Managed servicesEmail & phishing

Keep phishing from becoming a tenant takeover — mail and login defended together

Mailbox protection plus identity checks on every sign-in — so a convincing fake invoice or QR lure is less likely to become stolen credentials and firm-wide access

Most breaches still start with an email or text that looks routine — a vendor update, a wire request, a QR code on a PDF. Spam filters catch a lot, but BEC, credential harvesting, and quishing often slip through because they look like normal work. Manage IT NY combines mailbox inspection with identity policies that block sign-ins even when a password was typed into a fake login page — alongside backups and endpoint controls, not instead of them.

Technology partners

  • ThreatLocker logo
  • SentinelOne logo
  • Fortinet logo
  • NinjaOne logo
  • Barracuda logo
  • Microsoft 365 logo
  • Google Workspace logo

Why spam filters alone are not enough — and how phishing, BEC, and quishing differ

A spam filter (often built into Microsoft 365 or Google Workspace) blocks known bad senders and obvious junk. A secure email gateway (SEG) sits in the mail path and adds link rewriting and attachment scanning — but many firms still rely on the cloud filter alone. Neither stops a text-only executive impersonation (business email compromise, or BEC) or a QR code hidden inside an image (quishing) the same way API-level mailbox protection can. Multi-factor authentication (MFA) and Conditional Access answer a different question: "Should this login succeed on this device from this location?" — even when the password is correct. Security awareness training helps staff spot lures; it does not replace technical controls when someone is rushed or distracted.

Microsoft 365 and Google Workspace keep your tenant online — that is shared responsibility, not the same as you owning recoverable mail backups or immutable copies of critical data. Manage IT NY designs mailbox defense, identity policies, and backup posture as complementary layers partners can explain without vendor jargon.

Four phishing shapes leaders should recognize

Select a threat type to see what it looks like in plain language, what traditional filters often miss, and how mailbox plus identity controls change the outcome — without assuming you already speak SEG or API jargon.

Credential harvesting

A fake login page — often mimicking Microsoft 365, QuickBooks, or a bank — tricks someone into typing a password. The attacker captures credentials immediately. Gateway filters may miss it if the link was clean at delivery and turned malicious later, or if the lure arrived via text or personal email outside the corporate filter.

Assess mailbox posture

1 / 4

What mailbox and identity protection cover

Four layers that work together — not four disconnected product toggles

Manage IT NY maps email security from lure types to sign-in outcomes — so partners and ops leaders know which control stops which failure mode.

  • API-native mailbox inspection

    Stops this failure mode: malicious mail delivered because the gateway only saw a clean link at send time

    Connects into Microsoft 365 or Google Workspace via APIs to analyze headers, attachments, and URLs without MX record changes — quarantining anomalies before staff treat them as routine.

  • Time-of-click URL sandboxing

    Stops this failure mode: delayed-payload links that look safe when scanned but turn malicious later

    Links are rewritten and re-checked when someone clicks — blocking pages that were benign at delivery but weaponized hours afterward.

  • Conditional Access on sign-in

    Stops this failure mode: stolen password used from an attacker's device or country

    Every login is evaluated for device health, location, and risk — deny or step up when context does not match how your staff actually work.

  • Phishing-resistant MFA

    Stops this failure mode: MFA fatigue or push prompts accepted on a lookalike site

    FIDO2 passkeys and number-matched prompts bind authentication to the real tenant — so harvested passwords and replayed sessions fail at the door.

Credential harvesting

Fake login pages

Attackers copy your cloud sign-in screen. Staff enter real passwords; attackers use them immediately. Conditional Access and phishing-resistant MFA limit what a stolen password alone can do.

BEC

Business Email Compromise

Impersonation aimed at wire transfers and payment changes — often no malware attached. Combines mailbox baselining, finance verification habits, and locked-down identity for accounts that can move money.

Quishing

QR code phishing

Malicious URLs hidden in images or PDFs. Phone cameras bypass corporate link protection unless OCR and sandboxing extract and test the destination.

MFA + Conditional Access

Blocking stolen passwords

MFA adds a second factor. Conditional Access adds context — managed device, approved location, compliant patch level. Together they fail closed when a phished password arrives from the wrong machine.

What good looks like

A short buyer checklist before you trust the program — not a vendor feature list, a readiness scan.

  • MFA on mail and admin?

    Every mailbox and admin portal requires MFA — preferably phishing-resistant methods, not SMS alone.

  • Conditional Access enforced?

    Unmanaged devices and risky sign-in locations are blocked or stepped up — not silently allowed because the password matched.

  • Dangerous mailbox rules watched?

    Auto-forward and inbox rules that exfiltrate mail are monitored and restricted — a common post-compromise move.

  • Quishing and OCR covered?

    URLs embedded in images or QR codes are extracted and sandboxed — not only plain-text links in the body.

  • Travel and remote policies documented?

    Executives on the road use managed devices and approved paths — with written rules finance and IT can follow.

  • Mail backed up separately?

    Microsoft 365 or Google uptime is not the same as you owning recoverable mail — shared responsibility still applies.

Defense in depth: mailbox content plus identity on every sign-in

Two pillars answer different questions. The content layer asks: 'Should this message or link reach the inbox?' The identity layer asks: 'Should this login succeed on this device?' Most firms need both — a filtered inbox reduces lures; identity policy limits damage when someone still clicks.

Content layer — inspect mail without MX latency

API-native protection connects directly into Microsoft 365 or Google Workspace via Graph or Admin APIs — analyzing inbound mail without rerouting MX records or adding gateway delay.

How a credential-harvesting attempt is usually interrupted

A teaching sequence from lure to blocked sign-in — what mailbox inspection and Conditional Access do when both layers are already in place. Times are an example; real clocks vary by tenant size, policy strictness, and whether the user clicked from a managed device.

  1. A message mimics a legitimate vendor — urgent QuickBooks or payment-portal language, link to a credential page. BEC-style urgency is designed to bypass calm verification habits.

How email and identity controls map to your industry

Privileged matter files, taxpayer PII, and CUI each raise different questions about mailbox risk and sign-in policy. Here is how Manage IT NY explains the controls each vertical actually needs — in language partners and ops leaders can follow.

Law firms & client confidentiality

ABA competence expectations include understanding technology risks — including how quickly a phished partner credential could reach matter files and client portals. Mailbox baselining plus Conditional Access supports the reasonable-efforts story partners explain to clients, without promising that spam filters catch everything.

Law firm cybersecurity

Frequently asked questions

Straight answers on stolen credentials, spam filters vs layered protection, quishing, SaaS backup responsibility, rollout timing, and travel access.

Stolen passwords are common — the goal is to make them useless alone. Manage IT NY enforces Conditional Access with phishing-resistant MFA and device compliance checks. The attacker's machine typically lacks a managed device certificate and fails location and health rules — so the sign-in is denied and sessions are revoked while the account is reset. Speed matters; so does having the policies already enabled before the click.