Office 365 Security Is Surprisingly Powerful — IF You Know It’s There.

Jan 29, 2020 | Cloud Computing, Cyber Security, IT News

Is your organization searching for a cloud-based software that offers strong security? Microsoft’s Office 365 might be your best solution. Today, we’re going to take a closer look at the security side of things — specifically, how Microsoft handles their “security as a service” approach and how their understanding of an organization’s security needs in today’s technology-based business world is integrated into the Office 365 platform for both government and commercial entities. We’ll also highlight a few essential features and steps to take, per their own recommendations.

The Microsoft 365 Secure Score

In the Microsoft 365 security center, from a centralized dashboard, you can monitor and improve the security for your Microsoft 365 identities, data, apps, devices and infrastructure. Your Microsoft Secure Score is a measurement of your organization’s security posture. The higher the number, the safer you are. Following the Security Score recommendations can protect your organization from threats.

You are given points for configuring recommended security features, performing security-related tasks (such as viewing reports), or addressing the improvement action with a third-party application or software. Some improvement actions only give points when fully completed, and some give partial points if they are completed for some devices or users. It may sound a bit like “gamification,” but you would be surprised how well this method works.

Multi-factor Authentication

Nearly everyone uses multi-factor authentication these days, and Microsoft especially is no stranger to it. It’s one of the easiest (and most essential) things you can set up to increase security. All this process refers to is that when logging in with your password, you also receive a confirmation code on a separate device (usually on your phone) to you will need in order to log in. This extra step can help prevent your password from being stolen or even notify you if someone is trying to access your account.

Email Malware Protection

The Microsoft 365 environment also includes protection against malware. It’s a strong service, but it doesn’t account for everything. Proper judgement and training is still going to be your best weapon against malware and phishing scams. Additionally, Microsoft 365 allows an administrator to outright block all attachments with file types that are commonly used for malware. These features are found within the Office 365 Security & Compliance Center, where various file type filters can be enabled.

Ransomware Protection

If you’ve been following our posts on Facebook, Twitter and Instagram, you should know by now that ransomware is currently a huge problem for businesses, and it’s only getting worse. Entire systems are locked down until a ransom is paid, which is often used to fund nefarious ends worldwide. Fortunately, 365 lets you curtail some of this by creating one or more “mail flow rules” to block file extensions that are commonly used for ransomware or to warn users who receive these attachments in email. For example, ransomware is often hidden inside macros. You can have Office 365 warn users before opening Office file attachments that include macros. You can also block various file types altogether.

Office 365 Security Is Surprisingly Powerful — IF You Know It’s There.These are only some of the full suite of security features offered within the entire Office 365 package. If you decided to go the Office 365 route, we’ll be happy to show you and explain every tool in the box. From message encryption to ATP Safe Attachment protection, we know the ins and outs and every hidden tweak and setting in order to make the most use of this software.

The potential power behind Office 365 is quite high, and we’re happy to help you wield it safely.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

What Government Contractors Get Wrong About Secure Cloud Environments

Secure cloud environments require more than moving files into Microsoft 365, SharePoint, or another cloud platform. For government contractors, controlled access, proper configuration, CUI scoping, enclaves, and shared system responsibilities all matter. This blog explains what GovCons often get wrong about cloud security and how to stay aligned with current CMMC expectations.

Hybrid Work in 2026: The Endpoint Problem That Never Went Away

Hybrid work is now a normal part of business, but the endpoint problem never went away. Laptops, mobile devices, remote access tools, and unmanaged personal devices can create cybersecurity risk when they are not properly secured. This blog explains how small businesses and government contractors can strengthen endpoint security in 2026.

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic