Microsoft enhances Windows 11 Phishing Protection with new features

Teilen:

Microsoft is further enhancing the Windows 11 Enhanced Phishing Protection by testing a new feature that warns users when they copy and paste their Windows password into websites and documents.

With the release of Windows 11 22H2, Microsoft introduced a new security feature called Enhanced Phishing protection, designed to protect your Windows and Active Directory domain credentials from being obtained by threat actors.

One of the most common methods threat actors use to gain access to websites or a corporate network is to purchase or steal corporate credentials. These credentials are obtained initially through phishing attacks or via information-stealing malware.

Threat actors use these stolen credentials to access other accounts used by the Windows user, including email accounts, bank accounts, and cryptocurrency trading accounts. Even worse, these stolen accounts can be used to access corporate networks, allowing the hackers to spread laterally on a network to conduct BEC scams, data theft, supply chain attacks, and ransomware attacks.

The number of stolen credentials is a massive and widespread problem, with cybercrime marketplaces selling billions of credentials and authentication cookies and more specialized sites selling over a million remote desktop credentials.

Stolen RDP credentials sold on dark web marketplace
Stolen RDP credentials sold on dark web marketplace

Due to this widespread abuse, law enforcement has been actively targeting stolen credential marketplaces in law enforcement operations, seizing the WT1SHOP in 2022, and, more recently, taking down the Genesis Market.

Windows 11’s Enhanced Phishing Protection

When Microsoft first released the new Windows Enhanced Phishing protection, it only warned users when they manually typed their Windows password into a document or web login page.

However, as it’s commonly advised that users use password managers to create strong and unique passwords for all their logins, many people copy and paste their passwords from the password manager into their login prompts.

As the feature did not previously protect against copy and paste, this would bypass the Windows security feature.

With the release of Windows 11 Insider Dev build 23506, Microsoft has enhanced the phishing protection feature by now detecting the copy and paste of a user’s Windows password.

“We are trying out a change starting with this build where users who have enabled warning options for Windows Security under App & browser control > Reputation-based protection > Phishing protection will see a UI warning on unsafe password copy and paste, just as they currently see when they type in their password,” reads the Dev build release notes.

As this feature is not enabled by default, Windows users should turn it on by going to Windows Security > App & browser control > Reputation-based protection > Phishing protection and putting checkmarks under all three options, as shown below.

Phishing protection enabled in Windows 11
Phishing protection enabled in Windows 11
Quelle: BleepingComputer

Once enabled, this feature will warn users when they type or copy and paste their Windows logon password into website forms or documents.

This alert will be titled “Password reuse is a security risk,” and warns users to reset their Windows account password, linking to this support document.

“If your password is stolen from this site, attackers will true to use it other sites too. Use strong, unique passwords to keep your personal information safe,” reads the Windows phishing protection alert.

“Microsoft recommends changing your local Windows account password.”

Windows 11 phishing protection warning
Windows 11 phishing protection warning
Quelle: BleepingComputer

While our previous Windows Enhanced Phishing Protection test showed that it did not work with certain applications, such as Firefox and Excel, today’s tests show that this has been fixed, making the feature more robust.

However, it still does not work with other third-party applications that could commonly be used to store passwords, such as Notepad2, Notepad++, and likely many others.

Microsoft has also introduced a new “Warn others about suspicious apps and sites” phishing protection setting, but there is no information about this new setting and who ‘others’ represents.

Microsoft has not answered our questions related to this new setting.

Finally, it must be noted that the Windows 11 Phishing protection feature does not work if you use Windows Hello, such as PIN or biometrics, to log in to Windows.

For this feature to work, Windows users must log in with a password so it is cached in memory and can be compared to inputted text (typed or copied and pasted).

As this feature can be a powerful tool to protect corporate credentials, instantly alerting admins when a user is reusing their Windows password, trading the convenience of Windows Hello for better security is worth it.

It is recommended that all Windows users enable this security feature in Windows Security, even if it does not support all applications now.

 

(c) Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:51 am, Juni 1, 2025
Wetter-Symbol 15°C
L: 13° | H: 15°
overcast clouds
Luftfeuchtigkeit: 80 %
Druck: 1014 mb
Wind: 9 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
13° | 15°°C 0.2 mm 20% 15 mph 72 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 12 mph 81 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 17 mph 89 % 1013 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
9° | 17°°C 0.61 mm 61% 13 mph 79 % 1011 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
11° | 17°°C 1 mm 100% 15 mph 96 % 1010 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
15° | 16°°C 0 mm 0% 11 mph 72 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 13 mph 51 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 15 mph 39 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 11 mph 55 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 81 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 78 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 8 mph 71 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,975.90
0.50%
Ethereum(ETH)
€2,217.58
-0.28%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.91
1.33%
Solana(SOL)
€136.71
-0.01%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.167734
0.16%
Shiba Inu(SHIB)
€0.000011
2.28%
Pepe(PEPE)
€0.000011
2.49%
Peanut das Eichhörnchen(PNUT)
€0.229814
3.10%
Nach oben scrollen