microsoft 365 defender
89 TopicsEmails being accepted by large organisation
Hi I have to interact regularly with alarge UK public sector organisation. Unfortunatley, a number of my emails (and those of my colleagues that have the same domain name) end up in spam folders or spam quarantines and it is very frustrating. I have requested that our email addresses are "whitelisted" but this has been refused on the grounds of security even though there is no history of the domain being used insecurely. I am told it is because of the "hopping" of my emails . My emails have the spf on them. I have also never received a blocked senders notice from Microsoft. Is there anything that can be done?Automating User Tags
When we create a custom user tag we can select a group and have all the users in the group tagged. However if a user is removed or added to that group at a later stage the tag is not removed/added. Is there a way to automate this? Only thing I found is that this was before on the roadmap but seems to have been removed? https://m365admin.handsontek.net/microsoft-defender-for-office-365-tagging-support-for-groups/ https://learn.microsoft.com/en-us/defender-office-365/user-tags-about If you assign a group to a user tag, members of the group at the time of tag creation are assigned tag. Users later added to the group aren't automatically assigned the user tag.MS 365 Defender - What permissions are needed to move and delete emails in Explorer?
I need a tech with limited permissions to be able to Remediate malicious email delivered in Office 365 These are the options I have in Admin. I tried a bunch of recommended actions, yet I don't seem to have the correct Admin portals as shown here. For example, I don't have MS 365 Defender Permissions Group shown in the video:440Views0likes4CommentsWhat steps can I take, given Microsoft Defender's report?
In September I posted a question in this forum,I'm not sure what to do with the data breaches Microsoft Defender reports. I've proceeded to use the "Take Action" button. After clicking on that button Microsoft Defender took me to its report on what it found. It listed a website I've never heard of before. I use a password manager, so I double checked there. I don't have an account on that website. The information it has there is about half correct, a quarter of the information is wrong, and the rest is out of date by 10+ years. There were a few other websites that it reported on. Some I can manage, as Microsoft Defender gave me enough information about them. Others are not helpful, as Defender just says, "From an unknown source", then the rest of the information isn't helpful at all. Anyway, my concern is that this information is out there especially with the first reported incident, and I don't see how I can stop this spurious website from displaying it. And I certainly have no idea how it got it in the first place. So, what can I do about some website that got this information from somewhere and displays it for whoever to see it?231Views0likes0CommentsMicrosoft Defender for Office 365 Implementation
Hello. I would like to discuss and get few information as mentioned below, 1) Which plan of Defender for Office 365 is included in Microsoft 365 Business Basics? 2) Can I buy only Microsoft Defender for Office 365 licenses? Which plan will be included in that license? 3) If only Defender for Office 365 license is bought then will this license only provide protection to the user that has the license assigned or the whole organization? 4) Are there any steps that I can follow to configure/ implement Microsoft Defender for Office 365? 5) What are the features of Microsoft Defender for Office 365 (plan 1 and Plan 2)? Thank you for your attention.I'm not sure what to do with the data breaches Microsoft Defender reports
First of all, I realize that this forum may not be the right place for me to post any question about Microsoft Defender. If this is the wrong place, I apologize and please direct me to the correct place. I have a Microsoft 365 for Family license, so I thought this forum might be the correct place for me to post a question about Microsoft Defender. When I logged into my Windows profile on my Windows 11 desktop, I was presented with a popup from Microsoft Defender. It asked me to fill out some additional information, which I did. At the end of that process, it told me that I was listed in some data breaches, that it found on "the dark web". But many of them (there aren't a lot of them) have unhelpful information. For example, one reads: "Compromised info found on Aug 19, 2022 From an unknown source" Then it lists my email address and a glyph for an email password. But the bottom line is I don't know what to do with this. There's a button that's labeled, "Take action", but I'm not comfortable clicking on a button when it appears to me like Microsoft Defender hasn't a clue as to what to do about it. So, what should I do with this ambivalent information?SolvedClarification on Microsoft Teams Encryption: E2EE vs. Default Encryption
I’m seeking some clarity on the differences between the end-to-end encryption (E2EE) offered with the Teams Premium license and the default encryption for data at rest and in transit within Microsoft Teams. From what I understand, Teams data is already encrypted both in transit and at rest by default. However, I’m unsure how the E2EE provided under the Teams Premium license differs from this standard encryption. Could someone explain in simple terms the specific differences between these two encryption methods? I’m particularly interested in understanding how I can effectively communicate these differences to my clients, who may not be very technical but need to grasp the security advantages of the Premium license.SolvedAIR Result : Email template modification
Hi, I want to change the email language for the Automated investigation and response (AIR) after a phishing report. I found the page where you can set a custom email "Body" and "Footer". This works, but I also need to change the other parts of the email or at least find a way to translate it in french. Right now, there's a mix of english and french (The body and footer I configured) but I need the whole thing to be in french. I would appreciate a hand on this issue. Thank you !! PS : See the screenshot for the part I want to translate.looking for a test protocol defender for o365
Hi together, I am looking for a test protocol defender for o365 to generate alerts and emails. The idea is generate alerts add/or mails from Defender for EOP/O365. We have only the license Defender for O365 Plan 1 in use. We know this options: https://learn.microsoft.com/en-us/defender-office-365/anti-spam-policies-configure#send-a-gtube-message-to-test-your-spam-policy-settings https://learn.microsoft.com/en-us/defender-office-365/anti-malware-policies-configure#use-the-eicartxt-file-to-verify-your-anti-malware-policy-settings https://learn.microsoft.com/en-us/defender-office-365/safe-links-policies-configure#how-do-you-know-these-procedures-worked https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure#how-do-you-know-these-procedures-worked https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-simulations But this options does not work very good for us or depends an Defender for O365 Plan 2 license. Does anyone have an good idea or know a option or a way i did not finde till yet? Thanks for an feedback and regardsinternal user email quarantined and reason "high confidence phish"
Have you ever seen email quarantined when both sender and recipient are internal organization user and the quarantine reason is high confidence phish by the default built-in anti spam policy? really confused why it happened and how to avoid such false positive..615Views0likes3Comments