Browse all topics
Microsoft Defender (Security)

Microsoft Defender for Office 365 explained

By Emil Björk · Microsoft ecosystem consultant, Gothenburg

What Defender for Office 365 adds on top of EOP — Safe Links, Safe Attachments, AIR, attack simulation — plus Plan 1 vs Plan 2 and the settings worth tuning.

Microsoft Defender for Office 365 is the advanced threat-protection layer for Exchange Online, Teams, SharePoint, OneDrive, and the Office apps. Every Exchange Online tenant already has Exchange Online Protection (EOP) — baseline anti-spam, anti-malware, and basic anti-phishing that you can't turn off and didn't pay extra for. Defender for Office 365 is the paid layer above it, built for the attacks EOP's reputation-and-signature approach misses: freshly weaponised links, zero-day attachments, and targeted impersonation.

Email remains the front door for most compromises, which is why this is usually the first Defender product worth buying in the Defender family — and why it delivers value faster than any of its siblings.

What Defender for Office 365 adds

  • Safe Links — URLs in email, Teams messages, and Office documents are rewritten through a Microsoft proxy and checked against live threat intelligence at click time, not just at delivery. This defeats the standard trick of sending a clean link and weaponising the destination an hour after it lands in inboxes. If the verdict has turned bad, the user hits a block page instead of the payload.
  • Safe Attachments — unknown attachments are detonated in a sandbox before delivery. Dynamic Delivery removes the classic objection: the message body arrives immediately with a placeholder, and the attachment follows once scanning completes, so users don't feel the delay.
  • Advanced anti-phishing — impersonation protection for named users and domains (the "CEO display-name fraud" defence), mailbox intelligence that learns each user's normal correspondents and flags anomalies, and spoof intelligence for domains sending as you.
  • Automated Investigation and Response (AIR) — when a phishing campaign is detected or a user reports a message, automated playbooks identify every affected mailbox, quarantine or soft-delete the campaign tenant-wide, and produce an investigation trail. This is the feature that turns "forward suspicious mail to IT" from an afternoon of manual searching into an approval click.
  • Attack Simulation Training — controlled phishing simulations with embedded training for those who click; covered in depth in Attack Simulation Training.
  • Threat Explorer and Campaign Views — the analyst surface: hunt across delivered mail, trace a campaign as one object instead of four thousand messages, and remediate from the same screen.

Plan 1 vs Plan 2

The product ships in two plans, and the split is protection versus operations:

  • Plan 1 — the prevention set: Safe Links, Safe Attachments, advanced anti-phishing, real-time detections. Included in Microsoft 365 Business Premium.
  • Plan 2 — everything in Plan 1 plus the response set: AIR, Threat Explorer, Campaign Views, Attack Simulation Training, and advanced hunting over email data. Included in Microsoft 365 E5 and Office 365 E5; also a standalone add-on.

The honest guidance: Plan 1 is the minimum any business tenant should run — its features stop compromises. Plan 2 pays off where somebody actually works the security queue; AIR alone can justify it in organisations that see regular phishing waves, because it replaces the most tedious incident-response labour there is. If nobody in your organisation will ever open Threat Explorer, buy Plan 1 and spend the difference elsewhere.

Preset policies beat artisanal ones

Defender for Office 365 configuration used to be a craft project of a dozen interlocking policies. Don't do that. Microsoft's preset security policies — Standard and Strict — bundle the current recommended settings for EOP and Defender in one assignment, and they update as recommendations evolve. Start with Standard for everyone, apply Strict to high-value targets (executives, finance, IT admins), and hand-build custom policies only for documented exceptions. The configuration analyzer in the Defender portal will tell you where existing settings drift from the recommendation.

Tuning that still matters

Presets don't know your organisation. Worth doing by hand:

  • Add your VIPs and finance approvers to user impersonation protection, and your key partner domains to domain impersonation protection.
  • Configure quarantine policies and end-user notifications so users self-release low-risk spam without a ticket — the quarantine workflow guide covers the design.
  • Deploy the Report Phishing button and actually feed reports into AIR; user reports are a top detection source in real incidents.
  • Get SPF, DKIM, and DMARC right for your own domains — Defender's spoof protection works far better when your outbound authentication is clean, and it's covered in Exchange Online anti-spam and anti-phishing.

Integration with Defender XDR

Detections flow into Microsoft Defender XDR at security.microsoft.com, where they correlate with Defender for Endpoint, Defender for Identity, and Defender for Cloud Apps signals. The payoff is incident-level context: a phishing message, the credential entry on the fake page, the suspicious sign-in that followed, and the mailbox rule the attacker created appear as one incident with the chain assembled — and attack disruption can act on it automatically, disabling the compromised account before the analyst finishes reading. Email security stops being a silo, which is the actual argument for staying inside the Microsoft stack rather than bolting on a third-party gateway.

Bottom line

Route mail through EOP, turn on the Standard preset, protect your VIPs, deploy the report button. That's a first month that measurably reduces compromise risk — more than almost any other product in the suite can claim for the same effort.

Further reading

Microsoft Docs & product blog

Spot something wrong or want a topic covered? Send it through the contact form.