar network. </p><p>Conditional Access supports this model by evaluating identity, device, application, location, and risk signals before enforcing access requirements. </p><p>For a small business, Zero Trust does not mean creating an enormous collection of complicated rules. It can begin with practical decisions such as requiring MFA for privileged accounts, blocking legacy authentication, restricting access from unmanaged devices where appropriate, and responding to high-risk sign-ins. </p><p>The objective is to make access decisions based on evidence rather than treating every successful password login the same way. </p><h2><strong>How Should a Small Business Start?</strong> </h2><p>Conditional Access should be introduced carefully. A policy that looks reasonable on paper can behave differently once it encounters real users, devices, applications, and sign-in patterns. </p><p>Start by identifying the accounts and resources that require the strongest protection. Administrators should usually receive stricter controls than ordinary users because they have broader permissions. </p><p>Next, review the devices employees use to access Microsoft 365. If the company manages its devices through Microsoft Intune, device compliance can become part of access decisions. </p><p>Then review sign-in locations and authentication methods. Unusual locations, older authentication protocols, and elevated sign-in risk can provide useful signals for additional controls. </p><p>Before activating restrictive policies, use report-only mode and test them with designated users. Microsoft specifically recommends maintaining a test user and validating policies before deployment. </p><p>A practical rollout can follow this order: </p><ol><li><p>Protect administrator accounts with MFA and stronger authentication requirements. </p></li></ol><ol start="2"><li><p>Block legacy authentication and review sign-in activity. </p></li></ol><ol start="3"><li><p>Apply device and application requirements to sensitive resources. </p></li></ol><ol start="4"><li><p>Add risk-based policies where the required Microsoft Entra licensing is available. </p></li></ol><ol start="5"><li><p>Review policies regularly as users, devices, applications, and business requirements change. </p></li></ol><p>This approach keeps the initial configuration manageable while creating room for more specific access policies later. </p><h2><strong>Common Conditional Access Mistakes to Avoid</strong> </h2><p>The biggest problems often come from policy design rather than the feature itself. </p><p>One common mistake is creating broad block policies without testing them. A rule that blocks an entire location, user group, or application can affect legitimate business activity. </p><p>Another issue is applying too many policies at once. Multiple policies can affect the same sign-in, so administrators need to understand how assignments overlap and which requirements users must satisfy. </p><p>Excluding emergency access accounts is also an important safeguard. These accounts provide a recovery path if a configuration error prevents normal administrative access. </p><p>Businesses should also avoid treating Conditional Access as a replacement for every other Microsoft 365 security control. Strong authentication, appropriate account privileges, device management, secure configuration, monitoring, and regular reviews all contribute to a safer environment. </p><h2><strong>What Does Conditional Access Mean for Your Business?</strong> </h2><p>For an SMB, Conditional Access is essentially a set of rules that determines when a Microsoft 365 login should be allowed, challenged, restricted, or blocked. </p><p>Its value comes from adding context to authentication. A user with valid credentials may receive different access requirements depending on the device, application, location, identity, and risk associated with the sign-in. </p><p>That makes Conditional Access a practical part of Microsoft 365 login security and identity security. Instead of applying the same login rule to every situation, businesses can create access policies that reflect the sensitivity of their resources and the circumstances of each sign-in. </p><p>Franklin Web Technologies can help businesses review their Microsoft 365 configuration, identify gaps in Conditional Access policies, and prioritize controls that fit their users and working environment. </p><h2><strong>Build a More Controlled Microsoft 365 Login Environment</strong> </h2><p>Conditional Access gives small businesses a practical way to move beyond password-based access decisions. The most useful policies are not necessarily the most complicated ones. Strong administrator protection, modern authentication, sensible device requirements, legacy authentication blocking, and risk-based controls can establish a solid foundation. </p><p>The right configuration also requires testing and ongoing review. Microsoft recommends validating policies before enforcement because poorly designed rules can interrupt legitimate access. </p><p>For businesses that want a clearer assessment of their Microsoft 365 access policies, <a class="Hyperlink SCXW138293303 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Request a Security Consultation</u></strong></a> to review your current configuration and identify practical improvements. </p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Microsoft 365 Security Checklist: 15 Settings Every Small Business Should Review</title>
		<link>https://franklinwebtech.com/microsoft-365-security-checklist/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 06:17:57 +0000</pubDate>
				<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Microsoft 365 Security Checklist]]></category>
