How to Reduce Phishing Emails in Microsoft 365
Question details
The organization needs to stop a large volume of phishing emails from bypassing filters and reaching user inboxes in Microsoft 365.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Administrators are receiving large volumes of phishing messages despite having mail flow rules, domain blocks, and URL restrictions in place.
- Observed behavior
- Phishing emails continue to bypass basic filters and reach user inboxes, requiring advanced security configurations to block them.
Ensure you have Global Administrator or Security Administrator permissions in your Microsoft 365 tenant to access the Microsoft Defender portal and modify threat policies.
Configure Advanced Anti-Phishing and Safe Links Policies
Review and strengthen your security policies in the Microsoft Defender portal to actively identify and block sophisticated phishing attempts.
Static lists (like blocking specific .jp or .np domains) are often ineffective against modern phishing campaigns that constantly rotate sender addresses. Relying on advanced AI-driven features like Defender for Office 365 anti-phishing policies is highly recommended.
Go to the Microsoft Defender portal (security.microsoft.com) and navigate to Email & Collaboration > Policies & Rules.
Select Threat policies, then click on Anti-phishing. Review and increase the advanced phishing thresholds and ensure impersonation protection is properly configured.
Return to Threat policies and select Safe Links to ensure URL protection is actively applied to all incoming messages.
Continue submitting malicious messages to Microsoft for analysis from the Submissions page and record the submission IDs to improve tenant-specific filters.

Implement User-Level Defenses and Training
Strengthen account security to mitigate the impact of phishing and train users to recognize suspicious emails.
Open a Microsoft Support Case for Tenant-Specific Investigation
If extensive filtering rules fail, escalate the issue to Microsoft for a deep-dive investigation into your tenant's mail flow.
Looking for a Secure and Lightweight Office Suite?
While Microsoft 365 handles your enterprise email security, you can equip your team with WPS Office for robust, lightweight, and highly compatible document editing. WPS Office provides a familiar interface without the heavy subscription costs.
- 1. Visit the Website: Go to the official WPS Office website.
- 2. Download the Installer: Download the free installer appropriate for your operating system.
- 3. Install and Run: Run the setup file and open your Office documents instantly upon completion.

Frequently Asked Questions
Why do phishing emails still get through despite having domain blocks in Microsoft 365?
Attackers frequently change their sending domains and IP addresses. Static blocks like domain or sender lists quickly become outdated. Relying on advanced AI-driven features like Defender for Office 365 anti-phishing policies is far more effective than manual blocking.
What is the Tenant Allow/Block List in Microsoft 365?
The Tenant Allow/Block List is a feature in the Microsoft Defender portal that allows security admins to manually override the system's filtering verdicts, explicitly blocking or allowing specific URLs, files, or spoofed senders.
How does Attack Simulation Training help reduce phishing?
It allows administrators to send safe, simulated phishing emails to employees. This helps identify vulnerable users and automatically assigns them targeted training modules to improve their awareness, significantly reducing the likelihood of real breaches.
How long does it take for Microsoft to analyze a submitted phishing email?
Typically, Microsoft analyzes user- or admin-submitted messages within a few minutes to a few hours. The verdict helps update the machine learning models for your tenant to block similar threats in the future.




