Managing security settings and protections in Outlook on the web for business
Thank you for bringing this to the community's attention.
Domain impersonation and business email compromise attacks are unfortunately becoming increasingly common, particularly when financial transactions are involved.
To help reduce the risk of similar issue, organizations should consider implementing a layered approach to security, including:
- Configuring and enforcing SPF, DKIM, and DMARC to help prevent email spoofing.
- Enabling anti-phishing and impersonation protection within their email platform.
- Monitoring for lookalike domains that could be used to mimic their organization.
- Establishing a formal process to verify any banking or payment-related changes through a secondary trusted channel before funds are transferred.
- Enforcing Multi-Factor Authentication (MFA) for all accounts, especially those with financial or administrative privileges.
If you're using Microsoft 365, reviewing your Defender for Office 365 anti-phishing policies and DMARC implementation would be a good starting point.
Thank you for your understanding.