Feedback by UserVoice

Andy Hoult

My feedback

  1. 104 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    Andy Hoult supported this idea  · 
  2. 3,645 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    199 comments  ·  Office 365 Security & Compliance  ·  Flag idea as inappropriate…  ·  Admin →

    Azure Active Directory Conditional Access has functionality for “Countries/Regions” – see https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/location-condition

    That said, the most effective protection you can have against password spray attacks is to enable MFA and disable basic authentication. If you cannot do this for your entire organization, then blocking user access to legacy protocols like POP, EWS, IMAP and SMTP is another step you can take. Exchange Online Client Access Rules can help you to further customize (https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/client-access-rules/client-access-rules). For additional recommendations, please see Office 365 Secure Score.

    That said, please know that we are listening to feedback and working on solutions to help make Office 365 users more secure. Thank you for the feedback.

    Andy Hoult supported this idea  · 
  3. 10,349 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1087 comments  ·  Office 365 Admin  ·  Flag idea as inappropriate…  ·  Admin →
    An error occurred while saving the comment
    Andy Hoult commented  · 

    This should be a simple few minutes of code that makes a world of difference.
    Admins have been crying out for this for years now.

    An error occurred while saving the comment
    Andy Hoult commented  · 

    This is probably the most painful thing for admins at the moment.
    Unfortunately many people still need multiple reminders in the form of emails, popups just get ignored.

    Andy Hoult supported this idea  · 

Feedback and Knowledge Base