Secure your business
A critical part of running your business these days is doing so securely. Fortunately, Microsoft 365 gives you a lot of tools to help you do that and it's easy to turn them on.
Click the headings below for more information
If criminals get the username and password of you or one of your team, they'll try to sign into your system to see what they can take. Using multifactor authentication makes it much harder for them to get in, even if they do have your username and password.
Tip: Want to know more about multifactor authentication? See What is: Multifactor Authentication.
To confirm multifactor authentication is on:
-
Go to the Microsoft 365 admin center at https://admin.microsoft.com.
-
Select Show all to display the additional admin centers, then select Azure Active Directory.
-
Select Azure Active Directory from the navigation on the left, then Properties.
-
Select Manage security defaults from the bottom of the page.
-
On the panel that opens to the right, turn the security defaults on, then select Save.
The next time you sign into Microsoft 365 you'll be prompted to set up the Microsoft Authenticator app as a second factor. It should take just a couple of minutes to download and set up the app on your Android or iPhone. Once it's set up, you're all set. For more details on how to do it see Set up Security info from a sign-in page.
For regular users it should rarely ask for the second factor when they sign into the device they always sign into. For admin users it may ask a little more often due to the sensitive nature of an admin account.
Phishing messages are often cleverly disguised to look like a message from a person or organization you trust. If you do a lot of business with alexw@contoso.com you're inclined to trust Alex and you might not notice if a message came in from alexw@contos0.com during a busy day.
Microsoft 365 can add a safety tip to that message alerting you that this is a new sender, and that might give you a chance to pause and recognize that this message is from an imposter.
To turn on the first contact safety tip.
-
In your browser sign into https://security.microsoft.com/antiphishing.
-
Select the default anti-phishing policy from the list.
-
Select Edit actions.
-
Select the check box for Show first contact safety tip.
-
Select Save.
Microsoft 365 has a set of security features that can help protect your business and to make it easier for you to turn them on we've packaged them as a set that you can turn on together.
-
Go to the Microsoft 365 Defender portal (https://security.microsoft.com) and sign in.
-
Under Email & Collaboration go to Policies & Rules > Threat policies > Preset Security Policies in the Templated policies section.
-
On the Preset security policies page, in the Standard card, select Manage protection settings.
-
The Apply standard protection wizard starts in a flyout. On the Exchange Online Protection page select All recipients. You want these protections to apply to everyone in your business. Then select Next.
-
Repeat step 4 on the Defender for Office 365 page and select Next.
-
Next, we'll set up impersonation protection. This makes it harder for criminals to send you malware while pretending to be somebody you trust.
Tip: Your own addresses or domains hosted in Microsoft 365 are automatically protected so you don't need to add them here.
On the first screen you can enter the email addresses of people you communicate with regularly. Don't worry about adding all of your contacts here. You can even skip this step if you don't want to add individual contacts right now.
The second screen is more important. This lets you specify entire domains for Microsoft 365 to watch for. Here you should enter the domain names of people or organizations you message with regularly.
Important: Type the domain name then select the suggested domain that appears, before clicking Add.
The final screen of this step asks you to enter any trusted senders that you want to make sure don't get quarantined. It's often best to skip this step unless you know that a particular sender is being falsely quarantined. You can always come back and add senders or domains to this list later.
Select Next. -
Leave the setting to Turn on the policy after I finish so that the settings will take effect right away and select Next.
-
Review your settings and select Confirm to finish.