BM Technologies

BM Technologies Tech That Works. Website designs and hosting, IT Support and Cloud Solutions. Business and home

If you use Excel and Microsoft 365 Copilot, an upgrade from March 2026 might save you hours every week. It's called Work...
20/06/2026

If you use Excel and Microsoft 365 Copilot, an upgrade from March 2026 might save you hours every week.

It's called Work IQ, and it changes how Copilot handles spreadsheets.

Before, you had to manually feed Copilot the data you wanted it to use. Copy figures from an email, paste them into Excel, then ask Copilot to clean it up.

Now, Copilot can pull context directly from your related emails, Teams chats, meetings, and files in your Microsoft tenant. It reads the source material itself.

You can do things like:

▶️ Reconcile a vendor invoice against the quoted price by pointing Copilot at the original email thread.

▶️ Update a sales forecast based on the recap of yesterday's pipeline meeting.

▶️ Reformat a messy data dump a client sent over.

To use it, you need a Microsoft 365 Copilot license and the document stored in your business tenant, not a personal OneDrive.

One note on security: Copilot can only access files the user already has permission to see.

If your SharePoint and OneDrive permissions are messy, Copilot will surface things you didn't intend to share.

Audit your file permissions before turning this loose on your team.

5 Star Google Review from another happy customer ⭐⭐⭐⭐⭐                🌟🌟🌟🌟🌟
19/06/2026

5 Star Google Review from another happy customer ⭐⭐⭐⭐⭐

🌟🌟🌟🌟🌟

Pay attention to this fake “Microsoft” scam.If an email asks you to enter a verification code on Microsoft's login page,...
17/06/2026

Pay attention to this fake “Microsoft” scam.

If an email asks you to enter a verification code on Microsoft's login page, don't enter the code.

That request is the giveaway for a phishing technique called device code phishing, which has hit over 340 organizations across the US, Canada, and Europe since February.

What makes this attack dangerous is that it bypasses Multi-Factor Authentication entirely, even strong MFA.

The attacker is tricking you into authorizing their device into your Microsoft 365 tenant.

You get an email about a shared SharePoint document, a payroll bonus PDF, or a meeting invitation from someone who looks legitimate.

The link sends you to login.microsoftonline.com, which is the real Microsoft login page.

The page asks you to type in a short verification code that was included in the email. You enter it and move on with your day.

But what you did was approve the attacker's device into your Microsoft 365 environment.

They now have a valid access token tied to your account.

They can read your email, download your files, and set up mailbox forwarding rules without ever needing your password again.

A turnkey phishing kit called EvilTokens started selling on Telegram in February 2026, which means even low-skill attackers can run these campaigns at scale.

To shut this attack down inside your business:

▶️ Block device code authentication flow in Entra ID for users who don't need it.

This protocol was designed for devices with limited input, which most office staff don't use. Open Conditional Access and create a policy that blocks device code flow by default.

▶️ Train your team. Microsoft will never email you a verification code to enter on its login page.

If a user gets an email instructing them to enter a code into login.microsoftonline.com, the email is phishing, no matter how legitimate the sender looks.

▶️ Use phishing-resistant MFA where possible, like FIDO2 hardware keys or Windows Hello for Business.

Authenticator app prompts are better than nothing, but they don't protect against this specific technique.

If you don't know how to do these things, let us know and we’ll help you out.

The one Outlook rule you need to set to save yourself from awkward conversations. It's called "delay delivery." You set ...
15/06/2026

The one Outlook rule you need to set to save yourself from awkward conversations.

It's called "delay delivery." You set it once in classic Outlook, and from that point on every email you send sits in your Outbox for a specific time (that you set) before it leaves.

If you spot a typo, realize you sent the wrong attachment, or wrote something in frustration you wish you hadn't, you have can a standard 2-minute delay to give you enough time to stop it.

Just delete the email from your Outbox before the timer runs out.

To set it up in classic Outlook:

1. Go to File > Manage Rules & Alerts

2. Click "New Rule" and pick "Apply rule on messages I send"

3. Skip past the conditions so it applies to every email

4. Check "defer delivery by a number of minutes" and set it to 2

5. Save the rule

This is better than Outlook's built-in "Recall" feature, because it works every single time.

If a website ever tells you to press Windows Key + R, close the tab.That single instruction is the giveaway for a fast-g...
11/06/2026

If a website ever tells you to press Windows Key + R, close the tab.

That single instruction is the giveaway for a fast-growing scam called ClickFix, which has been behind a wave of infostealer infections all year.

An infostealer is malware that scrapes every saved password, browser cookie, session token, and stored credit card...

You click a Google result that takes you to a hacked website.

A fake CAPTCHA pops up and tells you to press Windows Key + R, then Ctrl + V, then Enter to verify you're human.

The second you hit Enter, you've installed malware on your own machine.

This attack slips past most security tools because you run the command yourself.

No file was downloaded, so antivirus has nothing to scan.

The browser shows no warning.

From the operating system's perspective, you typed a command into a Windows utility, the same as any admin doing real work.

A few things you can do this week:

▶️ Tell your team that if any website prompts the user to press Win+R or paste something into the Run box, they should close the tab and report it.

▶️ Restrict PowerShell for non-IT staff using AppLocker or Windows Defender Application Control. Most office employees have no work reason to run PowerShell scripts.

▶️ Make sure your endpoint protection is doing behavioral monitoring and not just signature scanning. Microsoft Defender for Endpoint and most modern EDR tools have detection rules specifically for this attack chain.

There's no shame in falling for a fake CAPTCHA. They're designed to look real. But once your team knows the keystroke trick, this scam stops working on them.

15/05/2026

📢 New 12-Week Taster Classes Starting Next Week!

KYP in conjunction with Hopwood Hall College is offering FREE taster classes in Digital Skills 🙌💻

📅 Monday - 9:30am

✔ Typing skills
✔ Microsoft Office basics
✔ CV writing & Indeed accounts
✔ Online job applications
📍Perfect for building confidence, skills & employability.

📩 Get in touch to book your place!
01706 630140 or email [email protected]

Address

109 Dale Street
Manchester
OL163NW

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Telephone

+441616727461

Alerts

Be the first to know and let us send you an email when BM Technologies posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to BM Technologies:

Share