Skip to content
CBT Nuggets
DemoBook a Demo

Secure messages by using Microsoft 365 Defender

This skill covers essential techniques for securing messages using Microsoft 365 Defender. It includes configuring anti-phishing, anti-spam, and anti-malware policies to protect users from various cyber threats. Additionally, it explores the use of safe links and safe attachments to enhance security within an organization. The skill provides practical steps and best practices for implementing these security measures effectively.

Full skill from MS-203. Preview the IT training 23,000+ organizations trust.

49m

Skill 1 of 5 in MS-203

Overview

Join John Munjoma as he covers essential techniques employed in securing messages using Microsoft 365 Defender.

Recommended Experience

  • None

Related Job Functions

  • Systems Admin
  • Systems Engineer

John’s path to becoming a trainer started when he found himself helping people more and more at work with tech-related issues.

Configure And Manage Anti-Phishing Policies

In this nugget, we configure an anti-phishing policy in Microsoft 365 Defender.

Knowledge Check

Which of the following protocols would protect against domain spoofing in Microsoft 365?

Configure and Manage Anti-Spam Policies

In this nugget, we go through the process of configuring anti-spam policies in Microsoft 365 Defender.

Knowledge Check

Phishing attacks can be stopped by configuring anti-spam messages in Microsoft 365. True or false?

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Configure and Manage Anti-Malware Policies

In this nugget, we configure an Anti-Malware Policy to protect users against impersonation.

Knowledge Check

What feature in Microsoft 365 Defender helps protect organizations against email-based attacks that involve social engineering techniques such as impersonation?

Configure and Manage Quarantine Policies

In this nugget, we focus on how we can configure custom quarantine policies in Microsoft 365 Defender.

Knowledge Check

The Limited Access option when configuring quarantine policies is the most secure option for message recipients. True or false?

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Configure and Manage Safe-Attachments

In this nugget, we go through the configuration of safe attachments in Microsoft 365 Defender and PowerShell.

Knowledge Check

An Administrator would like to verify whether the "Allow people to click through Protected View" option is disabled. Using PowerShell to remotely connect to Exchange Online, which cmdlet should the Administrator use to verify this?

Configuring Safe Links

In this nugget, we focus on how safe links function and how we can use them as an additional security measure in out tenant.

Knowledge Check

Which security feature in Microsoft 365 Defender involves rewriting URLs in emails and Teams messages?

Conclusion

I hope this has been informative for you and I would like to thank you for consuming.

View Transcript

Configure And Manage Anti-Phishing Policies

0:00[AUDIO LOGO]

0:06Hello, and thank you for joining me in this Nugget

0:08as we look at configuring anti-phishing policies.

0:12Now, if you're going to find yourself with a team within

0:14your organization where the concern is how best we protect

0:18our users from anti-phishing-- let's imagine that there is

0:21a hook over there and a fishing image--

0:24we actually have to look at a number of things

0:26before we can go ahead and say, this is what we're going to do.

0:30Now, some of those things that we have to look into

0:32are the various threat intelligence sources

0:35that we have within our environment because this

0:37is where we get the feeds in terms of what is training

0:40in a cybersecurity environment, and what exactly is being

0:43attacked, what methods are being used,

0:45and how best do we make sure that each

0:48and every user within our environment

0:49is actually protected against those.

0:52So by making use of a threat intelligence sources,

0:55whether those are recommended by Microsoft

0:56or other large vendors in our environment,

0:58we'd then be able to look into how best we could accurately

1:02create an anti-phishing policy within our environment.

1:06And then after the whole threat intelligence sources

1:08have directed us, we then can begin

1:10looking at the various areas around Exchange Online,

1:13for example, being able to look at the various filtering

1:16configurations that we can do that actually allow

1:18us to be able to thwart those messages that

1:21are likely to be malicious within our environment.

1:23Exchange Online is really key in ensuring

1:25that our protection for the various mailboxes that

1:27exist within the environment is enforced.

1:30In addition to that, it is very important for us to make sure

1:33that we have sender authentication implemented

1:36within our environment.

1:37Now, what's an authentication simply

1:39does is that it makes use of various protocols,

1:41such as sender policy framework, domain keys, identification

1:45mail, and many others to simply verify

1:48the authenticity of those particular emails that are

1:50coming into your organization.

1:52In essence, the implementation of these protocols

1:54would simply enhance your security

1:56by ensuring that each and every email that

1:58is sent to your users is actually

2:00taken through a process of verifying

2:02its authenticity of vetting it, finding itself

2:05within your environment.

2:06And that vetting would prevent malicious attacks,

2:09such as domain spoofing, where a malicious attacker would simply

2:12be able to replicate a particular domain

2:15and thereby send out an email that

2:17may end up compromising the security of your environment.

2:20So armed with the rightful information and the best

2:22configuration practices, you just

2:24have to protect, refine, and repeat.

2:27The protection part simply means that you're

2:29going to select the various users or mailboxes that

2:32are simply supposed to be included

2:34in your phishing configuration.

2:35So if your policy is targeting the Sales department,

2:38you have to make sure that those groups

2:39and users within the cell's department are included.

2:41Now, there are times when you would

2:43like to exclude certain users.

2:45If it is necessary that you exclude maybe the executives,

2:47you have to go ahead and exclude those users maybe

2:50for training purposes, or you've got a system limitation,

2:53or maybe you simply want to avoid

2:54having a lot of false positives, et cetera.

2:56Now, the fact that you've configured your protection part

2:59doesn't mean that everything is good, and you sit and relax.

3:02You have to continually refine.

3:04This simply looks into running updates

3:07for those particular policies whenever necessary.

3:10You have to constantly review and make

3:12sure that your policies are actually

3:14in line with the various trends that you've picked up

3:16from your threat intelligence sources

3:18and that your users are secure.

3:20And that process has to be repeated

3:22through and through in order for us

3:25to make sure that our environment are secure.

3:27Well, without further ado, let's dive into Microsoft

3:29365 and look at how we can configure our phishing

3:32policies.

3:33So here we are within Microsoft 365 admin center.

3:36Let's go ahead and access our Security admin center.

3:39And here within our Security admin center,

3:41notice that Microsoft 365 Defender opens up.

3:43And we simply have to go and access Email and collaboration.

3:46Now, it's in this area that we can access policies and rules,

3:50and thereby having access to threat policies, where we can

3:53create our phishing policies.

