This message:
Is new to Microsoft 365 and is called the "First Contact Safety Tip." It was enabled in the default phishing rules by default in 2023.
It can be very useful to defeat phishing scams, since the impersonated email account will show up as a first contact. It's recommended that we leave this on for everyone. However, if someone really wants it gone:
- Go to https://security.microsoft.com
- Go to "Email & collaboration" -> "Policies & rules" -> "Threat Policies" -> "Anti-phishing"
- Click on "Create" and then make a new policy. These settings will likely change, so not much point in documenting them here. However, try to match up to the AntiPhish default as best you can. There really isn't a great way to do this that I've found yet. No copy/paste, export/import, etc.
- This policy can be attached to specific users, which is what you want to do:
That's it!
