Admin Defenses

Policy Is Your Best Defense

Staff awareness reduces risk, but it does not eliminate it. A single mistake by anyone — a new volunteer, a pastor in a hurry — can hand over an account. The settings in this section let you block these attacks at the platform level, so that a click does not automatically become a compromise.

M
Microsoft 365 / Entra ID

G
Google Workspace

People and Process (Still Required)

Platform settings reduce risk significantly but do not replace staff awareness. A few simple process rules cover what technology cannot:

Verify with a known contact

If someone calls, texts, or emails asking for a device code or app approval: hang up (or close the message) and call the person back on a number already in your contacts. Do not use the number in the suspicious message.

One-sentence staff policy

Post this in your volunteer onboarding and office:"Never enter a device code or click Allow on an app unless you started the process yourself and can see the device in front of you."

New integrations require admin approval

Any new app connection — a giving platform, a planning tool, a scheduling service — should go through your tech lead or admin, not be self-authorized by individual staff.

Quick-Start Admin Checklist
  • Block device code flow via Conditional Access (Microsoft) or confirm it is off
  • Set user consent to verified publishers only or admin-approval required (Microsoft)
  • Enable the admin consent request workflow so staff can request apps properly
  • Audit Enterprise Applications / Connected Apps — remove unknowns
  • Review sign-in logs for device code authentication events
  • Block or restrict unconfigured third-party apps (Google Workspace)
  • Enforce 2-step verification / phishing-resistant MFA on all admin accounts
  • Separate daily-use accounts from admin accounts for key staff
  • Post a one-sentence consent / device-code policy for volunteers