3:55So if we scroll down, there we have anti-phishing policies.

3:58So go ahead and open that.

4:00And then we can start the process of creating our own.

4:02Now, you'd realize that there is a default anti-phishing policy

4:05that Microsoft already had put for us over here.

4:07But if we create one, it should actually take precedence.

4:10Why?

4:10Because this is just default. So we

4:13want to customize something for organization.

4:15So let's say this is going to be for our Sales team,

4:18and this is going to be to protect our Sales

4:20team from phishing attacks.

4:22So go ahead and click Next over there.

4:24And here, we have to decide whom among the Sales team

4:28has to take part in this particular policy.

4:31So it could be a particular user, or it could be a group.

4:35And if you're going to be dealing with groups,

4:37you have to ensure that those groups are either Microsoft 365

4:40groups or distribution list that you have in your environment,

4:43as those are the easiest to work with when

4:45it comes to implementing phishing policies using groups

4:49within Microsoft 365.

4:50You can also make use of domains.

4:52This is very prominent for organizations that

4:54may have different domains.

4:55Maybe you have a Sales team that have a different domain.

4:57You can go ahead and simply specify that over there.

5:00Now, in this case, I just go ahead and type Sales.

5:02I've got a Sales department group over here.

5:04So go ahead and select the Sales team.

5:06If you have multiple groups within your environment,

5:08it's very much possible for you to go ahead and select

5:10all those that are supposed to participate in that policy.

5:14There are times when you really have to exclude certain users.

5:16If that's something that you'd like to do,

5:18then you can go ahead and click over there

5:19and exclude those users.

5:21It is possible that you might have maybe users that

5:23aren't supposed to be included due to special circumstances

5:26that you may have in your organization.

5:28And this is where you would simply add those users over

5:30here.

5:31Let's go ahead and click Next.

5:32This area over here simply looks at how

5:34aggressive this particular policy is going to be.

5:37And if you really make it to be more aggressive,

5:40that simply means you may end up finding yourself

5:42in a scenario, whereby even information that is not

5:44regarded as a phishing attack could actually

5:47be prevented from making its way to your mailbox.

5:49So it's quite important to make sure

5:51that this is in line with what you

5:53want to do by making it a little bit more moderate.

5:55So if you're getting a lot of false positives,

5:57or simply reports from users who are complaining

6:00to say the emails that were previously receiving

6:02in their mailboxes are no longer coming through,

6:04this is where you simply have to come and make adjustment.

6:08Over here, we can simply protect impersonation,

6:11where another user maybe externally or internally can

6:14actually be impersonated.

6:15By simply enabling this feature, that would prevent that.

6:18And we can have up to 350 users or mailboxes

6:22protected by making use of this feature over here.

6:25And then we have Enable domain protection.

6:27If we have multiple domains within our environment,

6:30whether these are domains that we own

6:32or domains of our partners and suppliers,

6:34we can simply make adjustments over here.

6:36For example, if I went to view my domains,

6:38if we had multiple domains within this picture a tenant,

6:40we'd simply be able to have them listed over here.

6:42And we could also have those protected

6:45within their environment.

6:46Now, imagine that we were a retailer company,

6:48and we have multiple suppliers who actually

6:51provide the various produce and merchandise that we actually

6:54trade.

6:55It's important for us to actually go ahead and include

6:57them over here.

6:58And that would allow us to make sure

7:00that each and every time such messages are coming through,

7:02we are assured that the messages that we are receiving

7:05are coming from legitimate domains.

7:07If we scroll down once, you'd realize

7:09we have Enable mailbox intelligence, which

7:11is recommended over there.

7:13And then we have Enable intelligence for impersonation

7:15protection also recommended, Enable spoof intelligence

7:19also recommended.

7:19Now, these are features that we simply have to make sure

7:22that they are available each and every time

7:23we're configuring our anti-phishing policies,

7:25as they help enhance that security.

7:28So if we go ahead and click Next,

7:29we have this particular area where we have multiple actions

7:32to carry out.

7:33Now, the actions simply define what should happen in the event

7:36that there is a violation of this particular policy.

7:39For example, if a message is detected as user impersonation,

7:42what should happen?

7:43Should it be redirected to a particular email address?

7:45This can become handy if you have maybe an admin who

7:49is watching over what is happening

7:50with your environment.

7:51And they can always be able to respond every time there's

7:54this kind of scenario.

7:55So what you'd like to do is to make sure

7:56that each and every time there is that kind of a message,

7:59the recipient should actually receive it.

8:01But then that particular admin should

8:03be the one to look into that message upon receiving it

8:06and verify whether it is authentic

8:08and take further action.

8:10Now, the best practice for this is just to delete the message.

8:13But also, deleting messages may save us from being victims.

8:16However, it may deny us our chance

8:18to really be able to get inside information regarding

8:21the perpetrators intentions.

8:22And the same can be applied to the domains.

8:25If we detect domain impersonation,

8:27what should we do within our environment?

8:28Should we quarantine the message?

8:30Or should we delete the message before it is delivered?

8:33You have mailbox intelligence over here.

8:35We also have others, such as if message is detected as a spoof

8:39by spoof intelligence, we actually

8:40want to maybe quarantine that message

8:42and let our own look into what is happening.

8:44Now, you may have additional quarantine policies that

8:47may specify for how long that message should

8:49be kept in quarantine, et cetera, the escalation

8:52procedures, and so on and so forth.

8:54But over here, we have the safety tips,

8:56which are also very important indicators

8:58that users can simply be notified

9:00of each and every time there is suspicious information that

9:02has been shared.

9:03For instance, we could look at Show contact safety tips,

9:06which is actually recommended.

9:07And that is simply there to notify the recipient

9:10when there is something that is happening that is unusual.

9:12Unusual activity may include receiving an email

9:15from a particular sender for the very first time.

9:18So if that email is coming into my mailbox for the first time,

9:21I'll be notified to say, hey, you

9:22know what, this sender is sending an email for the very

9:25first time.

9:25Take caution.

9:26So we have others here, such as Short user impersonation tips.

9:30You have Show domain impersonation tips.

9:32All of these would be very helpful for the various users

9:36that we have within our environment

9:37in their everyday work life to identify

9:40anything that is likely to cause harm to environment.

9:43And this is where also user training becomes very important

9:46because if your users are unable to actually identify

9:49those tips, it becomes very difficult for them

9:52to know when they are vulnerable and when they are not.

9:55With these changes down over here,

9:56we go ahead and click Next.

9:58And then we can have a quick review of the configuration.

10:01And if everything regarding your phishing policy looks perfect,

10:04then you can go ahead and submit that.

10:06And eventually, that policy becomes enabled,

10:09or it simply goes on.

10:10And over here, you can actually see that the policy

10:13takes precedence.

10:14And your Sales teams will be protected.

10:16So this is how, my friend, we can make use of phishing policy

10:19within our environment to protect

10:20the various users that we have as they collaborate.

10:23For now, I hope this has been informative for you,

10:26and I'd like to thank you for viewing.

Configure and Manage Anti-Spam Policies

0:00[AUDIO LOGO]

0:05Nobody enjoys it.

0:07And it's not good.

0:07We're going to look at how we can

0:09stop spam messages by configuring anti-spam policies

0:12within Microsoft 365.

0:13Now, spam messages are one of the menaces

0:16that we actually have to manage within our environment.

0:18And these can actually be very distracting and time-consuming

0:21for our users, whether they'd be ads,

0:23or maybe they're sales pitches, or whatever

0:26it that is being sent away from unknown domains,

0:29maybe to sell us something, or simply ask us to participate

0:33in a particular activity.

0:34And within Microsoft 365, we have

0:36means through which you can actually manage these

0:38by making sure that our users are not bombarded

0:41by unnecessary spam messages.

0:44So back in our Microsoft 365 admin center,

0:46let us access Microsoft 365 Defender by going to Security.

0:50And over here, we'll go back to Email and collaboration

0:54and access Policies and rules.

0:56And then go back and access Threat policies.

0:59So let us proceed by clicking on anti-spam.

1:02This is where we can actually define what should be happening

1:05to our spam messages.

1:06And each and every time we actually get

1:08an email that is detected as spam,

1:11what action must be taken in the event of receiving

1:14such message?

1:15One thing you would notice when creating your custom anti-spam

1:18policies is that you have two rules.

1:20It's either going to be an inbound anti-spam policy

1:23or an outbound anti-spam policy.

1:25Now, if you're really concerned about all the messages coming

1:28in from various sources that may actually end up

1:31as spam within your mailboxes, then that kind of policy

1:35must be an inbound anti-spam policy.

1:37So this could be for the entire organization, or simply

1:40a group of users that you have within your environment.

1:43So with that in place, you can go ahead and create

1:46your anti-spam policy.

1:48You have your name.

1:49You can give a short description,

1:50detailing what exactly that particular policy is doing.

1:53And then you can go ahead and click Next.

1:56So here, we have to specify, just

1:58like we did in the previous Nugget,

2:00where we have to specify the users or the domains

2:02or the groups, et cetera.

2:03So over here, simply go ahead and say this

2:05is going to be for my Sales team.

2:07And I'll select the Sales teams that I have within my tenant.

2:10And with that in place, we can go ahead

2:13and exclude certain users or groups or domains

2:16within our environment, or simply go and click Next.

2:19Now, under the Bulk email threshold,

2:21by default, this is set to 7.

2:22But if we drop it lower to, let's

2:25say 1, that simply means that we'll be receiving messages

2:28mainly from ads that we may have signed up

2:31or newsletters that we've signed up to, et cetera.

2:33But that may also negate the coming in of any traffic

2:37that could also be legitimate.

2:38So for us to be able to maneuver and make sure

2:41that we are in a safe place, we could actually

2:44work with what Microsoft recommends being on 7.

2:47But if we really think we are missing out on some information

2:49that we're previously able to access,

2:52then we could set it up to 8.

2:53However, this is not recommended.

2:55So 1 is the best.

2:567 is what is default and recommended.

2:59And 9 is the worst.

3:00But what if we really want to go as low as

3:03possible and at the same time, be

3:04able to allow certain types of traffic?

3:06Well, there is an option for that.

3:08All we could do is to drop this all the way down,

3:10maybe to 2 or 3 or depending on what exactly we want.

3:13And then look at the various options provided

3:15under the increased spam score.

3:17What is happening in this area is

3:18that you're going to allow certain areas, such as image

3:22links to remote websites, to have a higher score,

3:25and thereby allowing the traffic to make

3:27its way to your mailbox.

3:28So we can go ahead and say image links to remote websites.

3:31Yes, we want that.

3:32Numeric IP addresses, not really, so keep it on off.

3:35URL to another port--

3:37that actually sounds a little bit dubious.

3:39So you might actually just want to keep it off.

3:41But we might also want to have information that is linking us

3:45to a dot biz or a dot info website, which

3:48is really cool to have, but not to show whether that

3:50will work for or against us.

3:52So just go ahead and put it on Test

3:54and see how things would turn out.

3:55And then we have the kind of messages

3:57that we may want to be marked as spam within an environment.

4:00So if a message simply comes in and it's empty, yes,

4:03you can mark that as spam.

4:04If there is some form of embedded tags that are in HTML,

4:08yes, you can mark that as spam.

4:09And these would simply help us to customize and well-design

4:13our spam policy in such a way that it's

4:15able to capture features that are actually regarded

4:18as spam within our environment.

4:20So we can go ahead and figure out all these areas

4:22and make sure that we have the rightful selections that

4:25would protect our users.

4:26We have options such as a message containing

4:28a particular language.

4:29So we can simply go ahead and say yes.

4:31And maybe that language is, let's say, Belarusian.

4:34We'll go ahead and specify that over there.

4:36And you have from these countries.

4:38You can specify what countries you'd

4:39like to have in that area.

4:41And they simply match your spam policy more effective

4:44in protecting the various users that you

4:46have in your environment.

4:47And finally, you can decide to receive

4:49an email for all those options that you may have

4:51selected to be in Test mode.

4:52So over here, we can simply go ahead and say, all right,

4:54we would like Alex to be receiving all those emails.

4:57And then we can go ahead and click Next.

4:58Now, you'd realize that over here, we

5:00have the various actions that you may simply

5:02want to see for each and every matched policy.

5:05So in the event that we receive a spam message,

5:08we can decide what this policy should actually do.

5:11So we can choose to move the message to a junk email

5:14folder, which is actually good practice

5:16because once it's moved to junk, in about 30 days,

5:18Microsoft will flush it out from there.

5:20So we can actually keep that ease.

5:22But if we want to be able to maybe redirect

5:24that particular message or delete the message,

5:26these are options that are also provided over here.

5:29We have High confidence spam.

5:30This simply means that the kind of message

5:32that you received as spam is highly rated as being spam.

5:35So it's that kind of messages.

5:36The best practice would be for us

5:38to go ahead and just delete them.

5:39And then we have phishing messages that we may simply

5:42want to also delete.

5:43And if we decide to quarantine them within our environment,

5:45then we simply have to go and choose

5:47one of our quarantine policies.

5:48The best practice is for us to go and choose

5:51an administrator who will look into those messages

5:53while they're in quarantine.

5:54We have High confidence phishing,

5:56which can also configure over there,

5:57and multiple other options that we can actually

5:59work with to make sure that we are secure.

6:02Now, when it comes to granting of those spam messages,

6:04we can decide for how long we'd like to retain them.

6:07Now, by default, this is set to 15.

6:08If you want to retain them for a longer period,

6:10we can always increase that or decrease, as desired.

6:14The Safety tips area is very important.

6:16And if you encounter any of these deselected like these

6:19and show that these are enabled, as this

6:21is what allows your users to receive banner messages that

6:24are keeping them of how vulnerable

6:26they could be by accessing that particular message.

6:28If messages are rated as being spam,

6:30then a safety tip is one of those layers of security

6:33you'd need to inform a user to act wisely.

6:37From here, we can go ahead and click Next.

6:39And here, we have the Allow and block list.

6:42So if you want to be allowing certain users

6:45within our environment, you can go ahead and add them over

6:47here.

6:47If we want to block those users, it's the same thing over here.

6:50So we can also do the same for the various domains and users

6:53that would like to allow or block within our environment.

6:55Now, depending with the approach that you

6:57would want to have in your environment

6:58and using your threat intelligence sources,

7:00you could actually be able to pick up certain domains

7:02and add them over here under your Blocked list.

7:05But under Senders, let's see if I can block a sender.

7:08I'll just go ahead and add my sender over here as Cameroon.

7:12Click Add sender's.

7:13Done.

7:14And then you can click Next.

7:15So this is the policy that we have now created.

7:18Let's see if when we try to send an email using Cameroon's email

7:23address and verify whether that email is going to go through,

7:26or be thwarted by this particular policy.

7:28So go ahead and click Done over here.

7:30And there is our policy.

7:32So let's go ahead and open Cameroon's mailbox.

7:35So let us test this out.

7:37I've got a user over here by the name of Megan.

7:39And Megan is part of my Sales groups.

7:41So those groups that I added earlier actually

7:44contain a user by the name of Megan.

7:46So if we go and try to send Megan an email from here,

7:50let's just try this out, let's say

7:53this is going to be a new email, and it's going

7:55to be directed to Megan Bowen.

7:58There we go.

7:59So let's say this is going to be spam.

8:01And then we can just also say in the message area over there

8:05as spam.

8:06And if we send this out, our expectation

8:08is that this message will not go through.

8:12So we've tried to send that out.

8:13Just quickly minimize that.

8:15And try to go to a legitimate email address.

8:19We can see here, there isn't anything brought in.

8:21Let's see what happens if we send

8:23a legitimate email to Megan.

8:25So just expand that as well.

8:27New email.

8:28And then we can say we're looking for Megan.

8:32And then we just say basic hello.

8:36So let's see if this is going to go through.

8:38Send that.

8:40And then you minimize it.

8:41Let's wait within-- and there we go.

8:43So this particular message from administrator

8:45does come through.

8:46But the other message that is coming from the spam message,

8:50does it actually find its way through?

8:52And this is how we can leverage the anti-spam policies

8:54to prevent messages that are malicious, making

8:57their way into our mailboxes.

8:59For now, my friend, I hope this has been informative for you,

9:01and I'd like to thank you for viewing.

Configure and Manage Anti-Malware Policies

0:00[AUDIO LOGO]

0:05Hello, and thank you for joining me in this Nugget

0:07as we configure and manage anti-malware policies.

0:12So it is great practice for us to be

0:13able to configure various Microsoft 365 solutions that

0:16will provide layers and layers of security

0:19to various resources and data that we

0:21have in our environment.

0:22But for us to be able to have anti-malware policies,

0:25we have to go and access the security area.

0:27And this will bring us into the Microsoft 365 Defender

0:30area, where we can actually access the various policies

0:33and rules.

0:34Now, once we are in here, we can access Threat policies.

0:38And from Threat policies, we have Anti-malware.

0:41So by clicking on that area, you'd

0:43realize that we have the area where

0:44we're able to see the various existing policies.

0:47And we can also create our own policies.

0:49But before we can go ahead and create our own policies,

0:52there are preset policies that actually exist in this area.

0:55And it's important, very important

0:56that you go and look at those and figure out whether they

0:59are enabled for environment.

1:00So just access them from the recommendation notification

1:03over here by clicking on Preset security policies.

1:05And this opens this Preset security policies area, where

1:09we have built-in policies.

1:10You'd realize that this is what is contained

1:12within those built-in policies.

1:14And if you wanted to exclude certain users from actually

1:17participating in that, you could go and add them over here.

1:19We also have the standard protection.

1:21And this can actually configure.

1:23And this is what is actually covered,

1:25features which is balanced action for malicious content,

1:27balanced handling of bulk content, et cetera.

1:30This can actually protect you from various orchestration

1:33and spamming that may actually happen in your mailboxes.

1:36You also have strict protection, which you can also implement.

1:39This is a version that is more aggressive in terms

1:41of how it controls malicious mail,

1:44the various management of bulk emails

1:46that are being sent within your environment,

1:48and many other machine learning tools that would actually

1:50enable you to be more secure than you would be

1:53with standard configurations.

1:55So let's quickly go ahead and look

1:57at the standard protection.

1:58We go ahead and click Manage protection settings.

2:00This area brings us into this particular window,

2:03where we're able to define the various users we would like

2:06to participate in this policy.

2:08So let's assume that this is meant for all users.

2:11We just set it to all recipients within our environment.

2:14If we wanted to exclude certain users,

2:15like administrators, in case this is just a pilot test,

2:18then you can go ahead and select them over there.

2:21Then you can go ahead and click Next.

2:22And over here, we can look at the various users

2:24where we can actually apply Defender for Office 365.

2:28And this is really important in making sure

2:30that Defender for Office 365 is simply implemented

2:34so that our users can be protected

2:36from the malicious types of malware that

2:38may come through Office 365.

2:40And if you want to apply this again

2:41to a specific group of users or recipients,

2:44we can still go ahead and make use

2:45of these options over there.

2:47And thereafter, we can click Next.

2:48And this brings us into the Impersonation protection area.

2:52Now, this is really a very important area

2:54in making sure that if an attacker has crafted

2:57some form of emails so as to impersonate

2:59the executives within your environment,

3:00you would be proactively having some form

3:02of policy within your environment

3:03that actually thought such kind of actions.

3:06And this is what impersonation policy simply looks for.

3:08So down here, we can always be looking for the various users

3:11that we do not want to see being impersonated.

3:14For example, if Allan is our finance manager,

3:17we can simply go and say Allan over there.

3:19And then go ahead and look for their email address.

3:21Having them added over there simply

3:23allows us to protect this particular user

3:26against these kind of attacks.

3:29Once that has been set, we can go ahead and click Next.

3:31And this brings us into the domains to flag

3:33when impersonated by attackers.

3:34Now, these could be our own domains or the domains

3:36of the various stakeholders or partners

3:39that you trade with that you may simply want to add over here,

3:41such that in the event that there

3:43is some form of impersonation that has happened,

3:45the messages that has actually come

3:47with that particular domain could

3:48be quarantined and thereby protecting the intended target.

3:51Let us look at the following section.

3:53Now, here we have all trusted email addresses and domains

3:56that you may want to have.

3:58So over here, we can simply add our own domain.

4:00We can also add the domains of our trade partners

4:03and various stakeholders, et cetera.

4:05Then you can click Next.

4:06In this area, we simply want to decide

4:08whether this particular policy should be turned off,

4:10or whether we should leave it on upon completion,

4:12or leave it as is.

4:13Go and click Next.

4:14And this gives us an opportunity to quickly preview

4:17this particular policy.

4:18Now, this becomes very important in securing

4:20the various areas, such as Office 365 impersonation,

4:24and other things that we may actually

4:25overlook as we consider what areas to protect

4:28within our environment.

4:29So click Done.

4:30And once that is done, we can head

4:32back to our rules and policies from where we can actually

4:35configure the desired anti-malware policy.

4:38So here, we have our standard preset security policy.

4:41Let's go ahead and create a new one.

4:42And this is going to be, let's say for the Sales department.

4:45We can give a description over here as

4:47to how this is protecting the people

4:49within that particular department.

4:50We go ahead and click Next.

4:52And here, we can specify the users or the groups

4:55that we simply want to see participating

4:57in this particular policy.

4:59So this is going to be Sales team.

5:01And then it's also going to add the Sales group.

5:03There we go.

5:04And once we've added those groups,

5:05you can always go in add domains or exclude users, groups,

5:08and domains.

5:09Let's go ahead and click Next.

5:10In here, you'd realize that we have various protection

5:13settings.

5:14And what you're seeing here are various types

5:16of formats which are identified as malware.

5:20Now, if you're going to be having any file that

5:22is an attachment that comes to your mailbox

5:23and carries any of these formats,

5:25then that file will not make it.

5:27It's important, therefore, to make sure

5:29that you exclude that particular format from this list.

5:32For example, you might have anything that is in scr.

5:35So you might just want to remove that.

5:37And if you have anything that is in dot vb or maybe dot z,

5:40you can go ahead and remove that.

5:42Otherwise, Microsoft will also thwart

5:44all those types of formats.

5:46If you have additional format types

5:48that you'd like to add in here, you can always go over there.

5:51Type it and add it over there.

5:53Now, this becomes very handy in making sure that it actually

5:56follows each and every attachment that

5:58comes through our environment.

5:59And if there is anything that has an executable potential,

6:02then that could actually be stopped

6:04from being executed within our environment.

6:06So assuming that an email was sent to your mailbox that

6:08had a dot cmd attachment, that particular email itself

6:12will not make it to your inbox.

6:14And what Microsoft does is that it will simply

6:16reject the delivery of that email

6:18and send an NDR or a Non-delivery Receipt

6:21to the sender.

6:22So the sender will be notified to say, hey,

6:24you know what, this user does not accept

6:26this format of attachments.

6:27And then the sender would decide whether they

6:29would send something differently,

6:30or it would just be a losing battle,

6:32or you can decide to quarantine.

6:34Now, this is not very recommendable

6:37because that message will make it to your environment.

6:39It will make it to your mailbox.

6:40And if we have a user who is not well-informed,

6:43they may end up tinkering with that message

6:45and executing any file that may actually

6:48become very malicious to the rest of us

6:50within our environment.

6:51So it's always best to leave it on Reject messages

6:54with an NDR sent to the sender.

6:56Then we have Enable zero-hour auto purge

6:58for malware, which is just a method

7:00to quarantine any message that may have been missed.

7:03So if there is any message that found itself into our mailbox,

7:06this option over here would go over there

7:09and collect those emails and quarantine them.

7:11And once they are in quarantine, we

7:13can then decide who should have access to that.

7:15It's always important to make sure

7:17that only administrators have access

7:19to those particular folders.

7:22The rest of this section, in terms of configuration,

7:25focuses on notification.

7:26How do we want our various stakeholders,

7:29especially from a security perspective,

7:31to be informed whenever there is anything that actually

7:33aligns with this policy?

7:34So we might look at notifying an administrator

7:37about undelivered message from internal senders or even

7:41undelivered message from external senders

7:43so that each and every time there is any message that

7:45is pending in the environment, those administrators are

7:48notified, and they can take action.

7:50So all we need to do is to specify

7:52the email addresses of those administrators over there.

7:55And once that is done, we can go ahead and click Next.

7:58And then we can review this particular policy

8:00and submit it.

8:01Now, anti-malware policies are very important.

8:04They are not a substitute for anti-viruses.

8:05But when combined with all different types of security

8:09solutions that we provided within our environment,

8:11we definitely can end up with a formidable environment.

8:14For now, my friend, I hope this has been informative for you,

8:17and I'd like to thank you for viewing.

Configure and Manage Quarantine Policies

0:00[AUDIO LOGO]

0:05After COVID, we no longer have to overemphasize

0:08on the importance of quarantine.

0:10Hello, and welcome.

0:11In this Nugget, we're going to look

0:12at how we can go about configuring

0:13quarantine policies.

0:16So quarantine policies are security policies

0:18that are designed to isolate and contain

0:20potentially malicious or suspicious files and messages

0:24that may traverse our network.

0:25And by use of Microsoft 365 Defender and Advanced Threat

0:29Protection, we can craft the best quarantine policies

0:32that would help protect the various areas of our tenant.

0:35For example, you could be interested in looking

0:37at our Exchange area, looking at the various mailboxes,

0:40and how we can simply protect our users from harm

0:44that may come as a result of maybe user clicking

0:46on a link or an attachment that may

0:48lead to the compromise of various resources

0:50that we have in our environment.

0:51We could also look at the various endpoints

0:53that we have within our environment

0:55and configure them in such a way that if there

0:57is a file that is a corrupt file that is actually accessing

1:00an endpoint, that particular endpoint should actually

1:03be isolated.

1:04So the file that is contained within that particular endpoint

1:07does not end up being transmitted to other devices

1:09that we have in our environment.

1:11And finally, cloud applications.

1:13Cloud applications could also be secured.

1:15And we can have some quarantine policies in place

1:18that would make sure that each and every time

1:20a cloud application accesses a file in the event

1:23that particular file is actually compromised or it's corrupt,

1:26then we can also lock that particular application

1:30and remediate that incident from the confinement

1:32of that application.

1:33So all this happens with the help of these tools over here.

1:37And we can let our own set up various alerts that

1:40could be sent to our administrators,

1:42notifying them of the various changes,

1:44or even certain things that would

1:45help them to proactively resolve issues within our tenant.

1:49Well, without further ado, let's dive into Microsoft

1:51365 and look at how we can configure

1:53our quarantine policies.

1:55So we're back in our Microsoft 365 Defender area.

1:57And if you go to Email collaboration,

1:59right under that, you have Policies and rules.

2:01You should be able to access this section over here.

2:04Now, if you scroll all the way down,

2:06you have quarantine policies.

2:08We'll click on that, and in here, we

2:10have some default quarantine policies that Microsoft

2:12has already designed for us.

2:14But we can go ahead and create our own custom policies.

2:17So these are the ones that are here by default.

2:19Let's go and click Add custom policy over here.

2:22And this simply allows us to begin crafting

2:24our quarantine policies.

2:26So this is going to be for our sales department.

2:29So this is going to be Sales-Q, for example.

2:31We can go ahead and click Next.

2:32And here, we have the various message access definitions.

2:35Now, if you look closely, we have the limited access.

2:38And this seems to be what Microsoft recommends

2:40because over here, users are not really

2:43having the power to be able to access

2:45a quarantine message, or maybe even delete,

2:47or release it, et cetera.

2:49So this simply keeps your team very safe.

2:52But if you think this is not enough,

2:53your team provided have been trained in information security

2:56and there is some form of awareness and the ability

3:00for them to be able to identify what

3:02is likely to be dangerous and malicious

3:04within that environment, then you can look

3:06at these advanced features.

3:07Now, if we go ahead select Set specific access,

3:10we then can decide what our users must be able to perform.

3:13So under Release action preference,

3:15for example, we can simply go and say Allow recipients

3:18to request a message be released, or Allow recipients

3:21to release a message from quarantine.

3:22Now, this would mean we're going really

3:24far in terms of giving these users the privilege

3:27to be able to interact and play around

3:29with those quarantine messages, which are potentially

3:32harmful for environment.

3:33So I would simply say let us give them the privilege

3:35to request each and every time they've got a message, which

3:37they think should actually be given or handed over to them.

3:41Then we can look into it prior to them having access to that.

3:43And further than that, we can decide

3:45whether these users should be able to delete

3:48those messages, preview, or even block

3:51the sender once they have an access to those messages

3:54or files.

3:55However, the safest zones to remain in the Limited access

3:59over there.

3:59Now, let's go ahead and click Next.

4:01In this area, we can decide whether we'd

4:03like to have some quarantine notifications.

4:05Yes, we would like to.

4:07And once we have that set up, we can go and click Next.

4:09We can do a quick preview of what we've configured

4:12and submit that particular quarantine policy.

4:14So these are very important in ensuring

4:17that we have the desired policies set in place

4:20and that they accurately reflect what

4:21we'd like to see happening with the various users

4:23that we have within the environment as far

4:25as the quarantining of files and messages is concerned.

4:29So there we have our policy over here.

4:31And if we select it and go to Global settings,

4:33this is where we then be able to configure

4:36the various information types that

4:38have to do with the sender of the quarantine message.

4:40For example, over here, we have to specify the quarantine name.

4:43So let's say the sender is going to be Allan.

4:45And then here, we have to specify the email address.

4:48Let's just search for Allan over here.

4:50That's Allan Deyoung.

4:51And then we can say the subject is

4:53going to be message has been quarantined.

4:55And then we can add the information that is relevant.

4:57Default language, you can set that to English,

5:00and many of the information types

5:01that you may simply want to have in this area,

5:03such your company logo, if you'd like to note that,

5:05and how often you would like to see the messages being

5:08sent out.

5:09Is it every 4 hours or daily or weekly?

5:11Now, the frequency here is very important

5:13because if we make them too long, again,

5:15it becomes a challenge for this person

5:16to be well-informed in time as what exactly could actually

5:20be happening within that particular environment.

5:23So let's go ahead over here and click on Save.

5:25And with that in place, we can then

5:27anticipate each and every user, who

5:29happens to have a message in quarantine,

5:31to actually receive this within their environment.

5:34Well, this is how we can make use of quarantine policies

5:36to inform various users that we have within our environment.

5:39And for now, I hope this has been informative for you,

5:41and I'd like to thank you for viewing.

Configure and Manage Safe-Attachments

0:00[AUDIO LOGO]

0:05Hello, and thank you for joining me in this Nugget

0:07as we look at how we can go about configuring

0:09safe attachments within our tenant.

0:11So we just looked at how we can create quarantine policies

0:14within our environment.

0:15But attackers use different means and ways

0:18to try and compromise our environments.

