HomeSecurityMicrosoft: Phishing protection features in Office 365

Microsoft: Phishing protection features in Office 365

Microsoft announced that phishing protections, including OAuth app publisher verification and app consent policies, are now available in Office 365.

These protections are designed to protect Office 365 users from an app-based variant of phishing attacks known as “consent phishing.”.

Office 365 phishing

In this type of phishing attack, targets are tricked into granting access to their Office 365 accounts by granting permissions to malicious Office 365 OAuth applications.

Microsoft says it will release three updates designed to strengthen the security of the Office 365 application ecosystem, including:

  • Publisher verification general availability
  • User consent updates for unverified publishers
  • General availability of app consent policies

Block apps from unverified sources

“Publisher verification” allows developers to “add a verified identity to app registrations and prove to customers that the app comes from an authentic source.”

Since this feature entered public preview in May, more than 700 app publishers have been verified by Microsoft, totaling over 1,300 app registrations.

Apps implemented by accredited publishers feature the “Verified” badge on all ad consents, as well as on other screens where they appear to make it easier for end-users to verify the authenticity of the app.

The new generally available app for end-user consent give administrators “more control over which apps and permissions users can consent to.”

“To reduce the risk of malicious apps trying to trick users into granting them access to data , we recommend that you only allow user consent in apps that are published by a verified publisher,” Microsoft explains.

Once app consent policies are configured, users will only be able to grant permissions to apps developed by verified publishers, thus blocking future phishing attacks.

All Office 365 users will be protected from app-based attacks now that publisher verification is generally available as they “will no longer be able to consent to new apps registered after November 8, 2020 that come from unverified publishers.”

Such apps will be automatically flagged as dangerous and marked as unverified on all consent screens.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS