<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Franklin Web Technologies</title>
	<atom:link href="https://franklinwebtech.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://franklinwebtech.com</link>
	<description>Cloud Security Hardening for Microsoft 365 and Google Workspace</description>
	<lastBuildDate>Wed, 26 Aug 2026 06:18:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://franklinwebtech.com/wp-content/uploads/2025/12/cropped-Franklin_Web_Technologies-512x512-Logo-32x32.png</url>
	<title>Franklin Web Technologies</title>
	<link>https://franklinwebtech.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Google Workspace Security Checklist: What Should a Small Business Configure First? </title>
		<link>https://franklinwebtech.com/google-workspace-security-checklist/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Google Workspace Security]]></category>
		<category><![CDATA[2-Step Verification]]></category>
		<category><![CDATA[Google Drive sharing controls]]></category>
		<category><![CDATA[Google Workspace Security Checklist]]></category>
		<category><![CDATA[Google Workspace security monitoring]]></category>
		<category><![CDATA[Google Workspace security settings]]></category>
		<category><![CDATA[MFA for Google Workspace]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2125</guid>

					<description><![CDATA[A small business should start with the Google Workspace controls that protect administrator accounts, user sign-ins, business data, and access from unmanaged devices. The highest-priority work is enabling strong authentication, securing super administrator accounts, controlling external sharing, reviewing third-party access, and turning on useful security monitoring. This Google Workspace security checklist puts those controls into [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/google-workspace-security-checklist/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2125" class="elementor elementor-2125">
				<div class="elementor-element elementor-element-d746156 e-flex e-con-boxed e-con e-parent" data-id="d746156" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-e8c9095 elementor-widget elementor-widget-text-editor" data-id="e8c9095" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A small business should start with the Google Workspace controls that protect administrator accounts, user sign-ins, business data, and access from unmanaged devices. The highest-priority work is enabling strong authentication, securing super administrator accounts, controlling external sharing, reviewing third-party access, and turning on useful security monitoring. This Google Workspace security checklist puts those controls into a practical order so founders, office managers, and IT administrators can address the most serious gaps first. </p><p>For businesses that rely on Gmail, Drive, Docs, Meet, Calendar, and other Workspace services, security is largely shaped by configuration. A default setup may not reflect how your business actually operates. <a class="Hyperlink SCXW224474186 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> recommends treating Workspace security as an administrative responsibility, not simply an employee password issue. </p><h2><strong>Start With the Critical Settings</strong> </h2><p>The critical tier contains controls that should be addressed before spending time on lower-priority configuration. These settings reduce the risk of account takeover and limit the damage that can follow a compromised credential. </p><h3><strong>1. Enforce Multi-Factor Authentication</strong> </h3><p>A password alone should not protect an account containing company email, documents, customer information, financial records, and internal communications. Google calls its multi-factor authentication system 2-Step Verification, commonly referred to as MFA. </p><p>Google recommends 2-Step Verification for administrator accounts, particularly super administrators, because those accounts can control organization-wide data and settings. </p><p>For a small business, the practical configuration is to allow employees to enroll first, communicate the requirement clearly, and then enforce the policy across the organization. Administrators should also select authentication methods that provide strong phishing resistance. Passkeys and physical security keys provide stronger protection against phishing than traditional SMS verification codes.  </p><p>Your Google Workspace MFA policy should also account for recovery. Admins should have secure backup methods available before enforcement creates a situation where someone cannot access their account. </p><h3><strong>2. Protect Super Administrator Accounts</strong> </h3><p>A super administrator can make changes that affect every user in the Workspace environment. That makes these accounts particularly attractive to attackers. </p><p>Google recommends having more than one super administrator, with each account assigned to a separate person. It also recommends keeping super administrator accounts separate from everyday accounts.</p><p>Do not use an account such as <strong>admin@company.com </strong>as a shared login for several employees. Individual administrator accounts provide accountability in audit records and make it easier to identify who made a configuration change. </p><p>A sensible small-business setup includes: </p><ul><li><p>Separate admin and daily-use accounts for administrators. </p></li></ul><ul><li><p>At least two independently managed super administrator accounts. </p></li></ul><ul><li><p>More than one registered security key or another secure recovery method for critical admins. </p></li></ul><p>This is one of the most frequently overlooked areas of Google Workspace admin security. Businesses often secure employee accounts while leaving administrator access exposed. </p><h3><strong>3. Review Account Recovery Information</strong> </h3><p>Account recovery deserves attention because a secure authentication policy can still create operational problems if administrators lose access to their recovery methods. </p><p>Check recovery email addresses, phone numbers, security keys, passkeys, and backup codes for administrator accounts. Remove outdated recovery information and make sure backup methods are stored securely. </p><p>Google states that backup codes can help an administrator sign in if a security key or phone is unavailable. </p><p>Recovery details should belong to the correct individual or be managed under a documented business process. Avoid leaving recovery information tied to an employee who no longer works for the company. </p><h3><strong>4. Remove Old and Unused Accounts</strong> </h3><p>Former employees, contractors, temporary accounts, and abandoned test accounts can create unnecessary access to business systems. </p><p>Create a simple offboarding process that disables accounts promptly when someone leaves. Before deleting an account, review ownership of important Drive files, calendars, groups, and other business resources so information is not accidentally lost. </p><p>Also review accounts that have not been used for a long period. An unused account with active access is still an access point that needs attention. </p><p><strong>Important Settings That Limit Data Exposure</strong> </p><p>Once authentication and administrator access are under control, the next priority is reducing unnecessary access to company information. </p><h3><strong>5. Review Google Drive Sharing</strong> </h3><p>Drive makes collaboration easy, but broad sharing can expose sensitive information outside the organization. </p><p>Review your organization&#8217;s external sharing rules and determine who actually needs to share files with external users. Pay particular attention to confidential folders containing financial information, employee records, customer data, contracts, intellectual property, and operational documents. </p><p>Avoid treating &#8220;Anyone with the link&#8221; as a normal sharing method for sensitive material. A link can be forwarded beyond the original recipient, making it harder to control who ultimately sees the file. </p><p>A useful policy is to make internal sharing the normal option and require deliberate approval for sensitive external sharing. </p><h3><strong>6. Control Third-Party Application Access</strong> </h3><p>Employees often connect Workspace accounts to external applications for productivity, project management, document handling, scheduling, and other tasks. </p><p>The risk is not limited to the application itself. A connected application may receive permission to access parts of a user&#8217;s Google data. </p><p>Review third-party application access in the Admin console and remove applications that are unnecessary, outdated, or no longer approved. Establish an internal process for approving applications before employees connect them to company accounts. </p><p>Google has also removed support for less secure apps that authenticate using only a username and password for Google Workspace accounts. Since January 2025, businesses should use more secure authentication methods instead. </p><h3><strong>7. Secure Company Devices</strong> </h3><p>Account security becomes weaker if employees access Workspace from poorly protected computers. </p><p>Consider enabling Endpoint Verification for organizations that need visibility into devices accessing business data. Google says Endpoint Verification can provide administrators with information about devices and help control access based on device and security attributes. </p><p>The appropriate level of device control depends on your workforce. A company handling sensitive customer or financial information may need stricter device requirements than a small team working primarily with low-risk documents. </p><p>At minimum, establish requirements for screen locks, operating system updates, browser updates, device encryption where supported, and removal of company access from lost or retired devices. </p><h3><strong>8. Review External Email and Phishing Protection</strong> </h3><p>Gmail is one of the most valuable targets in a business account because an attacker can use a compromised mailbox to impersonate employees, intercept conversations, and send convincing messages to customers or suppliers. </p><p>Review Gmail security controls that help identify suspicious messages and consider additional protections for high-risk users. </p><p>Employees should also know how to report suspicious messages. Security technology can reduce exposure, but users still need a clear process for reporting unusual login requests, payment instructions, password prompts, and unexpected attachments. </p><p><strong>Recommended Settings for Ongoing Control</strong> </p><p>The recommended tier focuses on visibility, maintenance, and gradual improvement. These controls may not be the first settings you configure, but they help prevent security from becoming a one-time project. </p><h3><strong>9. Monitor the Admin and Security Audit Logs</strong> </h3><p>A Google Workspace security audit should not be limited to the day after an incident. </p><p>Review administrative actions, login activity, suspicious events, and other relevant security records regularly. Look for unusual administrator changes, unexpected sign-ins, unfamiliar applications, and activity involving accounts that should no longer be active. </p><p>The purpose is not to inspect every event manually. Establish a review routine and define which events require investigation. </p><h3><strong>10. Minimize Administrator Permissions</strong> </h3><p>Not every IT employee needs super administrator access. </p><p>Use administrator roles that provide only the permissions required for a person&#8217;s responsibilities. A person managing users may not need access to every security or billing function. </p><p>Reducing administrative privileges limits the number of accounts that can make high-impact changes and makes the environment easier to manage. </p><h3><strong>11. Review Groups and Mailing Lists</strong> </h3><p>Google Groups can quietly become a source of information exposure. </p><p>Review who can join groups, who can post, who can view conversations, and who manages each group. Pay special attention to groups used for finance, human resources, leadership, customer information, and internal operations. </p><p>Remove former employees and inactive accounts from groups during offboarding. </p><h3><strong>12. Establish a Security Alert Process</strong> </h3><p>Security alerts only help if someone reviews and acts on them. </p><p>Assign responsibility for monitoring important alerts and define what happens after an alert is received. A small company does not necessarily need a large security team, but someone should own the process. </p><p>Document escalation steps for suspicious sign-ins, compromised accounts, unauthorized application access, and unexpected administrative changes. </p><h2><strong>A Practical Priority Order for Small Businesses</strong> </h2><p>A security configuration is easier to maintain when administrators know what to do first. Rather than changing dozens of settings at once, use a staged process. </p><p><strong>Critical:</strong> Enforce MFA, protect super administrator accounts, secure account recovery, remove inactive accounts, and review administrator privileges. </p><p><strong>Important:</strong> Tighten Drive sharing, review third-party application access, secure devices, strengthen Gmail protections, and review groups. </p><p><strong>Recommended:</strong> Monitor audit logs, establish alert procedures, document security policies, and schedule recurring reviews. </p><p>This order gives small businesses a sensible starting point without turning security configuration into an overwhelming project. It also provides a useful framework for future Google Workspace security best practices. </p><h2><strong>Common Configuration Mistakes to Avoid</strong> </h2><p>Small businesses often make security harder than it needs to be by focusing on isolated settings instead of access. </p><p>One common mistake is creating a single shared administrator account. Shared credentials remove accountability and make it difficult to investigate administrative activity. </p><p>Another is enforcing MFA without preparing recovery options. Strong authentication is valuable, but administrators should have secure backup methods before a policy becomes mandatory. </p><p>Broad Drive sharing is another recurring issue. Employees may share files externally for convenience without realizing that sensitive information can remain accessible long after the original business need has ended. </p><p>Businesses also sometimes install security tools without reviewing Workspace&#8217;s own administrative controls. Third-party products can have a role, but basic Google Workspace security settings should be properly configured first. </p><p>Finally, avoid treating security as a setup task that ends after implementation. Employee turnover, new applications, device changes, and changes in business operations can all create new access risks. </p><h2><strong>How Often Should a Small Business Review Workspace Security?</strong> </h2><p>A basic review should take place at least quarterly, with more frequent checks for organizations handling sensitive information. </p><p>A recurring review can cover administrator accounts, inactive users, MFA enrollment, recovery methods, external sharing, third-party applications, groups, device access, and security alerts. </p><p>A more detailed review should follow major organizational changes such as acquisitions, leadership changes, large employee departures, new business applications, or a security incident. </p><p>Google&#8217;s administrative guidance also emphasizes ongoing monitoring, administrator account protection, and recovery preparation rather than relying on passwords alone.  </p><h2><strong>Build a Security Baseline That Fits Your Business</strong> </h2><p>There is no single Google Workspace configuration that fits every small business. A company managing public marketing material has different information risks from an accounting firm, healthcare organization, legal practice, or technology company. </p><p>Start by identifying your most sensitive information and the people who can access it. Then work outward through authentication, administrator permissions, data sharing, devices, applications, and monitoring. </p><p>That approach makes a secure Google Workspace environment easier to maintain because each control has a clear business purpose. </p><p>A well-configured Workspace environment should make the secure choice the normal choice. Employees should not need to understand every technical control, but administrators should know why access is granted, who can change it, and how suspicious activity will be handled. </p><h3><strong>Final Thoughts</strong> </h3><p>Small businesses do not need to configure every Google Workspace security feature on the first day. They need to address the controls that have the greatest effect on account access and business data first. </p><p>Start with MFA and administrator protection. Then tighten sharing, application access, device controls, and monitoring. Keep recovery methods current and review the environment on a recurring schedule. </p><p>For organizations that want an expert review, Franklin Web Technologies can help assess the current configuration, identify gaps, and prioritize practical improvements. A focused review can provide a clearer picture of your current security posture and the changes that deserve attention first. </p><p>If your business has not reviewed its Workspace configuration recently, <a class="Hyperlink SCXW224474186 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Request a Security Consultation</u></strong></a> and turn your security settings into a documented, repeatable baseline. </p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/google-workspace-security-checklist/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Is Conditional Access? A Small Business Guide to Microsoft 365 Login Security </title>
		<link>https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 18:00:00 +0000</pubDate>
				<category><![CDATA[Conditional Access]]></category>
		<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Microsoft 365 Conditional Access]]></category>
		<category><![CDATA[multi-factor authentication (MFA)]]></category>
		<category><![CDATA[What Is Conditional Access]]></category>
		<category><![CDATA[Zero Trust security]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2119</guid>

					<description><![CDATA[A stolen password should not automatically give someone access to Microsoft 365. What is Conditional Access is a question about how Microsoft can evaluate the circumstances around a sign-in and apply additional access requirements before allowing entry. Microsoft Conditional Access uses signals such as the user, device, location, application, and sign-in risk to determine what [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2119" class="elementor elementor-2119">
				<div class="elementor-element elementor-element-2da8daa e-flex e-con-boxed e-con e-parent" data-id="2da8daa" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-f458740 elementor-widget elementor-widget-text-editor" data-id="f458740" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A stolen password should not automatically give someone access to Microsoft 365. What is Conditional Access is a question about how Microsoft can evaluate the circumstances around a sign-in and apply additional access requirements before allowing entry. Microsoft Conditional Access uses signals such as the user, device, location, application, and sign-in risk to determine what access should be allowed. </p><p>For a small business, this can mean requiring MFA for administrators, blocking access from untrusted locations, requiring managed devices for sensitive resources, or responding differently to risky sign-ins. <a class="Hyperlink SCXW138293303 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> helps businesses understand and configure these Microsoft 365 login security controls around their actual working environment. </p><h2><strong>What Is Conditional Access in Microsoft 365?</strong> </h2><p>Conditional Access is a policy-based access control feature in Microsoft Entra ID. It works through an &#8220;if-then&#8221; model: if specific conditions are present during a sign-in, then Microsoft applies a defined access requirement. </p><p>For example, a business could create a policy that says: if an employee signs in to Microsoft 365 from an unfamiliar device, require MFA before granting access. Another policy could require a company-managed device before someone can access sensitive business information. </p><p>Microsoft describes Conditional Access as its Zero Trust policy engine because it uses multiple signals to make access decisions instead of treating every successful password authentication as sufficient. </p><p>The policies can grant access, require additional controls, or block access altogether. Administrators can also apply session controls that influence how a user remains signed in or interacts with selected cloud applications. </p><h2><strong>Why Does Conditional Access Matter for Small Businesses?</strong> </h2><p>Many small businesses start with a basic combination of usernames, passwords, and MFA. MFA is an essential layer, but it does not answer every access question. </p><p>A valid username and password can still be used from an unmanaged computer. A compromised account can still be accessed from an unusual location. An administrator might sign in from a device that does not meet the organization&#8217;s requirements. </p><p>Conditional Access adds context to the login decision. </p><p>Instead of asking only, &#8220;Did this person provide the correct credentials?&#8221; an access policy can consider questions such as: </p><ul><li><p>Who is signing in? </p></li></ul><ul><li><p>What application or resource are they trying to access? </p></li></ul><ul><li><p>What device are they using? </p></li></ul><ul><li><p>Where is the sign-in coming from? </p></li></ul><ul><li><p>Is the sign-in showing elevated risk? </p></li></ul><ul><li><p>What additional authentication or device requirement should apply? </p></li></ul><p>This approach supports identity security by making access decisions based on the circumstances surrounding each request. </p><h2><strong>How Do Conditional Access Policies Work?</strong> </h2><p>Conditional Access policies contain assignments and access controls. Assignments establish the circumstances under which a policy applies, while access controls determine what happens when those circumstances are met. </p><p>An administrator can target specific users or groups, applications, device platforms, locations, and other conditions. The policy can then require MFA, require a compliant device, block access, or apply another supported control. </p><p>For example: </p><p><strong>Condition:</strong> An employee accesses Microsoft 365 from an unmanaged device. </p><p><strong>Action:</strong> Require MFA and a compliant device before granting access. </p><p>Several Conditional Access policies can apply to the same sign-in. Microsoft evaluates the applicable requirements, so a user may need to satisfy more than one condition before access is granted. </p><p>This is useful for businesses that need different rules for administrators, office staff, contractors, remote workers, and users accessing sensitive applications. </p><h2><strong>Conditional Access vs MFA: What Is the Difference?</strong> </h2><p>The distinction in MFA vs Conditional Access is straightforward. </p><p>MFA verifies that the person signing in can provide an additional authentication factor. Conditional Access determines when that additional requirement, or another access control, should be applied. </p><p>MFA can be viewed as an authentication method. Conditional Access is the policy layer that decides how and when access requirements are enforced. </p><p>For example, a company could require MFA for every user. It could then use Conditional Access to add another rule requiring administrators to use MFA when accessing administrative resources or requiring a compliant device for sensitive applications. </p><p>Microsoft&#8217;s Conditional Access grant controls include requirements such as MFA, authentication strength, device compliance, an approved client application, an app protection policy, or a password change. Administrators can also choose to block access. </p><p>That makes Conditional Access broader than simply turning on MFA. </p><h2><strong>Practical Conditional Access Policies for a Small Business</strong> </h2><p>A small business does not need dozens of complicated access policies to establish a stronger baseline. The useful starting point is a small set of policies that address common access risks. </p><h3><strong>Require MFA for Administrators</strong> </h3><p>Administrator accounts can change settings, manage users, and control business resources. Requiring MFA for these accounts creates an additional verification step before privileged access is granted. </p><p>Microsoft lists requiring MFA for administrators among its common Conditional Access policies. </p><p>For organizations with stronger authentication requirements, authentication strength policies can also be used to define the type of authentication required. </p><h3><strong>Block Legacy Authentication</strong> </h3><p>Older authentication protocols may not support modern authentication requirements. Blocking legacy authentication prevents users from accessing Microsoft 365 through methods that cannot properly satisfy modern controls. </p><p>Microsoft identifies blocking legacy authentication as a common Conditional Access policy and includes it in its recommended policy templates. </p><p>This is especially useful during Microsoft 365 hardening because a business can remove an older access path instead of relying only on passwords and MFA. </p><h3><strong>Require Managed or Compliant Devices</strong> </h3><p>A password and MFA do not tell an organization if the device being used is managed or meets its device requirements. </p><p>Conditional Access can require a device to be marked compliant before granting access. This can be useful for employees accessing sensitive Microsoft 365 resources from company-managed computers. </p><p>The exact device requirement depends on how the organization manages its endpoints and which Microsoft services and licenses it uses. </p><h3><strong>Respond to Risky Sign-Ins</strong> </h3><p>Microsoft Entra ID can provide risk signals that Conditional Access policies use to respond to suspicious authentication activity. For organizations with the required licensing, risk-based policies can require MFA for elevated sign-in risk or take other corrective action. </p><p>This creates a more responsive access policy. A familiar sign-in may follow the normal authentication process, while a sign-in presenting elevated risk can trigger an additional requirement. </p><h2><strong>Can Conditional Access Block Access?</strong> </h2><p>Yes. Conditional Access can block access when a defined condition is met. </p><p>For example, an organization could create a policy that blocks access from selected locations. Microsoft supports location-based policies that can use network location information to control access to cloud applications. </p><p>Blocking access requires careful testing because an overly broad policy can prevent legitimate users from reaching Microsoft 365. Microsoft recommends using report-only mode and testing policy impact before enabling restrictive policies. </p><p>Businesses should also maintain emergency access accounts that are excluded appropriately from policies to reduce the chance of administrators being locked out after a configuration mistake. </p><h2><strong>Conditional Access and Zero Trust</strong> </h2><p>Zero Trust is based on verifying access rather than assuming that a user should be trusted simply because they have valid credentials or are connecting from a familiar network. </p><p>Conditional Access supports this model by evaluating identity, device, application, location, and risk signals before enforcing access requirements. </p><p>For a small business, Zero Trust does not mean creating an enormous collection of complicated rules. It can begin with practical decisions such as requiring MFA for privileged accounts, blocking legacy authentication, restricting access from unmanaged devices where appropriate, and responding to high-risk sign-ins. </p><p>The objective is to make access decisions based on evidence rather than treating every successful password login the same way. </p><h2><strong>How Should a Small Business Start?</strong> </h2><p>Conditional Access should be introduced carefully. A policy that looks reasonable on paper can behave differently once it encounters real users, devices, applications, and sign-in patterns. </p><p>Start by identifying the accounts and resources that require the strongest protection. Administrators should usually receive stricter controls than ordinary users because they have broader permissions. </p><p>Next, review the devices employees use to access Microsoft 365. If the company manages its devices through Microsoft Intune, device compliance can become part of access decisions. </p><p>Then review sign-in locations and authentication methods. Unusual locations, older authentication protocols, and elevated sign-in risk can provide useful signals for additional controls. </p><p>Before activating restrictive policies, use report-only mode and test them with designated users. Microsoft specifically recommends maintaining a test user and validating policies before deployment. </p><p>A practical rollout can follow this order: </p><ol><li><p>Protect administrator accounts with MFA and stronger authentication requirements. </p></li></ol><ol start="2"><li><p>Block legacy authentication and review sign-in activity. </p></li></ol><ol start="3"><li><p>Apply device and application requirements to sensitive resources. </p></li></ol><ol start="4"><li><p>Add risk-based policies where the required Microsoft Entra licensing is available. </p></li></ol><ol start="5"><li><p>Review policies regularly as users, devices, applications, and business requirements change. </p></li></ol><p>This approach keeps the initial configuration manageable while creating room for more specific access policies later. </p><h2><strong>Common Conditional Access Mistakes to Avoid</strong> </h2><p>The biggest problems often come from policy design rather than the feature itself. </p><p>One common mistake is creating broad block policies without testing them. A rule that blocks an entire location, user group, or application can affect legitimate business activity. </p><p>Another issue is applying too many policies at once. Multiple policies can affect the same sign-in, so administrators need to understand how assignments overlap and which requirements users must satisfy. </p><p>Excluding emergency access accounts is also an important safeguard. These accounts provide a recovery path if a configuration error prevents normal administrative access. </p><p>Businesses should also avoid treating Conditional Access as a replacement for every other Microsoft 365 security control. Strong authentication, appropriate account privileges, device management, secure configuration, monitoring, and regular reviews all contribute to a safer environment. </p><h2><strong>What Does Conditional Access Mean for Your Business?</strong> </h2><p>For an SMB, Conditional Access is essentially a set of rules that determines when a Microsoft 365 login should be allowed, challenged, restricted, or blocked. </p><p>Its value comes from adding context to authentication. A user with valid credentials may receive different access requirements depending on the device, application, location, identity, and risk associated with the sign-in. </p><p>That makes Conditional Access a practical part of Microsoft 365 login security and identity security. Instead of applying the same login rule to every situation, businesses can create access policies that reflect the sensitivity of their resources and the circumstances of each sign-in. </p><p>Franklin Web Technologies can help businesses review their Microsoft 365 configuration, identify gaps in Conditional Access policies, and prioritize controls that fit their users and working environment. </p><h2><strong>Build a More Controlled Microsoft 365 Login Environment</strong> </h2><p>Conditional Access gives small businesses a practical way to move beyond password-based access decisions. The most useful policies are not necessarily the most complicated ones. Strong administrator protection, modern authentication, sensible device requirements, legacy authentication blocking, and risk-based controls can establish a solid foundation. </p><p>The right configuration also requires testing and ongoing review. Microsoft recommends validating policies before enforcement because poorly designed rules can interrupt legitimate access. </p><p>For businesses that want a clearer assessment of their Microsoft 365 access policies, <a class="Hyperlink SCXW138293303 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Request a Security Consultation</u></strong></a> to review your current configuration and identify practical improvements. </p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/what-is-conditional-access-a-small-business-guide-to-microsoft-365-login-security/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Microsoft 365 Security Checklist: 15 Settings Every Small Business Should Review</title>
		<link>https://franklinwebtech.com/microsoft-365-security-checklist/</link>
		
		<dc:creator><![CDATA[analytics11]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 06:17:57 +0000</pubDate>
				<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Microsoft 365 Security Checklist]]></category>
		<category><![CDATA[Microsoft 365 security settings]]></category>
		<category><![CDATA[Microsoft Entra ID MFA]]></category>
		<category><![CDATA[small business Microsoft 365 security]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=2112</guid>

					<description><![CDATA[A secure Microsoft 365 tenant depends on more than turning on multifactor authentication. Small businesses also need to review administrator privileges, legacy authentication, external forwarding, application permissions, audit logging, email protection, and sharing controls. This Microsoft 365 security checklist highlights 15 settings that are easy to overlook but can have a direct effect on account [&#8230;]<p>Read more at <a href="https://franklinwebtech.com/microsoft-365-security-checklist/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="2112" class="elementor elementor-2112">
				<div class="elementor-element elementor-element-ce89c04 e-flex e-con-boxed e-con e-parent" data-id="ce89c04" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-b845b5b elementor-widget elementor-widget-text-editor" data-id="b845b5b" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p data-pm-slice="1 1 []">A secure Microsoft 365 tenant depends on more than turning on multifactor authentication. Small businesses also need to review administrator privileges, legacy authentication, external forwarding, application permissions, audit logging, email protection, and sharing controls. This Microsoft 365 security checklist highlights 15 settings that are easy to overlook but can have a direct effect on account compromise, data exposure, and business continuity. <a class="Hyperlink SCXW101006295 BCX0" href="https://franklinwebtech.com/" target="_blank" rel="noreferrer noopener"><strong><u>Franklin Web Technologies</u></strong></a> uses this type of configuration-focused review to help businesses identify gaps that basic security setup can leave behind. </p><h2><strong>1. Confirm that MFA protects every user</strong> </h2><p>Multifactor authentication should cover regular users, administrators, contractors, and other accounts that can access business data. A password alone provides limited protection against phishing, password spraying, and reused credentials. </p><p>Businesses without Microsoft Entra ID P1 or P2 can use Security Defaults as a baseline. Security Defaults require MFA registration and block several older authentication methods. Organizations with Microsoft Entra ID P1 or higher can use Conditional Access for more granular policies. </p><p><strong>Example configuration:</strong> </p><p>Microsoft Entra admin center &gt; Entra ID &gt; Overview &gt; Properties &gt; Manage security defaults </p><p>Do not assume MFA is active simply because some employees receive authentication prompts. Check the tenant configuration and sign-in reports to verify coverage. </p><h2><strong>2. Review the authentication methods employees can register</strong> </h2><p>MFA is only as strong as the authentication methods behind it. Microsoft 365 administrators should review which methods users can register and remove methods that do not fit the organization&#8217;s security requirements. </p><p>For privileged users, phishing-resistant methods such as passkeys or FIDO2 security keys provide stronger protection against phishing than methods that depend entirely on passwords or approval prompts. </p><p>A useful Microsoft 365 security assessment should identify users with weak, outdated, or unnecessary authentication methods and verify that recovery options are also controlled. </p><h2><strong>3. Protect administrator accounts separately</strong> </h2><p>A Global Administrator account should not be the same account used for routine email, Teams conversations, web browsing, and document work. </p><p>Create dedicated administrator accounts and assign only the roles required for administrative duties. Microsoft recommends least-privileged administrative roles as part of identity security guidance. </p><p>Review the following: </p><ul><li><p>Global Administrator assignments </p></li></ul><ul><li><p>Exchange Administrator assignments </p></li></ul><ul><li><p>Security Administrator assignments </p></li></ul><ul><li><p>Privileged Role Administrator assignments </p></li></ul><ul><li><p>Inactive administrator accounts </p></li></ul><p>This is a central part of Microsoft 365 admin security because a compromised administrator account can affect far more than one employee&#8217;s mailbox. </p><h2><strong>4. Create and test emergency access accounts</strong> </h2><p>An emergency access account is designed for situations such as an administrator lockout or authentication-policy failure. It should not become someone&#8217;s everyday account. </p><p>Microsoft recommends maintaining at least two cloud-only emergency access accounts, protecting them with phishing-resistant authentication, storing credentials securely, monitoring their use, and validating them regularly. </p><p><strong>Example:</strong> </p><p>Create two dedicated <strong>.onmicrosoft.com </strong>accounts, document their purpose, secure their credentials separately, and test access at least every 90 days. </p><p>These accounts should be treated as controlled recovery mechanisms, not spare administrator accounts. </p><h2><strong>5. Block legacy authentication</strong> </h2><p>Legacy authentication is one of the settings that deserves immediate attention during Microsoft 365 hardening. </p><p>Older protocols such as POP3, IMAP, and other basic authentication methods do not support modern security controls such as MFA. Microsoft specifically recommends blocking legacy authentication because attackers can use these protocols to bypass protections applied to modern sign-ins. </p><p>Check sign-in logs before enforcing the policy. Identify devices, applications, scanners, or other services still relying on older authentication and migrate them first. </p><h2><strong>6. Review device code authentication</strong> </h2><p>Device code authentication can be useful for devices with limited input capabilities, but it can also be abused in phishing attacks. Microsoft Security Defaults block device code flow as part of their baseline protections. </p><p>Organizations using Conditional Access should review policies covering device code authentication and determine if any legitimate business process requires an exception. </p><p>An overlooked authentication flow can give an attacker another route into a tenant even after conventional MFA controls are enabled. </p><h2><strong>7. Limit unnecessary application consent</strong> </h2><p>Employees can sometimes grant applications access to Microsoft 365 data. An employee may approve an application without realizing that the permission allows access to mail, files, calendars, contacts, or other organizational information. </p><p>Review Microsoft Entra application consent settings and decide who can approve applications. For higher-risk permissions, route requests through administrator approval. </p><p><strong>Example policy approach:</strong> </p><p>Require administrator approval for applications requesting sensitive Microsoft Graph permissions. </p><p>This reduces the chance that a malicious or poorly configured third-party application becomes an indirect path to business data. </p><h2><strong>8. Review inactive users and guest accounts</strong> </h2><p>Old employee accounts, dormant users, former contractors, and unused guest accounts increase the number of identities that need protection. </p><p>Run regular reviews of: </p><ul><li><p>Disabled and inactive accounts </p></li></ul><ul><li><p>Guest users </p></li></ul><ul><li><p>Users with administrative roles </p></li></ul><ul><li><p>Accounts that have not signed in for extended periods </p></li></ul><p>Microsoft&#8217;s identity security recommendations specifically include removing dormant accounts from sensitive groups and using least-privileged administrative roles. </p><p>Account cleanup should be part of normal Microsoft 365 administration rather than an occasional security project. </p><h2><strong>9. Check external email forwarding</strong> </h2><p>Automatic forwarding deserves special attention because it can quietly move company information outside the tenant. </p><p>Microsoft identifies automatic forwarding to external recipients as a security concern because it can expose organizational information. Users can create forwarding through inbox rules, while administrators can configure mailbox forwarding. </p><p>Review existing forwarding rules and determine which external destinations are legitimate. </p><p><strong>Example check:</strong> </p><p>Exchange admin center &gt; Mail flow &gt; Remote domains / outbound