0:20And thereby, it's very important for us

0:21to make use of the various solutions that

0:24are available to protect our users and the resources

0:26that we have within the environment.

0:28So let us go ahead and look at how we

0:29can configure safe attachments.

0:31This is ideal for securing information

0:34that come in form of attachments,

0:36as well as for our SharePoint sites

0:38that may be used to share various types of files.

0:41So in here, we go ahead and create our attachment policy.

0:45And again, this is going to be for our Sales department.

0:48We can always have a description over there.

0:50We'll go ahead and click Next.

0:51And we'll point these to the various groups

0:53that we have within an environment.

0:55So add our Sales group as well as the Sales team.

0:58Now, once we have done that in place, as usual,

1:01we can always add various domains,

1:03as well as exclude certain users within our environment.

1:06But if everything over here has been configured,

1:08the work remains to be done under the Settings area.

1:11Now, it's in the Settings area where

1:12we can determine what should be happening,

1:14the various types of files that come as attachments

1:16within our environment.

1:18So if you scroll down, you'd realize

1:19we have different options that are provided over here.

1:21And if any email is sent to us with an attachment that

1:26actually contains malware, then we

1:28have to decide what has to happen over here.

1:30For instance, if we turn this to off,

1:31it simply means that particular email

1:33will make its way into our mailbox

1:36without being scanned at all.

1:37Then we also have Monitor.

1:39This simply allows us to be able to deliver

1:41the message if malware is detected

1:42and check scanning results.

1:44However, this may not be the best option

1:46as this allows that email to make

1:47its way into a mailbox, whose owner may end up opening

1:50the particular attachment.

1:51We also have the ability to block that particular message

1:55and prevent that particular attachment from making

1:57its way into our environment.

1:58Now, the Dynamic Delivery option allows

2:00us to receive the text part of that particular message,

2:03but it retains the attachment until the scan has actually

2:06been done and proven that the attachment itself

2:09is not harmful.

2:10So this may become very handy, just

2:12to be able to give the information that

2:14is relevant to the recipient.

2:15And later on, if the attachment doesn't

2:17contain any malicious contents, then that attachment

2:20can also be sent to that recipient.

2:23Under Quarantine options, we can use the default options.

2:26But we also have the ability to add our quarantine policy

2:29that we customized.

2:30So over here, we can simply go ahead

2:31and select the Sales quarantine option, which

2:34would ensure that quarantine settings that we applied

2:36in this particular quarantine policy

2:38would apply to this policy over here,

2:40meaning that if a user happens to receive an email that

2:43has an attachment and that attachment has contents that

2:45are not proven to be safe, the user will be provided

2:48with an opportunity to look into the quarantine folder

2:50and be able to block the sender, or even

2:52be able to delete that particular message

2:54from the quarantine folder.

2:55And if we're making use of the Monitoring mode,

2:57we could also enable redirection,

2:59which allows us to send an attachment that

3:01is proven to be malicious within the environment

3:04to a particular email address.

3:05This could be the administrators, email address,

3:07or maybe somebody in the security department

3:09who would then be able to look into that

3:11and resolve such kind of issues.

3:13But with this configuration, you can go ahead

3:15and click Next over here.

3:16This is just providing us a preview of that safe attachment

3:19configuration.

3:20And then we can submit to enable that policy.

3:24And there's our policy.

3:25We can select it and carry out various activities that pertain

3:27to that particular policy.

3:29But before, we can just conclude that two important things that

3:31actually happen in this area.

3:33The very first one is the Global settings area.

3:35This is to ensure that we have the rightful features enabled,

3:39such as turning on Microsoft Defender for Office 365

3:42to protect information in our OneDrive,

3:44or SharePoint, Microsoft Teams, et cetera.

3:46So you need to make sure that that is toggled over there.

3:49The other part is the turning on of Safe Documents

3:51for Office clients.

3:52What this simply does is that if a user is opening a file,

3:55let us say an Outlook or whatever

3:56application that it is in Office,

3:58that file goes through some real-time scanning.

4:01And if the file itself is not malicious in any way,

4:04then it goes over and opens for the end user

4:06to be able to access it.

4:07But if it so happens that the file contains

4:09some malicious files or anything that

4:11actually makes it to be deemed as unsafe, that file not open.

4:14It will have to go through some additional analysis, et cetera.

4:17Now, this is currently available only in Microsoft 365 E5

4:20license as well as the Microsoft 365 E3 Security license.

4:25So that is something to think about

4:26as you are configuring these policies within the environment

4:29and showing that all the users that you intend

4:31to participate in this particular policy

4:33have the rightful licenses.

4:34Now, these ties strongly into Advanced Threat Protection

4:38within Microsoft 365 ecosystem.

4:40And if you pull up our partial over here

4:42and access our Exchange Online, let

4:46us try to see whether these would also

4:47mirror the changes that we currently

4:49have within our environment.

4:50We can see that we have these enabled over here.

4:53So if we're going to partial and type

4:55Get Advanced Threat Protection Policy, that

4:58is going to be for Office 365.

5:01And then press Enter over here.

5:03You'd actually be able to tell whether those policies are

5:05enabled.

5:06For example, if we look closely, we

5:08will notice that we have enabled Safe Documents over there.

5:11And you can see that that is currently enabled.

5:13That's true.

5:14Of which it's also true for this particular configuration

5:17over here.

5:17But then just slightly below there,

5:19we can see that there is an option

5:21to allow people to click through Protected View

5:24whenever they're accessing Safe Documents, which simply means

5:26there could be a file that is maybe malicious.

5:28But we give the users the ability

5:30to be able to go through those kind of files.

5:33We can also look that up and see whether it's also enabled over

5:35here.

5:36So if we just try to, let's say filter through that

5:39and look for the rightful format,

5:41that is going to be SafeDocs.

5:44Then we can close that and press Enter.

5:46You'd realize that that is currently not enabled.

5:49AllowSafeDocsOpen is false.

5:52But if you enable that feature over here and click on Save,

5:56we should actually be able to verify

5:58whether it has also been enabled within our PowerShell

6:01environment.

6:01So if we press N over there, you'd

6:03realize that those features are all enabled.

6:05And we can leverage these tools, both in PowerShell, as well

6:09as in Microsoft 365, to make sure

6:11that we have the rightful configurations for our users,

6:14and that we have the rightful protection levels that

6:16will prevent our users from falling prey

6:18to the various malicious attacks that may actually

6:21exist within our environment.

