Forum Discussion

Livi_1's avatar
Livi_1
Copper Contributor
Mar 17, 2021

Improving security for shared mailboxes or generic user accounts

Hi,   Our organisation uses generic accounts for each location for example, location@company.com   Recently we have seen an increase in attempts to login to these generic accounts and I'm trying ...
  • VasilMichev's avatar
    Mar 17, 2021
    Do you need to send messages directly as these addresses? If not, simply recreate them as DLs or Office 365 Groups (you can still use Send As permissions to send messages if needed).

    You can safely block the account and it will continue receiving messages. You can also disable POP/IMAP/SMTP protocols, which are usually the target for brute-force attempts. And having a tenant-wide policy that block basic auth isn't a bad thing either 🙂

Resources