		<category><![CDATA[Microsoft 365 security settings]]></category>
		<category><![CDATA[Microsoft Entra ID MFA]]></category>
		<category><![CDATA[small business Microsoft 365 security]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2112</guid>

					<description><![CDATA[A secure Microsoft 365 tenant depends on more than turning on multifactor authentication. Small businesses also need to review administrator privileges, legacy authentication, external forwarding, application permissions, audit logging, email protection, and sharing controls. This Microsoft 365 security checklist highlights 15 settings that are easy to overlook but can have a direct effect on account [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/microsoft-365-security-checklist/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2112" class="elementor elementor-2112">
				<div class="elementor-element elementor-element-ce89c04 e-flex e-con-boxed e-con e-parent" data-id="ce89c04" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-b845b5b elementor-widget elementor-widget-text-editor" data-id="b845b5b" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A secure Microsoft 365 tenant depends on more than turning on multifactor authentication. Small businesses also need to review administrator privileges, legacy authentication, external forwarding, application permissions, audit logging, email protection, and sharing controls. This Microsoft 365 security checklist highlights 15 settings that are easy to overlook but can have a direct effect on account compromise, data exposure, and business continuity. <a class="Hyperlink SCXW101006295 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> uses this type of configuration-focused review to help businesses identify gaps that basic security setup can leave behind. </p><h2><strong>1. Confirm that MFA protects every user</strong> </h2><p>Multifactor authentication should cover regular users, administrators, contractors, and other accounts that can access business data. A password alone provides limited protection against phishing, password spraying, and reused credentials. </p><p>Businesses without Microsoft Entra ID P1 or P2 can use Security Defaults as a baseline. Security Defaults require MFA registration and block several older authentication methods. Organizations with Microsoft Entra ID P1 or higher can use Conditional Access for more granular policies. </p><p><strong>Example configuration:</strong> </p><p>Microsoft Entra admin center &gt; Entra ID &gt; Overview &gt; Properties &gt; Manage security defaults </p><p>Do not assume MFA is active simply because some employees receive authentication prompts. Check the tenant configuration and sign-in reports to verify coverage. </p><h2><strong>2. Review the authentication methods employees can register</strong> </h2><p>MFA is only as strong as the authentication methods behind it. Microsoft 365 administrators should review which methods users can register and remove methods that do not fit the organization&#8217;s security requirements. </p><p>For privileged users, phishing-resistant methods such as passkeys or FIDO2 security keys provide stronger protection against phishing than methods that depend entirely on passwords or approval prompts. </p><p>A useful Microsoft 365 security assessment should identify users with weak, outdated, or unnecessary authentication methods and verify that recovery options are also controlled. </p><h2><strong>3. Protect administrator accounts separately</strong> </h2><p>A Global Administrator account should not be the same account used for routine email, Teams conversations, web browsing, and document work. </p><p>Create dedicated administrator accounts and assign only the roles required for administrative duties. Microsoft recommends least-privileged administrative roles as part of identity security guidance. </p><p>Review the following: </p><ul><li><p>Global Administrator assignments </p></li></ul><ul><li><p>Exchange Administrator assignments </p></li></ul><ul><li><p>Security Administrator assignments </p></li></ul><ul><li><p>Privileged Role Administrator assignments </p></li></ul><ul><li><p>Inactive administrator accounts </p></li></ul><p>This is a central part of Microsoft 365 admin security because a compromised administrator account can affect far more than one employee&#8217;s mailbox. </p><h2><strong>4. Create and test emergency access accounts</strong> </h2><p>An emergency access account is designed for situations such as an administrator lockout or authentication-policy failure. It should not become someone&#8217;s everyday account. </p><p>Microsoft recommends maintaining at least two cloud-only emergency access accounts, protecting them with phishing-resistant authentication, storing credentials securely, monitoring their use, and validating them regularly. </p><p><strong>Example:</strong> </p><p>Create two dedicated <strong>.onmicrosoft.com </strong>accounts, document their purpose, secure their credentials separately, and test access at least every 90 days. </p><p>These accounts should be treated as controlled recovery mechanisms, not spare administrator accounts. </p><h2><strong>5. Block legacy authentication</strong> </h2><p>Legacy authentication is one of the settings that deserves immediate attention during Microsoft 365 hardening. </p><p>Older protocols such as POP3, IMAP, and other basic authentication methods do not support modern security controls such as MFA. Microsoft specifically recommends blocking legacy authentication because attackers can use these protocols to bypass protections applied to modern sign-ins. </p><p>Check sign-in logs before enforcing