What's Changing
The security tools behind the scenes are moving from the Notes/Domino environment to Microsoft's enterprise security platform.
Phishing detection challenge
it-support@yourcompany-secure.net
Your account will be locked in 24 hours — verify now
Reveal answer
PhishingPhishing. Look-alike domain (not @yourcompany.com), urgent countdown language, and a request that pressures you into clicking without thinking.
payroll@yourcompany.com
Your December pay stub is ready
Reveal answer
LegitimateLegitimate. Correct company domain, routine subject line, no links demanding credentials.
support@micros0ft-help.com
Action required: confirm your password
Reveal answer
PhishingPhishing. Misspelled domain (a zero instead of an ‘o’) and a direct request for your password — IT will never ask for this by email.
it.service.desk@yourcompany.com
Reminder: MFA setup session this Thursday
Reveal answer
LegitimateLegitimate. Correct internal domain, no urgency tactics, no attachment or link asking for credentials.
What Stays the Same
For you, the day-to-day doesn't change much, but there are a few things you should know to keep your account (and the organization's data) safe.
- The rules — don't click suspicious links, don't share your password, report anything weird.
- Common sense applies — if an email looks off, it probably is.
- IT has your back — the security team monitors for threats so you don't have to.
Spotting Phishing Emails
Phishing emails are fake emails that try to trick you into giving up your password or clicking a dangerous link. Watch for:
- Urgent language like “Your account will be locked in 24 hours!”
- Unexpected attachments from unknown senders.
- Misspelled email addresses (for example, support@micros0ft-help.com instead of a real Microsoft or @yourcompany.com address).
- Password requests — Microsoft (and the IT Service Desk) will never ask for your password by email.
- Mismatched links — hover before clicking to see where a link actually goes.
If You Get a Suspicious Email
Response
- Don't click links or open attachments.
- Don't reply.
- Use Outlook's Report button.
- Delete the email.
If You Already Clicked Something
- Change your password immediately at portal.office.com.
- Contact the IT Service Desk.
- Allow them to verify your account security.
Using Outlook's Report Function
- Select the suspicious email.
- Go to Home > Report.
- Choose Phishing or Junk — this forwards details to the security team.
Password Best Practices
Instead of a complex-but-hard-to-remember password like “Tr4ff!c#9,” consider a longer passphrase such as “SunnyOffice2026!” or “CoffeeBreak#Monday.” Use a different passphrase for work and personal accounts, never share it, and use Microsoft Authenticator or your browser's built-in password manager instead of writing passwords down.
Working Securely
On Shared Computers
- Always sign out when finished
- Don't save passwords in browsers
- Lock your screen with Windows + L when stepping away
On Personal Devices
- Keep a device lock (PIN/biometric)
- Keep apps updated
- Avoid unknown Wi-Fi networks without IT approval
Handling sensitive information: avoid emailing personal or financial details, avoid storing work data on personal devices, and never plug in an unknown USB drive.
Tips for Your Organization Staff
- MFA is your best friend — it protects your account even if your password is stolen.
- When in doubt, don't click — it's always safer to check with IT first.
- The IT Service Desk is there to help, not judge — if you click something suspicious, reporting it quickly is the best response.
- Updates are important — when your computer asks to update, do it. Those updates include security fixes.
Need Help?
- Check the Quick Start guide on this site
- Ask a colleague who has already been migrated
- Contact the Your Organization IT Service Desk