A municipal security program’s phishing-resistant roadmap starts by requiring stronger sign-in for all Microsoft 365 users. Which foundational control should come first in that identity story?
Select an answer to reveal the explanation.
Short Explanation
Before fancy architecture debates, make every Microsoft 365 sign-in harder than a stolen password. MFA everywhere is that foundation. Phishing-resistant journeys still start with killing password-only access.
Full Explanation
MFA is a primary Microsoft 365 identity protection method that reduces successful password-based attacks across the tenant. A fundamentals roadmap that aims toward stronger, more phishing-resistant posture typically begins by requiring MFA broadly. Disabling logging, publishing passwords, or preferring legacy auth paths increases risk rather than reducing it.