How can we help you?

Defender for Office 365

Ensure that intelligence for impersonation protection is enabled
Move messages that are detected as impersonated users by mailbox intelligence
Enable impersonated domain protection
Set the phishing email level threshold at 2 or higher
Enable impersonated user protection
Ensure that mailbox intelligence is enabled
Quarantine messages that are detected from impersonated domains
Quarantine messages that are detected from impersonated users
Enable the domain impersonation safety tip
Enable the user impersonation safety tip
Enable the user impersonation unusual characters safety tip
Create zero-hour auto purge policies for phishing messages
Ensure that an anti-phishing policy has been created
Create Safe Links policies for email messages
Turn on Safe Attachments in block mode
Ensure Safe Attachments policy is enabled
Create zero-hour auto purge policies for malware
Ensure the Common Attachment Types Filter is enabled
Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams
Turn on Safe Documents for Office Clients
Ensure all forms of mail forwarding are blocked and/or disabled
Set action to take on high confidence spam detection
Set action to take on phishing detection
Set action to take on high confidence phishing detection
Set action to take on spam detection
Ensure Exchange Online Spam Policies are set to notify administrators
Set action to take on bulk spam detection
Ensure Safe Links for Office Applications is Enabled
Ensure that no sender domains are allowed for anti-spam policies
Retain spam in quarantine for 30 days
Set the email bulk complaint level (BCL) threshold to be 6 or lower
Set automatic email forwarding rules to be system controlled
Block users who reached the message limit
Create zero-hour auto purge policies for spam messages
Set maximum number of external recipients that a user can email per hour
Set maximum number of internal recipients that a user can send to within an hour
Set a daily message limit
Don't add allowed IP addresses in the connection filter policy
List of approved sender IP addresses.
Ensure the connection filter safe list is off
Ensure connection filter IP allow list is empty
Ensure comprehensive attachment filtering is applied

Can't find what you're looking for?