To reduce phishing reaching Teams users and company mailboxes, combine user actions with Microsoft 365 anti-phishing protections.
- Strengthen Microsoft 365 anti-phishing protection
- Use Microsoft Defender for Office 365 for additional anti-phishing features.
- Configure anti-phishing policies to enable protections such as:
- Impersonation protection for specific senders and domains
- Mailbox intelligence
- Adjustable phishing email thresholds
- If phishing is still getting through, the Phishing email threshold can be temporarily increased from Standard to Aggressive, More aggressive, or Most aggressive.
- Verify core protections are enabled
- Confirm Safe Links and Safe Attachments are active.
- These protections are turned on by default through Built-in protection in preset security policies.
- Anti-phishing has a default policy for all recipients with anti-spoofing protection turned on by default.
- Impersonation protection is not turned on in the default anti-phishing policy, so it needs to be configured explicitly.
- Improve Teams-specific protection
- Teams phishing can target users through links and attachments.
- Use Teams security best practices for safer messaging.
- Microsoft Defender for Office 365 also secures Teams.
- Suspicious message reporting is available for Teams users.
- If an external sender delivered a phishing message in Teams, tenant admins can remove it from the user’s view by using the Graph API RemoveAllAccessForUser.
- Enable user reporting and response
- In Outlook, use the built-in Report button so suspicious messages can be reported.
- Admins can configure whether reported messages are sent to Microsoft, to a designated reporting mailbox, or both.
- Admins can review user-reported messages on the User reported tab of the Submissions page in the Microsoft Defender portal.
- Reporting phishing messages helps tune Microsoft 365 filtering.
- Train users to recognize phishing
Teach users to avoid common phishing indicators:
- Mismatched sender domains
- Outlook banners such as we could not verify the sender
- Suspicious links or unexpected attachments
- Fake sign-in pages with typos, outdated logos, or requests for unusual information
- Pages that are only images made to look like a real sign-in page
- User actions for suspicious messages
- Never click links or open attachments in suspicious email or Teams messages.
- Verify the organization through known channels instead of using contact details in the message.
- If the message appears to come from a known person, confirm through another method such as phone or text.
- Report the message and delete it.
A practical baseline for a company domain is:
- Microsoft Defender for Office 365
- Safe Links
- Safe Attachments
- Anti-phishing policies with impersonation protection configured
- User reporting enabled in Outlook and Teams
- User phishing awareness training