Microsoft is making its Office 365 security better for businesses
Office 365 gets automated response to phishing, malicious links and malware
In an effort to help security teams deal with the barrage of critical alerts they receive daily, Microsoft has made its Automated Incident Response in Office 365 Advanced Threat Protection (ATP) available to all enterprise customers.
The software giant's automation feature is designed to aid security analysts in responding to alerts faster and more systemically.
In a recent blog post, Microsoft announced that it is making two categories of automated incident response available to its enterprise customers. The first category deals with automatic investigations that are triggered in response to new alerts that occur when users report phishing emails, click on a malicious link or when malware or a phishing emails are found in their mailboxes.
- Microsoft ups cloud security with Azure Sentinel launch
- Microsoft 365 update looks to supercharge your workplace
- Microsoft Edge is phasing out Flash
The second category consists of investigations that are initiated manually and use Microsoft's own 'automated playbook' sequences to get to the bottom of different scenarios and attack types.
Rich security playbooks
Microsoft's automation follows its rich security playbooks which are essentially a series of carefully logged steps that security teams can use to comprehensively investigate an alert. They also offer a set of recommended actions for containment and mitigation when dealing with an alert.
The company's playbooks correlate similar emails that have been sent or received within an organization to detect any suspicious activities for relevant users. Microsoft gives a few examples of flagged activities in its blog post citing mail forwarding, mail delegation, Office 365 Data Loss Prevention (DLP) violations and suspicious email sending patterns.
As part of the Microsoft Threat Protection promise, these playbooks also integrate with signals and detections from Microsoft Cloud App Security and Microsoft Defender ATP.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Organizations that have either an Office 365 ATP Plan 2 or Office 365 Enterprise E5 tier plan can take advantage of the company's automated incident response features beginning today.
- We've also highlighted the best online collaboration tools of 2019
Via ZDNet
After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home.