Designating an address for security notifications

Plan requirement

Subscription Any plan
Access Admin

Where security messages arrive. Set it to a shared mailbox somebody actually reads, not to a person.

Set it

  1. Open the security settings in Admin Center.
  2. Set the address for security notifications.
  3. Confirm a message actually arrives.
  4. Agree who reads that mailbox and how quickly.

Never an individual

People go on holiday, change roles and leave. A security notification arriving in a deactivated mailbox is the same as no notification, and you will not find out until it matters.

A monitored mailbox, not just a shared one

Shared is not the same as read. Decide who checks it, and how quickly they are expected to act, or the address is a place messages go to be filed.

What arrives here

Sign-in anomalies, changes to security settings, and notices that need somebody's attention. Not many messages, which is exactly why an unmonitored mailbox goes unnoticed for a year.

Test it

Trigger something that generates a notification and confirm it lands. An address with a typo behaves identically to a working one from the settings page.

Review it when your team changes

Reorganisations move mailboxes. This setting is small, invisible and exactly the sort of thing nobody thinks to check afterwards.

Say what to do with one

Who investigates, who can revoke access, and when to contact pluscloud support. An alert reaching somebody with no mandate to act achieves nothing.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.