Identity and security

Defender for Office 365

Microsoft Defender for Office 365

Microsoft Defender for Office 365 is the advanced email and collaboration security layer that sits above the baseline anti-spam and anti-malware protection every Microsoft 365 mailbox already receives through Exchange Online Protection.

Why Defender for Office 365 matters in a Microsoft estate

Defender for Office 365 matters because identity, access, endpoint, and data controls shape how Microsoft environments are protected. Readers should understand the term and then be able to move into security assessment, conformity, or remediation guidance.

How Defender for Office 365 shows up in practice

It adds the behavioural and detonation-based defences needed against modern phishing, business email compromise, and targeted malware delivery that signature-based filtering alone reliably misses. Safe Links rewrites URLs in email and Office documents so that when a link is actually clicked, it is checked against current threat intelligence at time of click rather than only at time of delivery. This matters because a link can be entirely benign when an email first arrives and get weaponised hours or days later, a pattern attackers deliberately exploit knowing static, delivery-time-only scanning will miss it.

Safe Attachments extends the same time-of-use principle to file attachments by detonating them in an isolated sandbox environment before delivery, observing their actual runtime behaviour rather than relying solely on static signature matching, which catches malware built specifically to evade conventional antivirus detection. Anti-phishing policies and impersonation protection address business email compromise directly, a threat category that often carries no malicious link or attachment at all and so evades traditional malware-focused defences entirely. They do this by analysing sender authentication signals, domain similarity to known trusted senders, and mailbox intelligence built from an organisation's own communication patterns to flag messages impersonating executives, known contacts, or the organisation's own domain.

Threat Explorer and the related campaign views give security teams a queryable interface across all delivered, blocked, and quarantined mail, letting them search for a specific indicator across the entire tenant and see it as part of a wider campaign rather than an isolated message. Zero-hour Auto Purge, meanwhile, retroactively removes messages from inboxes after delivery once they are subsequently identified as malicious, closing the gap for threats that were missed at the moment of delivery but caught shortly afterward through updated threat intelligence.

Like Defender for Endpoint, Defender for Office 365 is licensed in two tiers: Plan 1 covers the core protective features, Safe Links, Safe Attachments, and anti-phishing, and Plan 2 adds the investigative and automated response layer, Threat Explorer, automated investigation and response, and attack simulation training. Attack simulation training runs realistic phishing campaigns against an organisation's own users to measure and improve their real-world susceptibility. Because Exchange Online Protection is included in every Microsoft 365 plan by default, organisations sometimes assume their email is comprehensively protected when in fact they are running only the baseline layer. They often discover the gap only after a phishing or business email compromise incident that Defender for Office 365's additional detection would very plausibly have caught.

Related terms

Glossary