As we continue to build out depth of controls to harden Microsoft 365 environments, we have added the following protections against Shadow Workflows:
Microsoft Exchange Online:
  • Ensure Direct Send is disabled
Microsoft Defender for Office 365:
  • Tenant Allow/Block list should contain zero entries in the allow list
These recommended controls may now be scheduled for deployment. Due to potential impact on end users, they won't be rolled out automatically as part of Managed Deployments.