6:22And for best security practices, it

6:24is not advisable for us to have that option over here

6:28set to true.

6:28So we'll go ahead and set it back to Disabled

6:31and click on Save.

6:32And then we can just quickly go ahead and close that.

6:36The final thing to look at when working with safe attachments

6:38are the reports that Microsoft provides.

6:40Over here, we can gain visibility

6:42into the status of our threat protection

6:44and just be able to tell what exactly is trending,

6:47what things we should be paying more attention to, et cetera.

6:50Quite all right, there isn't much at this particular point,

6:52but this is the location, which would actually

6:55use to have a greater understanding

6:57into the various strains of our security posture.

7:00And by looking at the various filters provided over here,

7:03we can have visibility into detection technologies.

7:06We can look into policy types, delivery actions, et cetera.

7:09For example, over here under Detections,

7:11we can see the kind of detections

7:12that have been employed for this particular user over here.

7:15So it is the employment of these solutions, coupled with others

7:19that are provided by Microsoft, that

7:20actually makes our environment more and more secure.

7:23And this, my friend, is how we can

7:25work with the safe attachment policies within Microsoft 365.

7:29For now, I hope this has been informative for you,

7:31and I'd like to thank you for viewing.

Configuring Safe Links

0:00[AUDIO LOGO]

0:06So let us conclude by looking at how we can configure

0:08safe links within our tenant.

0:11Now, safe links are a Microsoft 365 Defender solution

0:14for combating different types of attacks

0:16that may come through various communication channels,

0:19such as your teams, as well your mailbox.

0:23So the whole idea is for us to be

0:24able to protect the various users that we have

0:27in our environment in such a way that when they receive a link,

0:30that particular link is simply scanned in real time

0:33using Microsoft solutions, and compared

0:35against a database of various links that have in the past

0:38been known to have been malicious.

0:40So here's how it works.

0:41When you receive an email containing a URL,

0:43safe links replaces the original URL

0:46with a Microsoft-generated URL.

0:48And this process is known as URL rewriting.

0:51This simply ensures that we would

0:53have a form of URL redirection, whereby

0:55when you click on that link, instead of us directly having

0:59access to it, it will be redirected to Microsoft servers

1:01for analysis and scanning prior to us

1:03being given access to the content of that particular URL.

1:06And once the URL is passed on to Microsoft servers

1:09and with the help of Microsoft 365 Defender,

1:13the URL would go through scanning an analysis,

1:16comparing it to a list of harmful URLs

1:18that are listed in the database.

1:19And other than that, Microsoft will also

1:21employ dynamic analysis.

1:23This simply allows that particular URL

1:26to launch and execute under a very controlled environment,

1:29and then observe its behavior and assess

1:31its potential threat.

1:32This dynamic analysis helps in detecting

1:35new and evolving threats that may have not

1:37been previously identified within the environment.

1:40It is only after the analysis that Microsoft would then

1:42be able to provide results based on the scanning.

1:46Now, if the link itself has been deemed

1:48to be safe and appropriate, safe links

1:50will proceed and give the user access to the website

1:53without any interruption.

1:54However, if the link is suspicious and malicious,

1:57activity has been identified with that particular URL,

2:00then safe links would block access and display a warning

2:03sign to the user, and thereby protecting

2:05the user from being exploited.

2:07Let's take a quick look at how we could configure

2:09safe links within our tenant.

2:10So here we are under Threat policies,

2:12still in Microsoft 365 Defender.

2:15If we scroll down all the way, we have safe links over here.

2:19And this simply allows us to begin the process of creating

2:22our own safe links policy.

2:23So if we click on Create, we can go ahead

2:25and say this is going to be safe links for Sales department.

2:28And then we can give a short description over there

2:30and click Next.

2:31And here, we can go ahead and add the various sales

2:33groups or the relevant parties that should actually

2:35participate in this particular policy.

2:37And with that in place, we then can go and click Next.

2:41Now, it is in this area that we can create our safe links

2:43policies for emails, for our Teams channel,

2:46Office 365 applications, and the various protection settings

2:49that you may simply want to see taking place

2:51in this particular tenant.

2:53So if you scroll upwards and go to Email,

2:55we have the turning-on button.

2:57This simply allows us to be able to implement

2:59safe links for the various URLs that we

3:01have in our environment.

3:02And here, we can apply safe links

3:04to email messages sent within our organization.

3:06Yes, it is important that we also enable this,

3:08as malicious attacks can potentially arise

3:10from within our organization.

3:12We can also apply real-time URL scanning.

3:15This might also just maybe take a bit of resources and time

3:18to actually execute.

3:19However, it's very important in making sure

3:21that each and every time there is

3:23a link that is pointing to a file,

3:24or a link that is pointing to an external site,

3:26that particular link is scanned in real time.

3:29Then we have Wait for URL scanning to complete,

3:31or Do not rewrite URLs if you're worried about speed

3:34and quick-access resources.

3:36This could be something that you have to decide upon.

3:38But for safety purposes, it is worth it

3:40to wait until a scan is completed before the message is

3:43delivered.

3:44And then you have the option Do not

3:45rewrite URLs do checks via Safe Links API only.

3:48Now, if your organization has some kind

3:50of functionalities our configurations that

3:53require you not to interact with the redirection of URLs

3:56to other servers, just Microsoft servers in this case,

3:59you may opt to use this option over here,

4:01whereby links are not redirected or rewritten.

4:04And you simply maintain the original of the link

4:07that you've received within your mailbox.

4:08And this could be very convenient

4:10if that regulatory feature is something

4:12that you may want to have within your environment.

4:14We can also apply safe links to our Team's communication,

4:17as well as the Office 365 applications.

4:19And we can track user links.

4:21If we want to have visibility into each and every time

4:25a user has accessed a URL, then it

4:27can do so by enabling this feature, which

4:29allows us to see each time a user clicks

4:31on the original URL.

4:32And click Next over here.

4:33This simply looks at notifications.

4:35And then we can do a quick review of our safe links

4:37configuration and click on Submit.

4:39So that, my friend, is how we can

4:41add an additional layer of security to our environment

4:43and protect our users against attacks, such as phishing

4:46attacks, malware infections, and other types of cyber threats.

4:50For now, I hope this has been informative for you,

4:52and I would like to thank you for viewing.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo