PORTFOLIO DEMO — a genericized recreation of a Microsoft 365 migration training hub iT9 delivered for a client. Client-identifying details replaced with placeholders. · See more from iT9 →
Coming from Notes security basics Security & Account 4 min

Staying Secure

Spot phishing emails, protect your account, and keep company data safe.

What's Changing

The security tools behind the scenes are moving from the Notes/Domino environment to Microsoft's enterprise security platform.

Phishing detection challenge

it-support@yourcompany-secure.net
Your account will be locked in 24 hours — verify now
Reveal answer
Phishing
Phishing. Look-alike domain (not @yourcompany.com), urgent countdown language, and a request that pressures you into clicking without thinking.
payroll@yourcompany.com
Your December pay stub is ready
Reveal answer
Legitimate
Legitimate. Correct company domain, routine subject line, no links demanding credentials.
support@micros0ft-help.com
Action required: confirm your password
Reveal answer
Phishing
Phishing. Misspelled domain (a zero instead of an ‘o’) and a direct request for your password — IT will never ask for this by email.
it.service.desk@yourcompany.com
Reminder: MFA setup session this Thursday
Reveal answer
Legitimate
Legitimate. Correct internal domain, no urgency tactics, no attachment or link asking for credentials.

What Stays the Same

For you, the day-to-day doesn't change much, but there are a few things you should know to keep your account (and the organization's data) safe.

  • The rules — don't click suspicious links, don't share your password, report anything weird.
  • Common sense applies — if an email looks off, it probably is.
  • IT has your back — the security team monitors for threats so you don't have to.

Spotting Phishing Emails

Phishing emails are fake emails that try to trick you into giving up your password or clicking a dangerous link. Watch for:

  • Urgent language like “Your account will be locked in 24 hours!”
  • Unexpected attachments from unknown senders.
  • Misspelled email addresses (for example, support@micros0ft-help.com instead of a real Microsoft or @yourcompany.com address).
  • Password requests — Microsoft (and the IT Service Desk) will never ask for your password by email.
  • Mismatched links — hover before clicking to see where a link actually goes.

If You Get a Suspicious Email

Response

  1. Don't click links or open attachments.
  2. Don't reply.
  3. Use Outlook's Report button.
  4. Delete the email.

If You Already Clicked Something

  1. Change your password immediately at portal.office.com.
  2. Contact the IT Service Desk.
  3. Allow them to verify your account security.

Using Outlook's Report Function

  1. Select the suspicious email.
  2. Go to Home > Report.
  3. Choose Phishing or Junk — this forwards details to the security team.

Password Best Practices

Instead of a complex-but-hard-to-remember password like “Tr4ff!c#9,” consider a longer passphrase such as “SunnyOffice2026!” or “CoffeeBreak#Monday.” Use a different passphrase for work and personal accounts, never share it, and use Microsoft Authenticator or your browser's built-in password manager instead of writing passwords down.

Working Securely

On Shared Computers

  • Always sign out when finished
  • Don't save passwords in browsers
  • Lock your screen with Windows + L when stepping away

On Personal Devices

  • Keep a device lock (PIN/biometric)
  • Keep apps updated
  • Avoid unknown Wi-Fi networks without IT approval
Handling sensitive information: avoid emailing personal or financial details, avoid storing work data on personal devices, and never plug in an unknown USB drive.

Tips for Your Organization Staff

  • MFA is your best friend — it protects your account even if your password is stolen.
  • When in doubt, don't click — it's always safer to check with IT first.
  • The IT Service Desk is there to help, not judge — if you click something suspicious, reporting it quickly is the best response.
  • Updates are important — when your computer asks to update, do it. Those updates include security fixes.

Need Help?

  1. Check the Quick Start guide on this site
  2. Ask a colleague who has already been migrated
  3. Contact the Your Organization IT Service Desk
Ask the M365 Assistant