How to Protect Microsoft 365 Emails from Viruses and Phishing
Question details
The user wants to learn how to secure Microsoft 365 email accounts against malware, phishing attempts, spam, and malicious links.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Securing business or personal email communications against cyber threats.
- Observed behavior
- Users need to establish a secure email environment to prevent unauthorized access, data breaches, and malware infections originating from emails.
Ensure you have global administrator or security administrator permissions in your Microsoft 365 tenant to access and configure advanced security policies in the Defender portal.
Configure Microsoft Defender for Office 365 and Exchange Online Protection
Utilize Microsoft's built-in Exchange Online Protection (EOP) and Defender to automatically filter and block malicious emails, links, and attachments.
Exchange Online Protection (EOP) serves as the first line of defense against spam and malware. Microsoft Defender for Office 365 expands on this by providing advanced protection against zero-day threats, malicious links, and sophisticated phishing campaigns.
Log in to the Microsoft 365 Defender portal at security.microsoft.com using your administrator credentials.
In the left navigation pane, go to 'Email & collaboration' and select 'Policies & rules', then click on 'Threat policies'.
Select 'Anti-phishing' and either edit the default policy or create a new one to define how impersonation attempts and spoofed emails are handled within your organization.
Under 'Threat policies', configure 'Safe Attachments' to scan incoming files for malware in a virtual environment, and set up 'Safe Links' to verify URLs in real-time when users click them.

Enforce Multifactor Authentication (MFA) and User Security Training
Strengthen account security by requiring MFA and educating users on how to spot suspicious emails to prevent credential theft.
Enhance Document Security with WPS Office
While securing your Microsoft 365 emails against phishing is crucial, protecting the documents you share and download is equally important. WPS Office is a lightweight, highly compatible, and free alternative to Microsoft Office that offers powerful built-in document encryption to keep your offline data secure.
- 1. Download and Install WPS Office: Get the official WPS Office suite from the website and securely install it on your device.
- 2. Open Your Document: Launch WPS Office and open the Word, Excel, or PDF document you wish to secure before emailing.
- 3. Apply Password Encryption: Navigate to the 'Menu', select 'Document Encryption', and set a strong password to protect your file's contents before sharing it externally.

Frequently Asked Questions
What is Exchange Online Protection (EOP)?
Exchange Online Protection (EOP) is the cloud-based filtering service built into Microsoft 365 that helps protect your organization against spam, malware, and other common email threats by analyzing both incoming and outgoing messages.
How does multifactor authentication (MFA) prevent email phishing?
MFA requires users to provide two or more verification methods to sign in, such as a password and a code sent to their mobile device. Even if a phishing attack successfully steals a user's password, the attacker cannot access the account without the secondary authentication factor.
Can I encrypt sensitive information inside Microsoft 365 emails?
Yes, Microsoft 365 allows you to send encrypted email messages. You can configure Office 365 Message Encryption (OME) to ensure that only intended recipients can read the message content, protecting sensitive data if intercepted.
How do Safe Links and Safe Attachments work in Defender for Office 365?
Safe Attachments opens incoming files in a secure virtual environment to test for malicious behavior before delivering them to the inbox. Safe Links scans URLs inside emails and documents at the time of click to ensure the destination is not harmful or tied to a known phishing campaign.




