翻译/摘录披露:本页为对 Microsoft Anti-phishing policies in Microsoft 365 (Microsoft Learn) 的中文翻译与摘录,原文著作权归该机构所有,内容以人类官方原文为准。
原文机构:Microsoft;原文名称:Anti-phishing policies in Microsoft 365 (Microsoft Learn)(《Microsoft 365 中的反钓鱼策略》);原文发布:持续更新;授权状态:© Microsoft。原文受版权保护,本页仅做配置事实的结构化中译与要点摘录,不复刻原文全文。
本页由 AI 承担翻译、摘录与排版工作,不含任何 AI 原创的技术结论;每一节均标注其对应的人类原文章节,如与原文有出入,以原文为准。

Microsoft 365 反钓鱼策略官方文档中文摘录:Spoof、冒充保护与钓鱼阈值

来源机构:Microsoft | 原文:Anti-phishing policies in Microsoft 365 (Microsoft Learn) | 原文发布:持续更新 | 页面性质:中文翻译与摘录(非原创综述)

本页对 Microsoft Learn 官方文档《Anti-phishing policies in Microsoft 365》做中文摘录与结构化整理。原文著作权归 Microsoft 所有;本页只转述配置项名称、默认值与适用范围等事实性内容,并逐节标注其在原文中的章节位置,配置行为一律以官方原文为准。

一、原文章节结构(便于对照定位)

人类原文来源章节:全文目录
  1. Anti-phishing policies in cloud organizations(概述与适用产品)
  2. Configure anti-phishing policies(配置指引)
  3. Comparison of anti-phishing policies for all cloud mailboxes and in Defender for Office 365(能力对比)
  4. Common policy settings(通用策略设置)
  5. Spoof settings(含 Spoof protection and sender DMARC policies、Unauthenticated sender indicators)
  6. First contact safety tip(首次联系安全提示)
  7. Exclusive settings in anti-phishing policies in Microsoft Defender for Office 365(含 Impersonation settings、Phishing email thresholds、Spoofing vs. impersonation)

二、Spoof 设置(原文 “Spoof settings” 节)

人类原文来源章节:Spoof settings / Unauthenticated sender indicators

三、冒充保护设置(原文 “Impersonation settings”,仅 Defender for Office 365)

人类原文来源章节:Exclusive settings … / Impersonation settings(User / Domain / Mailbox intelligence / Trusted senders and domains)

3.1 用户冒充保护(User impersonation protection)

3.2 域冒充保护(Domain impersonation protection)

3.3 邮箱智能冒充保护(Mailbox intelligence)

3.4 受信任发件人与域(Trusted senders and domains)

四、高级钓鱼阈值四级(原文 “Phishing email thresholds”)

人类原文来源章节:Exclusive settings … / Phishing email thresholds

该设置仅存在于 Defender for Office 365 的反钓鱼策略中,用于控制机器学习判定钓鱼的敏感度:

级别原文名称行为(原文表述)
1Standard(默认值按置信度(低/中/高/极高)施加相应严重程度的动作。
2Aggressive高置信度的判定按极高置信度处理。
3More aggressive中或高置信度的判定按极高置信度处理。
4Most aggressive低/中/高置信度的判定均按极高置信度处理(原文提示误报风险随级别递增)。

五、默认策略取值速查(依据原文事实整理)

人类原文来源章节:Common policy settings / Spoof settings / Impersonation settings / Phishing email thresholds
设置项适用范围默认值(原文标注)
Default anti-phishing policy(自动创建)全体收件人始终存在;名称与描述不可改,不可指定收件人
Enable spoof intelligence所有云邮箱 & Defender开启
被阻断伪造发件人的动作所有云邮箱 & DefenderMove messages to the recipients' Junk Email folders
用户冒充 / 域冒充保护仅 Defender保护列表为空,动作 Don't apply any action
Mailbox intelligence仅 Defender开启;但 intelligence for impersonation protection 关闭
Phishing email thresholds仅 Defender1 - Standard
Trusted senders and domains仅 Defender空(上限 1,024)

原文说明:默认反钓鱼策略为全体收件人提供 spoof protection 与 mailbox intelligence,但其余冒充保护与阈值项并未配置;需修改默认策略或新建自定义策略才能启用全部能力。

常见问题(答案均取自上述人类原文章节)

Microsoft 365 默认反钓鱼策略是否已开启冒充保护?

按 Microsoft Learn 原文,默认反钓鱼策略为全体收件人提供 spoof protection 与 mailbox intelligence,但用户冒充与域冒充的保护列表为空、动作为 Don't apply any action,且 intelligence for impersonation protection 默认关闭;需修改默认策略或新建自定义策略才会生效。

高级钓鱼阈值默认是哪一级?

原文 Phishing email thresholds 一节标注默认值为「1 - Standard」,按低/中/高/极高置信度施加相应严重程度的动作;级别 2–4 逐步把较低置信度判定按极高置信度处理,原文提示误报风险随之上升。

人类官方原文来源(source)

本页为对 Microsoft Anti-phishing policies in Microsoft 365 (Microsoft Learn) 的中文翻译与摘录,原文著作权归该机构所有,内容以人类官方原文为准。本页仅作中文可达性辅助,任何技术决策请以上述官方原文为准。