Impact Assessment: How Guest Access Affects Threat Detection in Office 365

Currently working on a deep-dive into a critical Teams guest access behaviour I discovered during testing.
My research shows how attackers can spin up fresh M365 tenants and completely bypass Defender protections by pulling users into external guests.
I’m documenting the attack flow, detection queries, and practical steps organisations can take to reduce exposure — learning a lot along the way.

#CyberSecurity #LearningInPublic #ThreatResearch #RedTeam #BlueTeam #Microsoft365 #Defender #SecurityCommunity

The post Impact Assessment: How Guest Access Affects Threat Detection in Office 365 appeared first on Threatninja.net.

December 2, 2025
Read More >>