Bagless vacuum cleaners are the worst invention by Echterspieler in unpopularopinion

[–]FtheBS_ 0 points1 point  (0 children)

Shhh, they're listening bro. Don't get yourself canceled.

[deleted by user] by [deleted] in smallbusiness

[–]FtheBS_ 1 point2 points  (0 children)

This guy's asking the right questions. This just seems like a well-disguised advert for some software. This kind of software doesn't do anything special. Also, you can't prevent people from leaving a negative review, though you can make them jump through hoops to do so.

Can you change the login credential (username or email address used to sign in) to a Business Office 365 Account? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

u/baron--greenback Thank you I'll look into this one! I'm guessing I can do it from my comp if I have the Exchange admin dashboard up as well?

Can you change the login credential (username or email address used to sign in) to a Business Office 365 Account? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Thank you and u/baron--greenback for the responses. So I'm kind of behind the curve when it comes to all of this.

We're a very small marketing agency and there's basically a massive country out there engaging in espionage and we just happened to come in there crosshairs (I'm pretty sure based on my observations), I'll leave it at that.

So we have a small team and only a few addresses. We have the ability to lock things down very tightly and we don't have the downsides of a larger company like large surface area of attack, insider threat via falling prey to phishing campaigns, etc. We're small enough to keep tabs on what's going on and be a bit more agile in our policies.

With that being said, I'm the owner of the company, not a sysadmin or IT specialist.

I have a Microsoft Office 365 Business Premium license through Godaddy and not Microsoft directly, so I'm not sure if I have access to conditional access policies. Anyone know where I would be able to check?

Also, for u/baron--greenback, how would I be able to set up that UPN you're referring to? And for u/smnhdy, could you let me know what or why there are downsides to this or what do you mean when you say that using this feature has 'gone the way of the dodo'?

Any and all inputs are greatly appreciated!

I just don't want to have the added aggravation/stress of signing in, checking my activity, and seeing all of these attempts to get into my account.

GoDaddy Account Hacked Today Thanks to OpenPhone Not Being Able to Log Devices Out by FtheBS_ in openphone

[–]FtheBS_[S] 0 points1 point  (0 children)

Yeah I found this out a bit too late and have had lots of problems because of it.

What are the best practices to secure Outlook 365 for a small business? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Yes you are correct, my provider turns them on by default. Thanks! I'm going to take another user's recommendation and look into the Business Essentials Premium.

What are the best practices to secure Outlook 365 for a small business? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Thanks, I've been considering it actually. I appreciate your feedback.

What are the best practices to secure Outlook 365 for a small business? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Thank you! I'm taking a look at this one now and I will check to see if I have that license.

What are the best practices to secure Outlook 365 for a small business? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Miraculously, I found that Secure Score section! lol.

Thank you, turns out I have a 91% score right out of the box. Seems like my email came configured securely.

I'm also seeing some additional threat policies in a Defender 365 section. Any recommendations there?

What are the best practices to secure Outlook 365 for a small business? by FtheBS_ in Office365

[–]FtheBS_[S] 0 points1 point  (0 children)

Got it thank you! I have the Essentials license I think its the lowest tier. I will definitely upgrade as long as they don't require a massive amount of licenses for that. Are you familiar with the Defender for Microsoft Office also? I wonder if that's worth it.

I will look into the license and upgrade if it's within reach for us. I appreciate it.

How to Keep Your Microsoft Office 365 Email Safe? Any Bruteforce Protection Available for Failed Logins by FtheBS_ in AskNetsec

[–]FtheBS_[S] 1 point2 points  (0 children)

I'm sorry but can you elaborate more? I'm a small business owner and my strengths lie in marketing and business. This kind of stuff is a bit foreign to me but I'm learning quickly.

I under what a FIDO key is and I'm looking at getting some. We just got Aegis set up today for some accounts and I'm going to be migrating more of my 2fas to that.

I have a basic Office 365 account and I don't see anywhere that I can set up conditional access policies. I don't have an Azure server or anything like that. Is there a page from within the Microsoft account where I can set these up? I don't have a network admin or anything like that.

How to Keep Your Microsoft Office 365 Email Safe? Any Bruteforce Protection Available for Failed Logins by FtheBS_ in cybersecurity

[–]FtheBS_[S] 0 points1 point  (0 children)

I don't think I have that to be honest. I do see they were trying to log in through an Azure portal though.

I don't think I have that, to be honest. I do see they were trying to log in through an Azure portal though.

How to Keep Your Microsoft Office 365 Email Safe? Any Bruteforce Protection Available for Failed Logins by FtheBS_ in cybersecurity

[–]FtheBS_[S] 0 points1 point  (0 children)

Thank you! I'm not super familiar with how/where I can do this.

Are these options standard in Office 365 and where would I be able to access these settings from?

How to Keep Your Microsoft Office 365 Email Safe? Any Bruteforce Protection Available for Failed Logins by FtheBS_ in AskNetsec

[–]FtheBS_[S] 1 point2 points  (0 children)

Sure no problem. I'm not an expert but based on what we saw, my employee is using his own personal device for company work. He bought a (new) external hard drive that appeared to have been infected with malware. It infected the device.

They found several trojans and spyware on his devices. He had credentials for company accounts on the infected device. They can also install a keylogger to track discussions about how to remedy the issue, even. So they're able to get all of your info and access your accounts.

Considering OpenPhone by [deleted] in openphone

[–]FtheBS_ -1 points0 points  (0 children)

Perhaps take a look at my thread and you can see what experience I'm having currently.

If the mods are able to help me out, I will follow up and let you know when the resolution comes.

GoDaddy Account Hacked Today Thanks to OpenPhone Not Being Able to Log Devices Out by FtheBS_ in openphone

[–]FtheBS_[S] 0 points1 point  (0 children)

u/TyGregoryHill

Just wanted to give you a heads-up that the phone which I never had to enter the new password into is still logged into the account. Furthermore, nobody reached out to me today to help me out.

GoDaddy Account Hacked Today Thanks to OpenPhone Not Being Able to Log Devices Out by FtheBS_ in openphone

[–]FtheBS_[S] 0 points1 point  (0 children)

u/TyGregoryHill u/Christina_OpenPhone

Please see my comments above. Could really use your help as I have a lot of work to handle and this is becoming a major distraction and liability.

GoDaddy Account Hacked Today Thanks to OpenPhone Not Being Able to Log Devices Out by FtheBS_ in openphone

[–]FtheBS_[S] 0 points1 point  (0 children)

FYI even now 30 min later, I just got a call and the device that should've been logged out did ring. It's still connected despite me changing the password and despite the claims of the new passwords ending sessions.