Skip to content
4 min fix 7 min read Recently reviewedBeginner
Quick Answer

Connect to your company VPN before doing any work on public Wi-Fi. If VPN is unavailable, avoid signing into work accounts or entering passwords. Use your phone's mobile hotspot as a safer alternative.

How to Stay Safe on Public Wi-Fi and Untrusted Networks

Applies to: Windows 11, Windows 10, Microsoft 365
Article Type: Informational
Last Updated: 2026-06-17

Summary

Public Wi-Fi at airports, hotels, and coffee shops is convenient but risky. This article explains the threats, what you can do to protect yourself without admin rights, and which habits keep your work data safe on any untrusted network.

Prerequisites

  • A Windows laptop with Microsoft 365 apps installed.
  • If your organization provides VPN access, have the VPN client installed. This article also covers what to do if you do not have a VPN.

Instructions

1. Understand the Risks

Before connecting, know what you are dealing with.

Public Wi-Fi networks — in hotels, airports, coffee shops, and conference centers — are shared with strangers. This creates several risks:

  • Fake hotspots (evil twins). An attacker creates a network with a name like "Hilton_Free_WiFi" or "Starbucks_Guest." You connect thinking it is legitimate, and the attacker can see your traffic.
  • Eavesdropping. On an unencrypted or poorly secured network, other users on the same network can intercept data you send and receive.
  • Man-in-the-middle attacks. An attacker positions themselves between your device and the internet, reading or altering data in transit — including login credentials.
  • Captive portal phishing. The "sign in to use Wi-Fi" page itself could be fake, designed to capture your email address and password.

The good news: encrypted connections (HTTPS, VPN) protect you from most of these. The steps below show you how to stay protected.

2. Connect Safely to Public Wi-Fi

Take these precautions before you open any work app.

  1. Verify the network name. Ask a staff member for the exact Wi-Fi name and password. Do not assume the strongest signal is the real network.
  2. Set the network to Public. When Windows asks "Do you want to allow your PC to be discoverable on this network?", click No. This sets the network profile to Public, which:
    • Turns off network discovery.
    • Blocks file and printer sharing.
    • Enables stricter firewall rules.
  3. To verify or change a network profile after connecting:
    • Click the Wi-Fi icon in the taskbar.
    • Click the info (i) icon or Properties next to the connected network.
    • Under Network profile type, select Public network.
  4. Disable auto-connect. In the same Wi-Fi properties screen, turn off Connect automatically when in range. This prevents your laptop from silently reconnecting to this network in the future.

3. Use Your VPN (If You Have One)

A VPN encrypts all traffic between your laptop and your company network — making public Wi-Fi effectively private.

  1. Connect to VPN before opening any work application — Outlook, Teams, SharePoint, OneDrive.
  2. Verify the VPN is active. Look for a VPN icon in the system tray or check the VPN client's status indicator.
  3. Keep VPN connected for the entire session. If the VPN disconnects, stop working on sensitive tasks until you reconnect.
  4. If VPN fails to connect, see step 4 below for alternatives. For VPN troubleshooting steps, see How to Troubleshoot VPN Connection Issues (User-Level Steps).

4. What to Do If You Do Not Have a VPN

Not every organization provides VPN access. You can still reduce your risk.

  1. Use your phone as a mobile hotspot instead of public Wi-Fi. This gives you a private, encrypted connection over cellular data.
    • On your phone, enable Mobile Hotspot or Personal Hotspot in settings.
    • Connect your laptop to your phone's hotspot instead of the public network. For the full steps on both iPhone and Android — including how to stop Windows draining your data allowance while you are tethered — see How to Use Your Phone as a Wi-Fi Hotspot for Your Laptop.
  2. Verify HTTPS on every site. Before entering any credentials, confirm the address bar shows a padlock icon and the URL starts with https://. Never enter a password on a page that shows http:// (no "s").
  3. Avoid sensitive activities on public Wi-Fi without VPN:
    • Do not access banking or financial sites.
    • Do not enter passwords on unfamiliar sites.
    • Defer downloading sensitive files or attachments until you are on a trusted network.
  4. Turn off file sharing. Open Settings > Network & internet > Advanced network settings > Advanced sharing settings and confirm File and printer sharing is turned off for Public networks.

5. Protect Your Device While Connected

Reduce your attack surface while you are on an untrusted network.

  1. Verify Windows Firewall is on. Open Windows Security > Firewall & network protection. Confirm the firewall is active for the Public network profile.
  2. Turn off Bluetooth if you are not using it. Open Settings > Bluetooth & devices and toggle Bluetooth off. Bluetooth can be exploited for unauthorized connections in crowded spaces.
  3. Lock your screen when you step away — even for a moment. Press Windows + L. For more lock options, see How to Lock Your Computer Quickly on Windows.
  4. Do not leave your laptop unattended in public spaces. Physical access is the easiest attack vector.
  5. Disable Wi-Fi if you are not using it. Click the Wi-Fi icon in the taskbar and toggle Wi-Fi off when you do not need internet access.

6. After You Disconnect

Clean up to reduce lingering risk.

  1. Forget the network. Open Settings > Network & internet > Wi-Fi > Manage known networks. Find the public network and click Forget. This prevents your laptop from auto-connecting to it later.
  2. Check your sign-in activity. After using public Wi-Fi, verify no suspicious sign-ins occurred on your Microsoft 365 account. See How to Check Your Sign-In Activity in Microsoft 365.
  3. Clear browser data if you used a shared or borrowed device. If you used someone else's computer (not your own), clear browsing data before returning it. See How to Clear Browser Cache and Cookies.
  4. Reconnect to your trusted network or VPN as soon as you are back in a secure location.

Troubleshooting

WARNING

If your organization requires VPN for remote access, do not access company data — email, SharePoint, Teams — over public Wi-Fi without VPN connected. Your IT team may block access or flag the sign-in as suspicious.

Symptom / ErrorPotential CauseSolution
VPN won't connect on hotel Wi-FiHotel captive portal blocking VPNOpen your browser first, accept the hotel's terms and conditions page, then try connecting VPN again.
"No Internet, Secured" after connectingIP conflict on crowded networkForget the network and reconnect. If it persists, use your phone's mobile hotspot instead. See How to Fix "No Internet, Secured" Wi-Fi Error on Windows 11.
Can't access work email or SharePointOrganization blocks access from untrusted networksConnect VPN first. If VPN is unavailable, switch to your phone's mobile hotspot.
Suspicious sign-in alert after travelingYour IP address changed unexpectedlyVerify and approve the alert in the Microsoft Authenticator app, then review your sign-in activity. See How to Check Your Sign-In Activity in Microsoft 365.
Wi-Fi keeps disconnectingWeak signal or network congestionMove closer to the access point. If unstable, switch to your phone's mobile hotspot.
Captive portal page won't loadDNS or browser cache issueTry opening http://neverssl.com in your browser to force the portal to appear. Clear your browser cache if it still does not load.