spam policies </p><p>For most small businesses, external automatic forwarding should be restricted unless there is a documented business requirement. </p><h2><strong>10. Tighten external sharing in SharePoint and OneDrive</strong> </h2><p>SharePoint and OneDrive can contain contracts, financial documents, customer information, employee records, and internal procedures. A permissive sharing configuration can make sensitive files accessible outside the organization. </p><p>Review default sharing links, guest access, anonymous links, and domain restrictions. Apply stricter controls to sites containing confidential information. </p><p>A useful configuration principle is simple: users should have an easy internal sharing process while external access requires a clear business reason. </p><h2><strong>11. Turn on the right email protection policies</strong> </h2><p>Microsoft Defender for Office 365 provides controls such as Safe Links, Safe Attachments, and enhanced anti-phishing protection. Microsoft notes that the built-in protection preset provides basic Safe Links and Safe Attachments protection for eligible Defender customers, while Standard and Strict preset policies provide stronger configurations. </p><p>Review: </p><ul><li><p>Anti-phishing policies </p></li></ul><ul><li><p>Impersonation protection </p></li></ul><ul><li><p>Safe Links </p></li></ul><ul><li><p>Safe Attachments </p></li></ul><ul><li><p>Anti-malware policies </p></li></ul><p>Pay particular attention to executive accounts, finance users, and employees who frequently handle payment or customer information. </p><h2><strong>12. Protect against impersonation attacks</strong> </h2><p>A basic spam filter does not address every impersonation scenario. Attackers may imitate executives, suppliers, domains, or trusted contacts to convince employees to transfer money or disclose information. </p><p>Microsoft Defender for Office 365 supports impersonation protection through its security policies. The default anti-phishing policy includes spoof protection and mailbox intelligence, while additional impersonation controls require configuration through preset or custom policies. </p><p>Add high-value users and important business domains to the appropriate protection policies and review alerts regularly. </p><h2><strong>13. Verify that audit logging is useful</strong> </h2><p>Audit logs are valuable only when the organization knows what activity it needs to investigate. </p><p>Confirm that auditing is available and that administrators know where to review activity involving users, administrators, mailboxes, applications, and other Microsoft 365 services. </p><p>A security review should also establish a basic retention and investigation process. Suspicious sign-ins, unexpected permission changes, forwarding rules, and administrator actions should have a clear path for investigation. </p><p>For emergency access accounts, Microsoft specifically recommends monitoring sign-in and audit logs. </p><h2><strong>14. Review Microsoft Secure Score instead of ignoring it</strong> </h2><p>Microsoft Secure Score provides a useful starting point for identifying security improvements. The identity portion evaluates configuration against recommended controls and recalculates based on the tenant&#8217;s security posture. </p><p>Do not treat the score as a complete security rating. A high score does not prove that every important business risk has been addressed. </p><p>Use it as a review queue. Prioritize recommendations based on the sensitivity of your data, user roles, current threats, licensing, and operational requirements. </p><h2><strong>15. Review Conditional Access policies for gaps and exceptions</strong> </h2><p>Conditional Access can apply rules based on factors such as user, application, device, location, and authentication requirements. The danger is not only missing policies. Poorly managed exclusions can create the same problem. </p><p>Review every policy for: </p><ul><li><p>Users or groups excluded from MFA </p></li></ul><ul><li><p>Emergency access exclusions </p></li></ul><ul><li><p>Legacy authentication blocks </p></li></ul><ul><li><p>Administrator protection </p></li></ul><ul><li><p>Unmanaged device access </p></li></ul><ul><li><p>Report-only policies that were never enforced </p></li></ul><p>Microsoft recommends using Conditional Access when organizations need more customization than Security Defaults provides. </p><p>Document every exception and assign an owner. An exception without an owner can remain in place long after the original business need has disappeared. </p><h3><strong>How To Turn The Checklist Into A Practical Security Review</strong> </h3><p>A useful Microsoft 365 security assessment should not stop at checking boxes. Record the current configuration, identify the business reason for exceptions, assign a responsible administrator, and set a review date. </p><p>For example, a small business might find that MFA is enabled for employees but three administrator accounts are excluded from a Conditional Access policy. Another review might uncover external forwarding from an old mailbox or guest accounts that have not been used for months. </p><p>Those findings have different levels of urgency, so prioritize them by business impact. An administrator account without strong authentication generally deserves faster remediation than a low-risk configuration preference. </p><p>Franklin Web Technologies can use this configuration-first approach to help businesses examine Microsoft 365 security settings beyond the obvious controls. The goal is to identify settings that attackers could exploit and translate technical findings into practical actions for the business. </p><h2><strong>A Simple Review Schedule For Small Businesses </strong></h2><p>Security settings should be reviewed after major Microsoft 365 changes, administrator changes, new applications, acquisitions, employee departures, and significant changes to how staff access company data. </p><p>A quarterly review can cover administrator roles, inactive users, guest accounts, authentication methods, forwarding rules, Conditional Access exclusions, external sharing, and Defender policies. A deeper annual review can examine the complete tenant configuration and compare it against current Microsoft 365 security best practices. </p><p>The process also gives business owners a clearer picture of their Microsoft 365 security risks instead of relying on assumptions about default protection. </p><h2><strong>Final Thoughts</strong> </h2><p>Microsoft 365 can provide strong built-in security, but secure configuration still requires attention. MFA, administrator protection, legacy authentication controls, forwarding restrictions, application consent, email defenses, sharing policies, and audit visibility all contribute to a safer tenant. </p><p>The most effective checklist is one that reflects how your business actually uses Microsoft 365. Review the settings, document exceptions, remove unnecessary access, and test recovery controls instead of assuming they work. </p><p>For small businesses that need a more detailed review or assistance with secure Microsoft 365 for small business, <a class="Hyperlink SCXW101006295 BCX0" href="https://franklinwebtech.com/contact/" target="_blank" rel="noreferrer noopener"><strong><u>Contact Us Now</u></strong></a> to discuss your Microsoft 365 configuration and identify practical security improvements.</p>								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/microsoft-365-security-checklist/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Plugging the Holes: Protect Your Business with Defender</title>
		<link>https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/</link>
		
		<dc:creator><![CDATA[Martin Franklin]]></dc:creator>
		<pubDate>Thu, 08 Jan 2026 15:52:55 +0000</pubDate>
				<category><![CDATA[Endpoint Security]]></category>
		<category><![CDATA[Malware Protection]]></category>
		<category><![CDATA[Microsoft 365 Security]]></category>
		<category><![CDATA[Phishing Prevention]]></category>
		<category><![CDATA[Microsoft Defender]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[Security Hardening]]></category>
		<category><![CDATA[SMB Cybersecurity]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=1925</guid>

					<description><![CDATA[Small businesses are prime targets for phishing, malware, and malicious links. Learn how Microsoft Defender for Office 365 helps block these threats—and how Franklin Web Technologies can make cybersecurity simple and affordable for your business.
