Skip to main content
SolarWinds MSP
  • Login
  • Support
  • Partnerships
    • Partnerships Overview
    • Solution Provider Program
    • Technology Alliance Program
    • Distributor Program
SolarWinds MSP
  • Products
    • SolarWinds N-central Automate what you need. Tackle complex networks. Try this remote monitoring and management solution built to help maximize efficiency and scale.
    • SolarWinds RMM Start fast. Grow at your own pace. Try this powerful but simple remote monitoring and management solution.
    • SolarWinds EDR Defend against ransomware, zero-day attacks, and evolving online threats with Endpoint Detection and Response
    • SolarWinds Backup Manage data protection for servers, workstations applications, documents and Microsoft 365 from one SaaS dashboard.
    • Mail Protection & Archiving Protect users from email threats and downtime.
    • Password Management Easily adopt and demonstrate best practice password and documentation management workflows.
      • Passportal Demo
    • PSA & Ticketing Manage ticketing, reporting, and billing to increase helpdesk efficiency.
    • Remote Support Help support customers and their devices with remote support tools designed to be fast and powerful.
  • Solutions

    I'm looking for...

    • Security Solutions
    • Monitoring Solutions
    • Efficiency Solutions
  • Resources
    • Blog
    • Webcasts & Events
    • Ask the N-central Experts
    • Daily Live Demos
    • RMM Foundations Training
    • Upcoming Events
    • Upcoming Webcasts
    • Resource Center
    • COVID-19 Resources
    • Resource Library
      • Case Studies
      • Product Information
      • eBooks
      • White Papers
      • Infographics
    • SolarWinds MSP Free Tools
    • GDPR Resource Center
    • Security Resource Center
    • MSP Institute Webinar Series
    • MSP Advice Project
  • About
    • Contact
    • Customer Success
    • Worldwide sales and support
    • Careers
    • Awards and Recognition
    • Get A Quote
    • Newsroom
      • Press Releases
      • In The News
      • Media Contacts
      • COVID-19 Response
    • Leadership Team
    • Legal
      • Cookie Policy
      • Privacy Notice
      • Software Services Agreement
      • Terms of Use
      • Backup Fair Use Policy
    • Security
      • SolarWinds Security Statement
      • Vendor Data Protection Requirements
    • Support
  • IT Departments
  • Contact Sales
    • Get A Quote
    • General Inquiry
  • TRY NOW
    • SolarWinds RMM
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Passportal
    • SolarWinds N-central
    • SolarWinds Mail Assure
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
  • Request a Quote
  • Try Now
    • SolarWinds RMM
    • SolarWinds N-central
    • SolarWinds Backup
    • MSP Manager
    • SolarWinds Mail Assure
    • SolarWinds Passportal
    • SolarWinds Risk Intelligence
    • SolarWinds Take Control
Request quote
Filter Blogs
  • Filter by:
  • MSP Business
    • Automation
    • Backup & Disaster Recovery
    • Security-series
    • Best Practices
    • Business
    • Business Growth
    • Business Risk
    • Cloud Computing
    • Customer Service
    • Cybersecurity
    • Cybersecurity Awareness Month
    • Data
    • GDPR
    • Internet of Things
    • IT Support
    • ITSM
    • LOGICcards
    • Machine Learning
    • Mail
    • Managed Services
    • Marketing
    • Mobile
    • Networking
    • Operations
    • Podcast
    • Product
    • PSA
    • Remote Management
    • Research & Trends
    • Risk Intelligence
    • Security
    • Security Vlog
    • Service Desk
    • Services & Support
    • The Head Nerds
    • Tips & Advice
    • Training
Home Blog MSP Business Security The Top 5 Microsoft 365 Email Security Best Practices
Security

The Top 5 Microsoft 365 Email Security Best Practices

By SolarWinds MSP
8 March, 2019

How good is your Microsoft 365 email security? Every company that uses this popular suite of cloud-based productivity applications should be asking themselves this question. Cloud-based services are also vulnerable to malware insertion, and email is the most common entry point for malware. It should, therefore, be a priority for MSPs that their clients know and enforce some Microsoft 365 email security best practices.

Is Microsoft 365 secure? 

That isn’t to say that Microsoft’s service is somehow inherently insecure—on the contrary, the company takes uniquely stringent security precautions. For example, it won’t publicly disclose the location of its physical servers, making it known only that the area is under tight surveillance at all times. It also offers encryption for data both at rest and in motion, going above and beyond what other cloud platforms provide to ensure your network transmissions aren’t intercepted. 

