Read this first — email breaks loudly and in public
Conditional Access locks you out of your own tenant. Email security is worse in one specific way: when you get it wrong, your customers find out before you do, because your invoices stop arriving. The order below isn't advice, it's the whole method.
- SPF and DKIM before DMARC. DMARC checks alignment between them. Enforce it before they're right and you'll reject your own mail.
- p=none, then p=quarantine, then p=reject. Never skip a step, however confident you feel about your sender list. You are not confident, you just haven't seen the reports yet.
- Two weeks between steps, reading the reports. A change nobody's measuring is a change you can't evaluate.
- Lowest-volume domain first. Your main domain last.
- Presets over hand-built policies. Microsoft keeps preset security policies current as attacks change. Your custom policy is frozen on the day you made it, and it drifts below the baseline in silence.
Full guidance: Set up DMARC to validate the From address domain ↗
Size up your environment
A few questions. The dojo tailors the control set to what you actually run — and tells you honestly when something isn't for you. If you've been through another dojo, your licence is already filled in.
Do you have Defender for Office 365?
Asked, not guessed: Microsoft's docs disagree on whether E3 includes Plan 1 (announced, not shipped). Business Premium and E5/A5/G5 do. Check yours ↗. Not sure counts as no.
How does mail reach Microsoft?
Own domains you never send mail from?
Walk out with a plan
Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section.