the policy. Identify devices, applications, scanners, or other services still relying on older authentication and migrate them first. </p><h2><strong>6. Review device code authentication</strong> </h2><p>Device code authentication can be useful for devices with limited input capabilities, but it can also be abused in phishing attacks. Microsoft Security Defaults block device code flow as part of their baseline protections. </p><p>Organizations using Conditional Access should review policies covering device code authentication and determine if any legitimate business process requires an exception. </p><p>An overlooked authentication flow can give an attacker another route into a tenant even after conventional MFA controls are enabled. </p><h2><strong>7. Limit unnecessary application consent</strong> </h2><p>Employees can sometimes grant applications access to Microsoft 365 data. An employee may approve an application without realizing that the permission allows access to mail, files, calendars, contacts, or other organizational information. </p><p>Review Microsoft Entra application consent settings and decide who can approve applications. For higher-risk permissions, route requests through administrator approval. </p><p><strong>Example policy approach:</strong> </p><p>Require administrator approval for applications requesting sensitive Microsoft Graph permissions. </p><p>This reduces the chance that a malicious or poorly configured third-party application becomes an indirect path to business data. </p><h2><strong>8. Review inactive users and guest accounts</strong> </h2><p>Old employee accounts, dormant users, former contractors, and unused guest accounts increase the number of identities that need protection. </p><p>Run regular reviews of: </p><ul><li><p>Disabled and inactive accounts </p></li></ul><ul><li><p>Guest users </p></li></ul><ul><li><p>Users with administrative roles </p></li></ul><ul><li><p>Accounts that have not signed in for extended periods </p></li></ul><p>Microsoft&#8217;s identity security recommendations specifically include removing dormant accounts from sensitive groups and using least-privileged administrative roles. </p><p>Account cleanup should be part of normal Microsoft 365 administration rather than an occasional security project. </p><h2><strong>9. Check external email forwarding</strong> </h2><p>Automatic forwarding deserves special attention because it can quietly move company information outside the tenant. </p><p>Microsoft identifies automatic forwarding to external recipients as a security concern because it can expose organizational information. Users can create forwarding through inbox rules, while administrators can configure mailbox forwarding. </p><p>Review existing forwarding rules and determine which external destinations are legitimate. </p><p><strong>Example check:</strong> </p><p>Exchange admin center &gt; Mail flow &gt; Remote domains / outbound spam policies </p><p>For most small businesses, external automatic forwarding should be restricted unless there is a documented business requirement. </p><h2><strong>10. Tighten external sharing in SharePoint and OneDrive</strong> </h2><p>SharePoint and OneDrive can contain contracts, financial documents, customer information, employee records, and internal procedures. A permissive sharing configuration can make sensitive files accessible outside the organization. </p><p>Review default sharing links, guest access, anonymous links, and domain restrictions. Apply stricter controls to sites containing confidential information. </p><p>A useful configuration principle is simple: users should have an easy internal sharing process while external access requires a clear business reason. </p><h2><strong>11. Turn on the right email protection policies</strong> </h2><p>Microsoft Defender for Office 365 provides controls such as Safe Links, Safe Attachments, and enhanced anti-phishing protection. Microsoft notes that the built-in protection preset provides basic Safe Links and Safe Attachments protection for eligible Defender customers, while Standard and Strict preset policies provide stronger configurations. </p><p>Review: </p><ul><li><p>Anti-phishing policies </p></li></ul><ul><li><p>Impersonation protection </p></li></ul><ul><li><p>Safe Links </p></li></ul><ul><li><p>Safe Attachments </p></li></ul><ul><li><p>Anti-malware policies </p></li></ul><p>Pay particular attention to executive accounts, finance users, and employees who frequently handle payment or customer information. </p><h2><strong>12. Protect against impersonation attacks</strong> </h2><p>A basic spam filter does not address every impersonation scenario. Attackers may imitate executives, suppliers, domains, or trusted contacts to convince employees to transfer money or disclose information. </p><p>Microsoft Defender for Office 365 supports impersonation protection through its security policies. The default anti-phishing policy includes spoof protection and mailbox intelligence, while additional impersonation controls require configuration through preset or custom policies. </p><p>Add high-value users and important business domains to the appropriate protection policies and review alerts regularly. </p><h2><strong>13. Verify that audit logging is useful</strong> </h2><p>Audit logs are valuable only when the organization knows what activity it needs to investigate. </p><p>Confirm that auditing is available and that administrators know where to review activity involving users, administrators, mailboxes, applications, and other Microsoft 365 services. </p><p>A security review should also establish a basic retention and investigation process. Suspicious sign-ins, unexpected permission