Does Microsoft 365 include antivirus, anti-spam (AVAS) protection? 

Exchange Online Protection is the built-in antivirus for Microsoft 365 security, guarding inboxes against spam, viruses, and known malware. This provides a basic layer for email safeguarding. But even with Microsoft covering the back end, there’s still plenty that hackers can do to seize user data and introduce harmful malware onto the network if users aren’t actively working to secure their platform. If you’re looking to take your business clients beyond the basics of stronger passwords and two-factor authentication, we’ve compiled a list of best practices for Microsoft 365 email security that should help leave you well prepared for the growing threats that enterprises face today from malware and data exposure.

1. Use Microsoft 365 Secure Score

If you haven’t checked out Microsoft 365’s suite of out-of-the-box security tools or read our blog on the subject, you may not have ever used Microsoft 365 Secure Score. The tool uses advanced analytics to recommend actions you can take to keep digital assets safer. It’s a great example of gamification, taking the complex work of cybersecurity and turning it into an intuitive and engaging app that allows the user to slowly but surely improve their security stance. 

The system gives you a “score” out of 452, though the goal isn’t necessarily to get as many points as possible. Secure Score recommends reaching a “balanced” score between 254 and 372 that indicates you do enough to secure your email data, but not so much that it unnecessarily impacts productivity. Secure Score takes into account security needs, settings and recent activity, and current Microsoft services in order to recommend the practices best suited for the enterprise.

Bullet-Proofing Office 365

DOWNLOAD our free white paper to discover how you can make things more difficult even for the determined attackers.

Protecting Office 365 with SolarWinds Mail Assure

2. Block attachments used for malware

Again, Microsoft 365 and Microsoft Exchange offer some robust anti-malware capabilities out of the box, including multiple anti-malware scan engines, real-time threat response, and rapid integration of new patches and malware definitions to respond quickly to new threats. But you can go even further by blocking email attachments of files that are commonly used for malware. 

Just sign into the Microsoft 365 Security and Compliance center, look under Threat Management and select Policy, then Anti-Malware. Double-click the default policy, then click Settings. Turn on Common Attachment Types—in the future, you can add or remove attachment types as needed. This step will add another layer of protection for your network in the event that authorized employees are careless about opening suspicious messages.

3. Create anti-ransomware mail flow rules

For improved Microsoft 365 email security, prevent hackers from locking you out of your own data systems and even your devices. You’ll need to create mail flow rules that block attachments commonly used for ransomware. Just open the admin center for Exchange, click on Rules under Mail Flow, then click Create a New Rule. You’ll be presented with a wide range of options that allow you to either block emails that could contain ransomware and other malicious code, or to preemptively warn users who receive such emails.

A ransomware attack can be one of the most financially damaging forms of online threat. It’s better to be particularly cautious in this arena and favor stringent rules, rather than leave the door open to emails with malicious code. 

CTA Image

Try SolarWinds Mail Assure

Advanced Threat Protection for Inbound and Outbound Email.

Try It Free

4. Implement additional security software

Businesses serious about safeguarding will want to choose a robust, email-specific tool like SolarWinds Mail Assure. This cloud-based solution focuses solely on email security, at an affordable per mailbox rate for any businesses of any size. With no additional hardware or maintenance needed, this tool integrates with Microsoft 365 to protect against spam, viruses, malware, and phishing, using a global threats database to identify even the latest scams. 

5. Use Office Message Encryption

Microsoft 365 has Office Message Encryption on as a default. The service encrypts both incoming and outgoing email messages and is fully compatible with the web-based version of Outlook, Gmail, Yahoo!, and other common email platforms. Email message encryption is critical for protection against email-borne malware because it represents the first layer of security, blocking outsiders from viewing message content.

With little exception, the rule at your office should be to use either or both of the two protection options that Office Message Encryption provides when sending an email message: Do Not Forward and Encrypt.

Going beyond security basics

Each of these steps is uniquely important, but the secret to eliminating the threat of malware can’t be boiled down to a one-size-fits-all security posture. Developing a strong policy for safeguarding data and emails on Microsoft 365 will require MSPs to understand each client’s unique security vulnerabilities and acknowledge the impact that certain best practices might have on their productivity. Following best security practices is only the first step toward establishing Microsoft 365 security.

For optimal email security, it’s best to go beyond basic Microsoft 365 functions and consider software that can keep an email server safe in the event of an attack or outage. Security isn’t a single, straightforward process, but a long journey that requires constant vigilance against advancing threats. These first steps will help lay a crucial foundation for companies hoping to remain protected from malware attacks. 

 

 

Interested in learning more about Email security? Explore our product suite to see how you can improve email security for your Microsoft 365 environment.

 

Additional reading:

Is it possible to never experience an IT security breach?
Cyberhygiene—The Fundamental Cornerstone of Good Security
The Top 7 Reasons to Back Up Office 365: Part Two
You might also like...
Automation

What the Head Nerds Were Up to in 2020

Security

January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be

Security

December 2020 Patch Tuesday—A quiet(er) finish to a busy year in vulnerabilities

Security

Documentation Management API and Why It’s Important for the MSP Business

Security

What Is FIPS-140-2 Standard and When Is It Required?

Security

Malware-as-a-Service: A Crucial Reason Why Security Has Grown More Complex

Want to stay up to date?

Get the latest MSP tips, tricks, and ideas sent to your inbox each week.

Loading form....

If the form does not load in a few seconds, it is probably because your browser is using Tracking Protection. This is either an Ad Blocker plug-in or your browser is in private mode. Please allow tracking on this page to request a subscription.

Note: Firefox users may see a shield icon to the left of the URL in the address bar. Click on this to disable tracking protection for this session/site

Recent Posts
  • What the Head Nerds Were Up to in 2020
  • RMM and PSA Tools: How to Make the Most of Both
  • How to Empower an IT Help Desk Team for Success
  • Six Tips That Will Make Managing Your MSP Company Easier
  • January 2021 Patch Tuesday: One Actively Exploited Vulnerability and a Few Likely to Be
Categories:
  • Security (230)
  • Tips & Advice (122)
  • Best Practices (94)
  • Managed Services (86)
  • Backup & Disaster Recovery (83)
  • The Head Nerds (75)
  • Business Growth (75)
  • IT Support (42)
  • Business (39)
  • Automation (37)
  • Cybersecurity (37)
  • Operations (34)
  • Mail (33)
  • Remote Management (28)
  • ITSM (25)
  • Cloud Computing (21)
  • Networking (21)
  • Data (21)
  • Marketing (14)
  • Product (11)
  • PSA (11)
  • Service Desk (5)
  • Services & Support (5)
  • Mobile (4)
  • Risk Intelligence (4)
  • Customer Service (3)
  • Internet of Things (3)
  • Research & Trends (2)
  • Training (2)
  • GDPR (2)
  • Business Risk (1)
  • LOGICcards (1)
Show moreless
SolarWinds MSP

Products
  • SolarWinds RMM
  • SolarWinds N-central
  • SolarWinds Backup
  • SolarWinds EDR
  • SolarWinds MSP Manager
  • SolarWinds Mail Assure
  • SolarWinds Risk Intelligence
  • SolarWinds Take Control
  • SolarWinds Passportal
  • All Products Use Cases
Solutions
  • Security Solutions
  • Monitoring Solutions
  • Efficiency Solutions
  • Identify which RMM solution is right for me
  • Drive Efficiency with Automation
  • Manage my MSP Business More Efficiently
  • Manage my IT Department More Efficiently
  • Layered Security
  • Cross-Platform Support
  • Data-Driven Insights
About
  • About Us
  • Careers
  • Newsroom
  • Leadership Team
  • Upcoming Events
  • Subscription Preferences
  • SolarWinds
  • SolarWinds Trust Center
  • COVID-19 Response
Support
  • SolarWinds RMM
  • Solarwinds N-central
  • SolarWinds Backup
  • SolarWinds Mail Assure
  • SolarWinds Take Control
  • SolarWinds MSP Manager
  • Solarwinds Risk Intelligence
  • Solarwinds Threat Monitor
  • SolarWinds Passportal
  • SolarWinds Take Control Downloads
  • Backup & Recovery Downloads
  • Service Status

Footer 2

  • Legal Documents
  • Privacy
  • California Privacy Rights
  • Security Information
  • Sitemap

© SolarWinds MSP Canada ULC and SolarWinds MSP UK Ltd.
All Rights Reserved.