How to prevent malware attacks using anti-malware protection in M365?
+
Configuring anti-malware policies in Microsoft 365 is essential to stop malware emails from infiltrating your organization. These policies dictate how malware is detected and handled across incoming and outgoing emails. By regularly configuring and reviewing anti-malware policies, admins can stay ahead of evolving malware attacks.
Let's see how to create these anti-malware policies in the Microsoft Defender to help prevent malware emails.
- Access the Anti-malware page in the Microsoft 365 Defender portal and click the "+Create" option.
- Enter a name and description for your policy, then click "Next".
- Specify the users, groups, and domains to include or exclude from the policy. Then click "Next".
- In the Protection settings page, you can enable the common attachments filter. This filter blocks dangerous file types like .exe, .bat, .cmd, and others from being sent or received. You will also have the option to: Reject the message with a non-delivery report (NDR) or Quarantine the message.
- You can Enable zero-hour auto purge for malware to automatically remove malicious messages even after they have been delivered to mailboxes.
- Choose a Quarantine policy to decide who can manage quarantined messages with malware (e.g., release, delete).
- Configure Admin notifications to alert admins if malware is detected in emails from internal or external senders. Moreover, you can also customize the notification message.
- Review all the settings and click Submit.
After configuring your anti-malware policies in Microsoft 365, it's essential to keep track of any changes made to these policies. This helps to ensure that no unauthorized changes are made. However, native methods fall short as there is no dedicated way to audit changes made to an anti-malware policy.
Monitor critical changes to Microsoft 365 anti-malware policies with AdminDroid!
- The anti-malware configuration changes report offers a detailed overview of any changes made to the anti-malware policy.
- Using this report, admins can track the username, respective anti-malware policy, event time, and more.