<p>Read more at <a href="https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="1925" class="elementor elementor-1925">
				<div class="elementor-element elementor-element-04139f6 e-flex e-con-boxed e-con e-parent" data-id="04139f6" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-49a5b0c elementor-widget elementor-widget-image" data-id="49a5b0c" data-element_type="widget" data-e-type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img fetchpriority="high" decoding="async" width="1024" height="683" src="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-1024x683.png" class="attachment-large size-large wp-image-1940" alt="Cybersecurity illustration showing Microsoft Defender protecting business devices from threats" srcset="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-1024x683.png 1024w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-300x200.png 300w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender-768x512.png 768w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_protect_with_ms_defender.png 1536w" sizes="(max-width: 1024px) 100vw, 1024px"  title="Plugging the Holes: Protect Your Business with Defender" />															</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-d61b811 e-flex e-con-boxed e-con e-parent" data-id="d61b811" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-eb12cdb elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="eb12cdb" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-4e023bc e-flex e-con-boxed e-con e-parent" data-id="4e023bc" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-5cae850 elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor" data-id="5cae850" data-element_type="widget" data-e-type="widget" data-settings="{&quot;drop_cap&quot;:&quot;yes&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Small businesses are prime targets. Cybercriminals know many small businesses don’t have dedicated IT teams. A single click can lead to <strong>data breaches, ransomware, and financial loss</strong>.</p><p>Let’s break down the <strong>three biggest threats</strong> and how <a href="https://www.microsoft.com/en-us/security/business/siem-and-xdr/microsoft-defender-office-365" target="_blank" rel="noopener">Microsoft Defender for Office 365</a> helps you stop them.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-bad0d07 elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="bad0d07" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-348e50b e-flex e-con-boxed e-con e-parent" data-id="348e50b" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-3c443de elementor-widget elementor-widget-heading" data-id="3c443de" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Phishing Emails – The Silent Trap</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-ff2bc37 elementor-widget elementor-widget-text-editor" data-id="ff2bc37" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Story:</strong><br />You’re managing invoices when an email arrives from what looks like your bank. It says there’s an urgent issue and asks you to click a link. You click, enter your details—and attackers now have your credentials.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Phishing" target="_blank" rel="noopener">Phishing</a> emails trick you into giving away passwords or sensitive info. They look legitimate and urgent.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6b6ca88 elementor-widget elementor-widget-text-editor" data-id="6b6ca88" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-9d6393f elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="9d6393f" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks suspicious emails before they hit your inbox</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text"> Real-time alerts for potential scams</span>
									</li>
						</ul>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-22da420 e-flex e-con-boxed e-con e-parent" data-id="22da420" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-62a5097 elementor-widget elementor-widget-heading" data-id="62a5097" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Malware – The Hidden Enemy</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-bab594f elementor-widget elementor-widget-text-editor" data-id="bab594f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Scenario:</strong><br />An invoice attachment from a “vendor” arrives. One click, and malware installs on your system, stealing data or locking files for ransom.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Malware" target="_blank" rel="noopener">Malware</a> can cripple your business overnight.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-8c94d9a elementor-widget elementor-widget-text-editor" data-id="8c94d9a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-e98f650 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="e98f650" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Scans every attachment for malicious code</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks harmful files before you open them</span>
									</li>
						</ul>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-2c2e7d0 e-flex e-con-boxed e-con e-parent" data-id="2c2e7d0" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d12929d elementor-widget elementor-widget-heading" data-id="d12929d" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Malicious URLs – The Click That Costs You</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-be62dcb elementor-widget elementor-widget-text-editor" data-id="be62dcb" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><strong>Scenario:</strong><br />Links in emails or chats lead to fake websites that capture your login details or install spyware.</p><p><strong>Why It Matters:</strong><br /><a href="https://en.wikipedia.org/wiki/Spoofed_URL" target="_blank" rel="noopener">Malicious URL</a> attacks often bypass basic spam filters.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5881e1a elementor-widget elementor-widget-text-editor" data-id="5881e1a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<strong>Defender&#8217;s Protection:</strong>								</div>
				</div>
				<div class="elementor-element elementor-element-1589d92 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="1589d92" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Safe Links technology rewrites and checks URLs in real time</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check"></i>						</span>
										<span class="elementor-icon-list-text">Blocks access to dangerous sites—even after you click</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-493bce1 elementor-widget elementor-widget-text-editor" data-id="493bce1" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Don’t wait until an attack happens. Let’s make your business resilient today.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-e68ba2c elementor-button-success elementor-widget elementor-widget-button" data-id="e68ba2c" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="/contact/">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Schedule a Consultation</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/plugging-the-holes-protect-your-business-with-defender/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Proper Email Configuration Is an Underrated Security Control</title>
		<link>https://franklinwebtech.com/proper-email-configuration-security-control/</link>
		
		<dc:creator><![CDATA[Martin Franklin]]></dc:creator>
		<pubDate>Mon, 29 Dec 2025 17:29:43 +0000</pubDate>
				<category><![CDATA[Email Security]]></category>
		<category><![CDATA[Phishing & Identity Protection]]></category>
		<category><![CDATA[Business email compromise]]></category>
		<category><![CDATA[Deliverability and trust topics]]></category>
		<category><![CDATA[DKIM]]></category>
		<category><![CDATA[DMARC]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[SPF]]></category>
		<guid isPermaLink="false">https://franklinwebtech.com/?p=1838</guid>

					<description><![CDATA[Learn why email authentication protocols like SPF, DKIM and DMARC are essential for email security, reducing phishing risk and improving deliverability.<p>Read more at <a href="https://franklinwebtech.com/proper-email-configuration-security-control/">Franklin Web Technologies</a></p>]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="1838" class="elementor elementor-1838">
				<div class="elementor-element elementor-element-93ee3e5 e-flex e-con-boxed e-con e-parent" data-id="93ee3e5" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-7dea597 elementor-widget elementor-widget-image" data-id="7dea597" data-element_type="widget" data-e-type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
															<img decoding="async" width="1024" height="683" src="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-1024x683.webp" class="attachment-large size-large wp-image-1888" alt="Email security illustration showing SPF DKIM and DMARC protection" srcset="https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-1024x683.webp 1024w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-300x200.webp 300w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security-768x512.webp 768w, https://franklinwebtech.com/wp-content/uploads/2026/01/fwt_email_security.webp 1536w" sizes="(max-width: 1024px) 100vw, 1024px"  title="Proper Email Configuration Is an Underrated Security Control" />															</div>
				</div>
