Office 365 Security Is Surprisingly Powerful — IF You Know It’s There.

Jan 29, 2020 | Cloud Computing, Cyber Security, IT News

Is your organization searching for a cloud-based software that offers strong security? Microsoft’s Office 365 might be your best solution. Today, we’re going to take a closer look at the security side of things — specifically, how Microsoft handles their “security as a service” approach and how their understanding of an organization’s security needs in today’s technology-based business world is integrated into the Office 365 platform for both government and commercial entities. We’ll also highlight a few essential features and steps to take, per their own recommendations.

The Microsoft 365 Secure Score

In the Microsoft 365 security center, from a centralized dashboard, you can monitor and improve the security for your Microsoft 365 identities, data, apps, devices and infrastructure. Your Microsoft Secure Score is a measurement of your organization’s security posture. The higher the number, the safer you are. Following the Security Score recommendations can protect your organization from threats.

You are given points for configuring recommended security features, performing security-related tasks (such as viewing reports), or addressing the improvement action with a third-party application or software. Some improvement actions only give points when fully completed, and some give partial points if they are completed for some devices or users. It may sound a bit like “gamification,” but you would be surprised how well this method works.

Multi-factor Authentication

Nearly everyone uses multi-factor authentication these days, and Microsoft especially is no stranger to it. It’s one of the easiest (and most essential) things you can set up to increase security. All this process refers to is that when logging in with your password, you also receive a confirmation code on a separate device (usually on your phone) to you will need in order to log in. This extra step can help prevent your password from being stolen or even notify you if someone is trying to access your account.

Email Malware Protection

The Microsoft 365 environment also includes protection against malware. It’s a strong service, but it doesn’t account for everything. Proper judgement and training is still going to be your best weapon against malware and phishing scams. Additionally, Microsoft 365 allows an administrator to outright block all attachments with file types that are commonly used for malware. These features are found within the Office 365 Security & Compliance Center, where various file type filters can be enabled.

Ransomware Protection

If you’ve been following our posts on Facebook, Twitter and Instagram, you should know by now that ransomware is currently a huge problem for businesses, and it’s only getting worse. Entire systems are locked down until a ransom is paid, which is often used to fund nefarious ends worldwide. Fortunately, 365 lets you curtail some of this by creating one or more “mail flow rules” to block file extensions that are commonly used for ransomware or to warn users who receive these attachments in email. For example, ransomware is often hidden inside macros. You can have Office 365 warn users before opening Office file attachments that include macros. You can also block various file types altogether.

Office 365 Security Is Surprisingly Powerful — IF You Know It’s There.These are only some of the full suite of security features offered within the entire Office 365 package. If you decided to go the Office 365 route, we’ll be happy to show you and explain every tool in the box. From message encryption to ATP Safe Attachment protection, we know the ins and outs and every hidden tweak and setting in order to make the most use of this software.

The potential power behind Office 365 is quite high, and we’re happy to help you wield it safely.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

Downtime Is a Cybersecurity Problem, Not Just an IT Problem

Downtime can affect payroll, customer service, compliance, productivity, revenue, and reputation. For small businesses and government contractors, outages are no longer just technical issues. This blog explains why downtime should be treated as a cybersecurity and business resilience problem, and how organizations can better prepare for disruptions.

Zero Trust Without the Buzzwords: What It Actually Looks Like in Practice

Zero Trust is often discussed as a complex cybersecurity strategy, but at its core, it is about verifying access, limiting unnecessary permissions, and reducing risk. This blog explains what Zero Trust actually looks like in practice for small businesses and government contractors — without the buzzwords, hype, or confusion.

Access Creep Is a Business Risk: How Over-Permissioned Users Create Exposure

Access creep happens when users accumulate permissions over time and keep access they no longer need. For small businesses and government contractors, this creates unnecessary cybersecurity, compliance, and operational risk. This blog explains how over-permissioned users increase exposure and what organizations can do to strengthen access controls, reduce privilege misuse, and improve audit readiness.

Why Identity-Based Attacks Dominate Cybersecurity in 2026

Identity has become the new cybersecurity perimeter. In 2026, attackers are increasingly using stolen credentials, MFA fatigue tactics, and identity misuse to gain access to business systems. This blog explains why identity-based attacks are dominating the threat landscape and what small businesses and government contractors can do to strengthen access controls, improve MFA, and reduce exposure.

The Audit Readiness Problem Government Contractors Can’t Afford to Ignore

Many government contractors are not failing audits because they lack tools. They are failing because documentation is incomplete, evidence is disorganized, and readiness starts too late. This blog explains the most common gaps and how to fix them before an audit begins.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic