Enable Defender for Office 365 (requires Business Premium or E5), configure Safe Links, Safe Attachments, and anti-impersonation policies. Don't rely on default settings—they're not aggressive enough.
What Microsoft 365 Offers
Exchange Online Protection (EOP)
Included in all M365 plans:- Basic spam filtering
- Known malware blocking
- Basic anti-phishing
- Connection filtering
Defender for Office 365 (Plan 1)
Included in Business Premium, E5, or add-on:- Safe Attachments (sandbox detonation)
- Safe Links (URL scanning at click time)
- Anti-impersonation protection
- Advanced anti-phishing policies
- Real-time reports
Defender for Office 365 (Plan 2)
Included in E5 or add-on:- Everything in Plan 1
- Threat Explorer
- Automated investigation
- Attack simulation training
- Campaign views
Essential Configuration
1. Safe Links
What it does: Scans URLs at click time, not just delivery. Catches links that become malicious after delivery.
Configure:
- Microsoft 365 Defender portal > Email & collaboration > Policies > Safe Links
- Create or edit policy
- Settings:
2. Safe Attachments
What it does: Opens attachments in a sandbox to detect malicious behaviour before delivery.
Configure:
- Microsoft 365 Defender portal > Email & collaboration > Policies > Safe Attachments
- Create or edit policy
- Settings:
3. Anti-phishing policies
What it does: Protects against impersonation of your users and domains.
Configure:
- Microsoft 365 Defender portal > Email & collaboration > Policies > Anti-phishing
- Create or edit policy
- Impersonation settings:
- Actions:
4. Anti-spam policies
Tighten beyond defaults:
- Microsoft 365 Defender portal > Email & collaboration > Policies > Anti-spam
- Edit default policy
- Consider:
Quick Wins
Today:
- Check you have Business Premium or Defender add-on
- Enable Safe Links and Safe Attachments
- Add executives to impersonation protection
- Configure anti-phishing policy fully
- Tighten anti-spam settings
- Test with a phishing simulation
- Review quarantine regularly
- Monitor phishing reports
- Update impersonation list as roles change
External Email Warning
Add banner to external emails:
- Exchange Admin Centre > Mail Flow > Rules
- Create rule
- Condition: Sender is outside organisation
- Action: Prepend disclaimer
- Text: "[EXTERNAL] This email originated from outside the organisation. Be cautious with links and attachments."
What Defender Won't Catch
Even with full configuration:
- Sophisticated impersonation from lookalike domains
- Compromised legitimate sender accounts
- Zero-day threats (temporarily)
- Business Email Compromise with no malware
- User awareness training
- Verification processes for financial requests
- Reporting culture
Common Mistakes
Using defaults Out-of-box settings are too permissive. Configure properly.
Not adding impersonation targets If you don't tell it who to protect, it doesn't protect them.
Blocking too aggressively Over-aggressive settings = false positives = users ignore warnings = worse security.
Ignoring reports Defender provides data. Use it. Review what's being caught and missed.
What We Configure
For managed clients:
- Safe Links and Attachments configured optimally
- Anti-impersonation for executives and finance
- Policies tuned over time based on false positive/negative feedback
- Monitoring of threats blocked and emerging patterns
- User training to complement technical controls
