Jump to content

Recommended Posts

Posted

Hi all,

 

Have seen a marked increase in phishing emails getting through to users receiving phishing-type emails and / or dodgy links recently via Office365 online.

 

Other than anti-phishing / malware threat protection being turned on (which it is by default) what are you doing to combat it? Do you have third-party email scanning?

Posted

Other than anti-phishing / malware threat protection being turned on (which it is by default)

 

 

It is, to a point. The "free" one we all get is very basic, you need ATP (M365 defender now??) to do the fancy safe link stuff. I've got a trial at the moment & it automatically pulled a phishing email out of a users mailbox the other day without me having to do anything, so it might be worth a look.

Posted
The 365 A5 Security licence is what you need for all staff. Very effective at scanning all attachments and URLs within messages. Enrol all machines into it and you can start using the Security Admin portal a lot more effectively. It does indeed warn of malicious content and pulls it before you've even taken a look.
Posted (edited)
There's the Office 365 Advanced Threat Protection, but the cost of that very quickly got out of hand once you were covering all mailboxes. We've just started with Barracuda Total Email Protection which has all the same stuff (link protection, file scanning & sandbox execution, AI phishing analysis, incident response...) but was less than half the price over three years. (Sophos was a bit cheaper, but the functionality wasn't as advanced--basically felt like a fancy UI on top of the standard 365 tools). It's still not cheap, per se--working out about £4k/year here, based on ~130 FTE staff same as Microsoft's EES licensing--but it's gotten to a point where I no longer felt comfortable being reactive in the email security arms race, and wanted every layer of protection I could get so I can sleep at night. Edited by sonofsanta
Posted
The 365 A5 Security licence is what you need for all staff. Very effective at scanning all attachments and URLs within messages. Enrol all machines into it and you can start using the Security Admin portal a lot more effectively. It does indeed warn of malicious content and pulls it before you've even taken a look.

 

Why just for staff not all domain users?

 

Just curious.

Posted

Sorry, typed that in a rush. Staff and Students get an A3 Office 365 licence with an A5 Security licence.

 

Governors and visiting teachers get an A1 licence.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...