The Email Phishing Protection Guide is a multi-part blog series written to walk you through the setup of many security focused features you may already own in Microsoft Windows, Microsoft Office 365, and Microsoft Azure. By implementing some or all of these items, an organization will increase their security posture against phishing email attacks designed to steal user identities. This guide is written for system administrators with skills ranging from beginner to expert.
Introduction: Email Phishing Protection Guide - Enhancing Your Organization's Security Posture
Part 1: Customize the Office 365 Logon Portal
Part 2: Training Users with the Office 365 Attack Simulator
Part 3: Deploy Multi Factor Authentication (MFA)
Part 5: Define Country and Region Logon Restrictions for Office 365 and Azure Services
Part 6: Deploy Outlook Plug-in to Report Suspicious Emails
Part 7: Deploy ATP Anti-Phishing Policies
Part 8: Deploy ATP Safe Link Policies
Part 9: Deploy ATP Safe Attachment Policies
Part 11: Monitor Phishing and SPAM Attacks in Office 365
Part 12: Discover Who is Attacking Your Office 365 User Identities
Part 13: Update Your User Identity Password Strategy
Part 14: Prevent Brute Force and Spray Attacks in Office 365
Part 15: Implement the Microsoft Azure AD Password Protection Service (for On-Premises too!)
Part 16: Disable Office 365 Legacy Email Authentication Protocols
Part 17: Control Application Consent Registrations in Microsoft Office 365 and Microsoft Azure
Part 18: Increase Security with Microsoft Secure Score
Part 19: Email Phishing Protection Security Checklist
Part 20: Recommended Security and Anti-Phishing Training from Microsoft Ignite 2018
Part 20: Recommended Security and Anti-Phishing Training at Microsoft Ignite 2018
While I have written many blogs in this Email Phishing Protection Guide about topics to help secure your environment, you may want to learn more. I encourage anyone looking for more information to search documentation available on AND to watch recorded conference sessions on just about any topic or product from Microsoft.
I find that information presented at the many conferences Microsoft hosts or attends is some of the best information available. Instead of just learning about product features and implementation steps in the documentation, there is often a large amount of valuable information also presented at these conferences. I reviewed the catalog of more than 1200 sessions presented at Microsoft Ignite 2018 in Orlando, FL with a focus to learn more about the latest anti-phishing and security products and recommendations Microsoft offers. Below is that list, separated into two sections - Phishing Protection and Security.
I have listed the session code, title, link to the session in the Microsoft Ignite website, and finally the link to watch the session directly on YouTube. Yes, I have watched each one and highly recommend them. These are only the sessions I found in my review but remember that there are over 1200 sessions available to watch. All the Microsoft Ignite sessions are in this YouTube channel.
Microsoft Ignite 2018 Sessions:
Phishing Protection
- BRK4000 - Leveraging the power of Microsoft Threat Protection to secure the modern workplace across data, endpoints, identities, and infrastructure
YouTube 75 minutes - BRK4002 Securing your Office 365 environment from Advanced Phishing Campaigns with Office 365 Advanced Threat Protection
YouTube 45 minutes - BRK3031 Getting to a World Without Passwords
YouTube 45 minutes - BRK3251 Shut the door to cybercrime with identity driven security
YouTube 75 minutes - BRK3408 Azure AD Best Practices from Around the World
YouTube 45 minutes - THR3047 Ensure all your users have strong passwords with Azure Active Directory Password Protection
YouTube 20 minutes - THR3048 Credential Protection in the Password-less Era
YouTube 20 minutes - THR2148 Experiences with going password-less
YouTube 20 minutes - THR2018 Single Sign-on best practices for Azure Active Directory and Microsoft accounts
YouTube 20 minutes - BRK3226 - Secure access to Office 365/Azure Active Directory with new features in AD FS in Windows Server 2019 and Azure AD Password Protection
YouTube 45 minutes - THR2355 A World Without Passwords
YouTube 20 minutes - BRK3037 Windows Devices and Azure Active Directory: What's new and what's upcoming
YouTube 75 minutes - BRK2253 What's new for Windows Hello for Business
YouTube 45 minutes - BRK2447 Cutting edge cyber security
YouTube 75 minutes - BRK4010 Anatomy of an attack in Microsoft 365
YouTube 45 minutes - THR4006 Raising Awareness and Education of Modern Threats to Office 365
YouTube 20 minutes - BRK3148 Securing Exchange Online from Modern Threats
YouTube 75 minutes - BRK4002 Securing your Office 365 environment rom advanced phishing campaigns with Office 365 ATP
YouTube 45 minutes - BRK3272 Authentication and passwords: The good, the bad, and the really ugly!
YouTube 45 minutes - THR2002 - Keeping your sensitive data secure in Office 365 with Data Loss Prevention (DLP)
YouTube 23 minutes - THR2363 Don't get phished
YouTube 16 minutes - THR4006 Raising awareness and education of modern threats to help reduce your organizations risk profile
YouTube 20 minutes
- BRK4000 - Leveraging the power of Microsoft Threat Protection to secure the modern workplace across data, endpoints, identities, and infrastructure
- THR1097 Security is important to Small Businesses, too
YouTube 20 minutes - BRK2482 End-end security for SMBs with Microsoft 365 Business
YouTube 75 minutes - BRK3368 Successfully deploy Microsoft 365 Business in your SMB
YouTube 45 minutes - BRK2158 Elevate the security for all your cloud apps and services with the Microsoft CASB - Cloud App Security
YouTube 75 minutes - BRK3221 Combat advanced cyber attacks with Microsoft Cloud App Security
YouTube 45 minutes - THR2130 Deploy and manage Cloud App Security in Office 365
YouTube 20 minutes - THR3040 Dramatically improve your security posture through attack surface area reduction
YouTube 20 minutes - THR2069 Raise your game as a security administrator with Windows Defender ATP
YouTube 20 minutes - GS008 - Microsoft Security: How the cloud helps us all be more secure
YouTube 20 minutes - THR2066 How Microsoft can save you X% on your EPP and EDR spend with Windows Defender ATP
YouTube 20 minutes - BRK4000 Leveraging the power of Microsoft threat protection to secure the modern workplace across data, endpoints, identities, and infrastructure
YouTube 75 minutes - BRK2020 Living in an Assume Breach world: What it means to run a secure Microsoft 365 cloud service and how you can apply these lessons to improve your security posture
YouTube 70 minutes - BRK3411 Secure enterprise productivity with Office 365 threat protection services including EOP, ATP, and Threat Intelligence
YouTube 75 minutes - THR3043 Secure administration across Microsoft Office and Azure Clouds
YouTube 20 minutes - THR2346 How to mitigate the new cybersecurity threat
YouTube 20 minutes - BRK3409 The future of threat protection: Become efficient, cost effective, and more secure with Office 365 Threat Intelligence
YouTube 45 minutes - THR1070 Go from zero to hero using Azure Site Recovery: Surviving a ransomware attack
YouTube 20 minutes - BRK4023 The rising risk of social engineering
YouTube 20 minutes - THR2037 Comprehensive threat protection for Office 365
YouTube 20 minutes - THR1096 Beware ransomware! How to mitigate risk with Windows 10 and Microsoft 365 security features
YouTube 20 minutes - THR3088 How to onboard your clients to Windows Defender ATP
YouTube 20 minutes
- THR1097 Security is important to Small Businesses, too