bwvanmanen Enhanced Phishing Protection protects you when you type the Microsoft password used to sign into your device into phish content on any app or Chromium site, reuse it on any app or Chromium site, or type it into certain text editor apps, like Notepad or an M365 application. Enhanced Phishing Protection does not scan your documents for stored passwords. It only warns when you are actively typing the password you typed to sign into your device into a text editor application, and only warns you if your organization enables user notifications for the unsafe password storage scenario. This is because typing your plaintext password into Notepad or Word is an unsafe practice that allows attackers easier access to sensitive data if your device is compromised. The warning recommends for you to remove your password from the file, so you can still work with confidential information. Your password information is always secure and encrypted at all times.
You can check if Enhanced Phishing Protection is enabled on your workstation in the App & browser control panel of the Windows Security app. The fastest way to get to it is to follow these steps:
-
Tap the start button and type phishing protection into the search box that appears
-
Select Phishing protection from the search results.
Once the app is open, scroll down to Phishing protection. If your organization has enabled this setting, it will say that your administrator controls this setting and the options will be greyed out.