				<div class="elementor-element elementor-element-31c3c29 elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="31c3c29" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-87e305f e-flex e-con-boxed e-con e-parent" data-id="87e305f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-23b14e9 elementor-drop-cap-yes elementor-drop-cap-view-default elementor-widget elementor-widget-text-editor" data-id="23b14e9" data-element_type="widget" data-e-type="widget" data-settings="{&quot;drop_cap&quot;:&quot;yes&quot;}" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email remains the most trusted communication channel in business, yet it is also the most commonly exploited. Properly configured email authentication is one of the simplest and most effective ways to reduce phishing and impersonation risk.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-d7681cf elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="d7681cf" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-9dbb68f e-flex e-con-boxed e-con e-parent" data-id="9dbb68f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d8812ed elementor-widget elementor-widget-heading" data-id="d8812ed" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Understanding Email Authentication</h2>				</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-d70e068 e-flex e-con-boxed e-con e-parent" data-id="d70e068" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-4bae726 elementor-widget elementor-widget-text-editor" data-id="4bae726" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email authentication technologies like <a href="https://en.wikipedia.org/wiki/Sender_Policy_Framework" target="_blank" rel="noopener">SPF</a>, <a href="https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail" target="_blank" rel="noopener">DKIM</a>, and <a href="https://en.wikipedia.org/wiki/DMARC" target="_blank" rel="noopener">DMARC</a> are designed to verify that email messages are legitimately sent from authorized sources. Together, they help receiving mail systems answer a critical question before delivering a message to an inbox: Can this sender be trusted?</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a59b003 elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="a59b003" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">SPF specifies which mail servers are allowed to send email on behalf of your domain</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">DKIM ensures messages have not been altered in transit</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-shield-alt"></i>						</span>
										<span class="elementor-icon-list-text">DMARC ties these controls together and defines how failed authentication should be handled</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-5a57198 elementor-widget elementor-widget-text-editor" data-id="5a57198" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									When implemented and enforced correctly, these controls significantly reduce the ability for attackers to impersonate your domain.								</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-a86eb59 e-flex e-con-boxed e-con e-parent" data-id="a86eb59" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d403e8a elementor-widget elementor-widget-heading" data-id="d403e8a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Why DMARC Matters</h2>				</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-760275e e-flex e-con-boxed e-con e-parent" data-id="760275e" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-416e83f elementor-widget elementor-widget-text-editor" data-id="416e83f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><a href="https://en.wikipedia.org/wiki/DMARC" target="_blank" rel="noopener">DMARC</a> goes beyond basic authentication by adding policy enforcement and reporting. It allows domain owners to instruct receiving mail systems on what to do when authentication fails and provides visibility into all systems attempting to send email using the domain.</p><p>Organizations that fully implement DMARC see tangible benefits:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-5da0ee1 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="5da0ee1" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Reduced phishing and spoofing attempts using their domain</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Improved trust with customers, partners, and vendors</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Better email deliverability and fewer messages routed to spam</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Clear visibility into third party email services</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<i aria-hidden="true" class="fas fa-check-circle"></i>						</span>
										<span class="elementor-icon-list-text">Stronger protection for employees against impersonation attacks</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-25ef0bb elementor-widget elementor-widget-text-editor" data-id="25ef0bb" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									In many cases, organizations are surprised to discover how many unknown or misconfigured systems are sending email on their behalf.								</div>
				</div>
		<div class="elementor-element elementor-element-5512c10 e-con-full e-flex e-con e-child" data-id="5512c10" data-element_type="container" data-e-type="container" data-settings="{&quot;background_background&quot;:&quot;gradient&quot;}">
				<div class="elementor-element elementor-element-1748b5a elementor-widget elementor-widget-heading" data-id="1748b5a" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h3 class="elementor-heading-title elementor-size-default">"The risk is not misconfiguration.<br>
The risk is incomplete enforcement."</h3>				</div>
				</div>
				</div>
				<div class="elementor-element elementor-element-90c00f6 elementor-widget elementor-widget-heading" data-id="90c00f6" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">The Most Common Oversight</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-fe85683 elementor-widget elementor-widget-text-editor" data-id="fe85683" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>A frequent issue we encounter is incomplete implementation. SPF records are outdated, DKIM is enabled for only one platform, and DMARC is left in monitoring mode indefinitely. Over time, new services are added such as CRMs, marketing platforms, payroll providers, or support tools, but email authentication is never revisited.</p>

<p>Attackers take advantage of this gap.</p>

<p>Without enforcement, fraudulent emails can still appear legitimate to recipients, increasing the likelihood of successful phishing attempts.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-a6ca616 elementor-widget elementor-widget-heading" data-id="a6ca616" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">A Small Investment With Significant Impact</h2>				</div>
				</div>
				<div class="elementor-element elementor-element-4ce60d3 elementor-widget elementor-widget-text-editor" data-id="4ce60d3" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Proper email authentication does not require new software or complex infrastructure. It requires careful configuration, validation across all email sources, and a clear enforcement strategy.</p>

<p>The payoff is significant. Strong email authentication reduces risk, improves trust, and strengthens the overall security posture of an organization with relatively low ongoing maintenance.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-1ae695b elementor-widget-divider--view-line elementor-widget elementor-widget-divider" data-id="1ae695b" data-element_type="widget" data-e-type="widget" data-widget_type="divider.default">
				<div class="elementor-widget-container">
							<div class="elementor-divider">
			<span class="elementor-divider-separator">
						</span>
		</div>
						</div>
				</div>
					</div>
				</div>
		<div class="elementor-element elementor-element-086c72f e-flex e-con-boxed e-con e-parent" data-id="086c72f" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-d8ddcde elementor-widget elementor-widget-heading" data-id="d8ddcde" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h3 class="elementor-heading-title elementor-size-default">How Franklin Web Technologies Can Help</h3>				</div>
				</div>
				<div class="elementor-element elementor-element-7990a59 elementor-widget elementor-widget-text-editor" data-id="7990a59" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Email authentication is one of the first areas we assess when helping organizations improve their security posture. A short review often uncovers gaps that can be addressed quickly and with measurable impact.</p>

<p>Franklin Web Technologies helps businesses validate email sources, properly configure SPF, DKIM, and DMARC, and safely move domains to enforcement. Our approach focuses on reducing phishing risk, improving deliverability, and ensuring secure, trusted communication between organizations, employees, and customers.</p>

<p>If you are unsure whether your email authentication is fully enforced or want a second set of eyes, this is one of the highest value security improvements you can make.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-6f7a6d8 elementor-button-success elementor-widget elementor-widget-button" data-id="6f7a6d8" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="https://franklinwebtech.com/contact/">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Request an Email Security Review</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
				</div>
				</div>
		<p>Read more at <a href="https://franklinwebtech.com/proper-email-configuration-security-control/">Franklin Web Technologies</a></p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
