Enable two-factor authentication when identity provider is configured. Assign least-privilege roles to team members. Verify sender domains before opening unexpected attachments. Revoke active sessions if a device is lost. Review audit logs periodically.
Safeguard Team Email
A practical checklist for 2FA, active sessions, and phishing prevention.