phishing protections in exchange online

crib bar 851 Reputation points
2023-12-19T14:15:49.2766667+00:00

Where specifically within the admin center(s) linked to the Exchange Online product can you review whether all suggested phishing protections have been enabled for your users/mailboxes? And do Microsoft have a list of suggesting phishing protections that tenants should enable to check the settings align with best practice and that there are no gaps? If Microsoft do not offer such guidance, are there any suggested phishing protections that can be enabled within the system that we can check?

Exchange Online
Exchange Online
A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.
Exchange | Exchange Server | Other
Exchange | Exchange Server | Other
A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

2 answers

Sort by: Most helpful
  1. Philippe Levesque 5,841 Reputation points Volunteer Moderator
    2023-12-19T16:01:47.8566667+00:00

    Hi

    Exchange Online Protection is the addon that enable more phishing protection. The below chart summarize what plan got it.

    User's image

    To configure or view the policy, please see that document, it's inside the Defender's portal.

    Configure anti-phishing policies in EOP

    Anti-phishing policies in Microsoft 365

    0 comments No comments

  2. Yuki Sun-MSFT 41,451 Reputation points Moderator
    2023-12-20T06:03:40.66+00:00

    Hi @crib bar

    Where specifically within the admin center(s) linked to the Exchange Online product can you review whether all suggested phishing protections have been enabled for your users/mailboxes?

    As far as I know, there's no such a place in the admin centers where you can check whether all the suggested phishing protections have been enabled in your tenant.

    And do Microsoft have a list of suggesting phishing protections that tenants should enable to check the settings align with best practice and that there are no gaps?

    You could review the official document below which lists all the anti-phishing protection features in Exchange Online Protection (EOP) and Microsoft Defender for Office 365, and check them in your own tenant.
    Anti-phishing protection in Microsoft 365

    User's image

    User's image


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in [our documentation] to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.