changes, forwarding rules, and administrator actions should have a clear path for investigation. </p><p>For emergency access accounts, Microsoft specifically recommends monitoring sign-in and audit logs. </p><h2><strong>14. Review Microsoft Secure Score instead of ignoring it</strong> </h2><p>Microsoft Secure Score provides a useful starting point for identifying security improvements. The identity portion evaluates configuration against recommended controls and recalculates based on the tenant&#8217;s security posture. </p><p>Do not treat the score as a complete security rating. A high score does not prove that every important business risk has been addressed. </p><p>Use it as a review queue. Prioritize recommendations based on the sensitivity of your data, user roles, current threats, licensing, and operational requirements. </p><h2><strong>15. Review Conditional Access policies for gaps and exceptions</strong> </h2><p>Conditional Access can apply rules based on factors such as user, application, device, location, and authentication requirements. The danger is not only missing policies. Poorly managed exclusions can create the same problem. </p><p>Review every policy for: </p><ul><li><p>Users or groups excluded from MFA </p></li></ul><ul><li><p>Emergency access exclusions </p></li></ul><ul><li><p>Legacy authentication blocks </p></li></ul><ul><li><p>Administrator protection </p></li></ul><ul><li><p>Unmanaged device access </p></li></ul><ul><li><p>Report-only policies that were never enforced </p></li></ul><p>Microsoft recommends using Conditional Access when organizations need more customization than Security Defaults provides. </p><p>Document every exception and assign an owner. An exception without an owner can remain in place long after the original business need has disappeared. </p><h3><strong>How To Turn The Checklist Into A Practical Security Review</strong> </h3><p>A useful Microsoft 365 security assessment should not stop at checking boxes. Record the current configuration, identify the business reason for exceptions, assign a responsible administrator, and set a review date. </p><p>For example, a small business might find that MFA is enabled for employees but three administrator accounts are excluded from a Conditional Access policy. Another review might uncover external forwarding from an old mailbox or guest accounts that have not been used for months. </p><p>Those findings have different levels of urgency, so prioritize them by business impact. An administrator account without strong authentication generally deserves faster remediation than a low-risk configuration preference. </p><p>Franklin Web Technologies can use this configuration-first approach to help businesses examine Microsoft 365 security settings beyond the obvious controls. The goal is to identify settings that attackers could exploit and translate technical findings into practical actions for the business. </p><h2><strong>A Simple Review Schedule For Small Businesses </strong></h2><p>Security settings should be reviewed after major Microsoft 365 changes, administrator changes, new applications, acquisitions, employee departures, and significant changes to how staff access company data. </p><p>A quarterly review can cover administrator roles, inactive users, guest accounts, authentication methods, forwarding rules, Conditional Access exclusions, external sharing, and Defender policies. A deeper annual review can examine the complete tenant configuration and compare it against current Microsoft 365 security best practices. </p><p>The process also gives business owners a clearer picture of their Microsoft 365 security risks instead of relying on assumptions about default protection. </p><h2><strong>Final Thoughts</strong> </h2><p>Microsoft 365 can provide strong built-in security, but secure configuration still requires attention. MFA, administrator protection, legacy authentication controls, forwarding restrictions, application consent, email defenses, sharing policies, and audit visibility all contribute to a safer tenant. </p><p>The most effective checklist is one that reflects how your business actually uses Microsoft 365. Review the settings, document exceptions, remove unnecessary access, and test recovery controls instead of assuming they work. </p><p>For small businesses that need a more detailed review or assistance with secure Microsoft 365 for small business, <a class="Hyperlink SCXW101006295 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Contact Us Now</u></strong></a> to discuss your Microsoft 365 configuration and identify practical security improvements.</p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/microsoft-365-security-checklist/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Plugging the Holes: Protect Your Business with Defender</title>
		<link>https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/</link>
		
		<dc:creator><![CDATA[Martin Franklin]]></dc:creator>
		<pubDate>Thu, 08 Jan 2026 15:52:55 +0000</pubDate>
				<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[Malware Protection]]></category>
		<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Phishing Prevention]]></category>
		<category><![CDATA[Microsoft Defender]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[Security Hardening]]></category>
		<category><![CDATA[SMB Cybersecurity]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=1925</guid>

					<description><![CDATA[Small businesses are prime targets for phishing, malware, and malicious links. Learn how Microsoft Defender for Office 365 helps block these threats—and how Franklin Web Technologies can make cybersecurity simple and affordable for your business.
