Back to all guides
Ransomware Protection Setup
Enable and configure ransomware detection and prevention.
Overview
Ransomware Protection monitors your environment for signs of ransomware activity, suspicious file changes, and mass encryption events. Early detection is critical.
Prerequisites
- Microsoft 365 or Google Workspace integration (for file monitoring)
- Endpoint protection integration (if available)
Step 1: Enable Ransomware Monitoring
- Navigate to Security Apps → Ransomware Protection
- Click "Enable Protection"
- Select monitoring scope (all users or specific groups)
- Configure detection sensitivity
Step 2: Configure Detection Rules
- Set thresholds for mass file modifications
- Configure alerts for known ransomware extensions
- Enable detection of encryption patterns
- Set up anomaly detection for unusual activity
Step 3: Set Up Alerts
- Configure immediate alerts for suspected ransomware
- Set up escalation paths for critical alerts
- Enable SMS/phone alerts for after-hours incidents
- Configure automatic account suspension (optional)
Step 4: Create Response Playbook
Prepare your incident response:
- Document isolation procedures
- Identify backup and recovery processes
- List key contacts and escalation paths
- Configure automatic response actions
Detection Capabilities
- Mass file encryption detection
- Known ransomware file extension monitoring
- Unusual file access patterns
- Shadow copy deletion attempts
- Suspicious process execution
Best Practices
- Maintain offline backups
- Test backup restoration regularly
- Train users on phishing awareness
- Keep systems patched and updated
- Implement network segmentation