<p>Read more at <a href="https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="1925" class="elementor elementor-1925">
				<div class="elementor-element elementor-element-04139f6 e-flex e-con-boxed e-con e-parent" data-id="04139f6" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-49a5b0c elementor-widget elementor-widget-image" data-id="49a5b0c" data-element_type="widget" data-e-type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img fetchpriority="high" decoding="async" width="1024" height="683" src="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-1024x683.png" class="attachment-large size-large wp-image-1940" alt="Cybersecurity illustration showing Microsoft Defender protecting business devices from threats" srcset="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-1024x683.png 1024w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-300x200.png 300w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-768x512.png 768w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px"  title="Plugging the Holes: Protect Your Business with Defender" />															</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-d61b811 e-flex e-con-boxed e-con e-parent" data-id="d61b811" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-eb12cdb elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="eb12cdb" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-4e023bc e-flex e-con-boxed e-con e-parent" data-id="4e023bc" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-5cae850 elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor" data-id="5cae850" data-element_type="widget" data-e-type="widget" data-settings="{&quot;drop_cap&quot;:&quot;yes&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Small businesses are prime targets. Cybercriminals know many small businesses don’t have dedicated IT teams. A single click can lead to <strong>data breaches, ransomware, and financial loss</strong>.</p><p>Let’s break down the <strong>three biggest threats</strong> and how <a href="https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365" target="_blank" rel="noopener">Microsoft Defender for Office 365</a> helps you stop them.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-bad0d07 elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="bad0d07" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-348e50b e-flex e-con-boxed e-con e-parent" data-id="348e50b" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-3c443de elementor-widget elementor-widget-heading" data-id="3c443de" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Phishing Emails – The Silent Trap</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-ff2bc37 elementor-widget elementor-widget-text-editor" data-id="ff2bc37" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Story:</strong><br />You’re managing invoices when an email arrives from what looks like your bank. It says there’s an urgent issue and asks you to click a link. You click, enter your details—and attackers now have your credentials.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Phishing" target="_blank" rel="noopener">Phishing</a> emails trick you into giving away passwords or sensitive info. They look legitimate and urgent.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6b6ca88 elementor-widget elementor-widget-text-editor" data-id="6b6ca88" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-9d6393f elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="9d6393f" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks suspicious emails before they hit your inbox</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text"> Real-time alerts for potential scams</span>
									</li>
						</ul>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-22da420 e-flex e-con-boxed e-con e-parent" data-id="22da420" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-62a5097 elementor-widget elementor-widget-heading" data-id="62a5097" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Malware – The Hidden Enemy</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-bab594f elementor-widget elementor-widget-text-editor" data-id="bab594f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Scenario:</strong><br />An invoice attachment from a “vendor” arrives. One click, and malware installs on your system, stealing data or locking files for ransom.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Malware" target="_blank" rel="noopener">Malware</a> can cripple your business overnight.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-8c94d9a elementor-widget elementor-widget-text-editor" data-id="8c94d9a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-e98f650 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="e98f650" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Scans every attachment for malicious code</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks harmful files before you open them</span>
									</li>
						</ul>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-2c2e7d0 e-flex e-con-boxed e-con e-parent" data-id="2c2e7d0" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d12929d elementor-widget elementor-widget-heading" data-id="d12929d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Malicious URLs – The Click That Costs You</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-be62dcb elementor-widget elementor-widget-text-editor" data-id="be62dcb" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Scenario:</strong><br />Links in emails or chats lead to fake websites that capture your login details or install spyware.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Spoofed_URL" target="_blank" rel="noopener">Malicious URL</a> attacks often bypass basic spam filters.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5881e1a elementor-widget elementor-widget-text-editor" data-id="5881e1a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-1589d92 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="1589d92" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Safe Links technology rewrites and checks URLs in real time</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks access to dangerous sites—even after you click</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-493bce1 elementor-widget elementor-widget-text-editor" data-id="493bce1" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Don’t wait until an attack happens. Let’s make your business resilient today.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-e68ba2c elementor-button-success elementor-widget elementor-widget-button" data-id="e68ba2c" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="/contact/">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Schedule a Consultation</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Proper Email Configuration Is an Underrated Security Control</title>
		<link>https://franklinwebtech.com/proper-email-configuration-security-control/</link>
		
		<dc:creator><![CDATA[Martin Franklin]]></dc:creator>
		<pubDate>Mon, 29 Dec 2025 17:29:43 +0000</pubDate>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Phishing & Identity Protection]]></category>
		<category><![CDATA[Business email compromise]]></category>
		<category><![CDATA[Deliverability and trust topics]]></category>
		<category><![CDATA[DKIM]]></category>
		<category><![CDATA[DMARC]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[SPF]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=1838</guid>

					<description><![CDATA[Learn why email authentication protocols like SPF, DKIM and DMARC are essential for email security, reducing phishing risk and improving deliverability.<p>Read more at <a href="https://franklinwebtech.com/proper-email-configuration-security-control/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="1838" class="elementor elementor-1838">
				<div class="elementor-element elementor-element-93ee3e5 e-flex e-con-boxed e-con e-parent" data-id="93ee3e5" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-7dea597 elementor-widget elementor-widget-image" data-id="7dea597" data-element_type="widget" data-e-type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img decoding="async" width="1024" height="683" src="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-1024x683.webp" class="attachment-large size-large wp-image-1888" alt="Email security illustration showing SPF DKIM and DMARC protection" srcset="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-1024x683.webp 1024w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-300x200.webp 300w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-768x512.webp 768w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security.webp 1536w" sizes="(max-width: 1024px) 100vw, 1024px"  title="Proper Email Configuration Is an Underrated Security Control" />															</div>
				</div>
				<div class="elementor-element elementor-element-31c3c29 elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="31c3c29" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-87e305f e-flex e-con-boxed e-con e-parent" data-id="87e305f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-23b14e9 elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor" data-id="23b14e9" data-element_type="widget" data-e-type="widget" data-settings="{&quot;drop_cap&quot;:&quot;yes&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email remains the most trusted communication channel in business, yet it is also the most commonly exploited. Properly configured email authentication is one of the simplest and most effective ways to reduce phishing and impersonation risk.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-d7681cf elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="d7681cf" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-9dbb68f e-flex e-con-boxed e-con e-parent" data-id="9dbb68f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d8812ed elementor-widget elementor-widget-heading" data-id="d8812ed" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Understanding Email Authentication</h2>				</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-d70e068 e-flex e-con-boxed e-con e-parent" data-id="d70e068" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-4bae726 elementor-widget elementor-widget-text-editor" data-id="4bae726" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email authentication technologies like <a href="https://en.wikipedia.org/wiki/Sender_Policy_Framework" target="_blank" rel="noopener">SPF</a>, <a href="https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail" target="_blank" rel="noopener">DKIM</a>, and <a href="https://en.wikipedia.org/wiki/DMARC" target="_blank" rel="noopener">DMARC</a> are designed to verify that email messages are legitimately sent from authorized sources. Together, they help receiving mail systems answer a critical question before delivering a message to an inbox: Can this sender be trusted?</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a59b003 elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="a59b003" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">SPF specifies which mail servers are allowed to send email on behalf of your domain</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">DKIM ensures messages have not been altered in transit</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">DMARC ties these controls together and defines how failed authentication should be handled</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-5a57198 elementor-widget elementor-widget-text-editor" data-id="5a57198" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									When implemented and enforced correctly, these controls significantly reduce the ability for attackers to impersonate your domain.								</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-a86eb59 e-flex e-con-boxed e-con e-parent" data-id="a86eb59" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d403e8a elementor-widget elementor-widget-heading" data-id="d403e8a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Why DMARC Matters</h2>				</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-760275e e-flex e-con-boxed e-con e-parent" data-id="760275e" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-416e83f elementor-widget elementor-widget-text-editor" data-id="416e83f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><a href="https://en.wikipedia.org/wiki/DMARC" target="_blank" rel="noopener">DMARC</a> goes beyond basic authentication by adding policy enforcement and reporting. It allows domain owners to instruct receiving mail systems on what to do when authentication fails and provides visibility into all systems attempting to send email using the domain.</p><p>Organizations that fully implement DMARC see tangible benefits:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5da0ee1 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="5da0ee1" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Reduced phishing and spoofing attempts using their domain</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Improved trust with customers, partners, and vendors</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Better email deliverability and fewer messages routed to spam</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Clear visibility into third party email services</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Stronger protection for employees against impersonation attacks</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-25ef0bb elementor-widget elementor-widget-text-editor" data-id="25ef0bb" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									In many cases, organizations are surprised to discover how many unknown or misconfigured systems are sending email on their behalf.								</div>
				</div>
		<div class="elementor-element elementor-element-5512c10 e-con-full e-flex e-con e-child" data-id="5512c10" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;gradient&quot;}">
				<div class="elementor-element elementor-element-1748b5a elementor-widget elementor-widget-heading" data-id="1748b5a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h3 class="elementor-heading-title elementor-size-default">"The risk is not misconfiguration.<br>
The risk is incomplete enforcement."</h3>				</div>
				</div>
				</div>
				<div class="elementor-element elementor-element-90c00f6 elementor-widget elementor-widget-heading" data-id="90c00f6" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">The Most Common Oversight</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-fe85683 elementor-widget elementor-widget-text-editor" data-id="fe85683" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>A frequent issue we encounter is incomplete implementation. SPF records are outdated, DKIM is enabled for only one platform, and DMARC is left in monitoring mode indefinitely. Over time, new services are added such as CRMs, marketing platforms, payroll providers, or support tools, but email authentication is never revisited.</p>

<p>Attackers take advantage of this gap.</p>

<p>Without enforcement, fraudulent emails can still appear legitimate to recipients, increasing the likelihood of successful phishing attempts.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a6ca616 elementor-widget elementor-widget-heading" data-id="a6ca616" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">A Small Investment With Significant Impact</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-4ce60d3 elementor-widget elementor-widget-text-editor" data-id="4ce60d3" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Proper email authentication does not require new software or complex infrastructure. It requires careful configuration, validation across all email sources, and a clear enforcement strategy.</p>

<p>The payoff is significant. Strong email authentication reduces risk, improves trust, and strengthens the overall security posture of an organization with relatively low ongoing maintenance.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-1ae695b elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="1ae695b" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-086c72f e-flex e-con-boxed e-con e-parent" data-id="086c72f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d8ddcde elementor-widget elementor-widget-heading" data-id="d8ddcde" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h3 class="elementor-heading-title elementor-size-default">How Franklin Web Technologies Can Help</h3>				</div>
				</div>
				<div class="elementor-element elementor-element-7990a59 elementor-widget elementor-widget-text-editor" data-id="7990a59" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email authentication is one of the first areas we assess when helping organizations improve their security posture. A short review often uncovers gaps that can be addressed quickly and with measurable impact.</p>

<p>Franklin Web Technologies helps businesses validate email sources, properly configure SPF, DKIM, and DMARC, and safely move domains to enforcement. Our approach focuses on reducing phishing risk, improving deliverability, and ensuring secure, trusted communication between organizations, employees, and customers.</p>

<p>If you are unsure whether your email authentication is fully enforced or want a second set of eyes, this is one of the highest value security improvements you can make.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6f7a6d8 elementor-button-success elementor-widget elementor-widget-button" data-id="6f7a6d8" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="https://franklinwebtech.com/contact/">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Request an Email Security Review</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/proper-email-configuration-security-control/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
