Skip to main content

Defender for Office 365 Policies Worth Configuring on Day One

Media Defender for Office 365 Policies Worth Configuring on Day One

 

Microsoft Defender for Office 365 can provide strong protection against phishing, malicious links, weaponised attachments, sender impersonation and threats discovered after email delivery.

However, buying the licence does not automatically mean every organisation is using the most appropriate protection.

Microsoft enables Built-in protection to provide baseline Safe Links and Safe Attachments coverage, but businesses should still review recipient coverage, preset security policies, impersonation settings, quarantine behaviour, user reporting and operational monitoring. Microsoft generally recommends using its Standard and Strict preset security policies rather than manually recreating dozens of individual settings. 

This guide explains the Defender for Office 365 policies worth configuring from day one and how to introduce them without creating unnecessary disruption.

What Is Microsoft Defender for Office 365?

Microsoft Defender for Office 365 is Microsoft’s cloud-based protection for email and collaboration services.

Depending on the organisation’s licence and configuration, it can help protect:

  • Exchange Online email
  • Microsoft Teams
  • SharePoint Online
  • OneDrive for Business
  • Office applications
  • Links and attachments
  • Users targeted by impersonation
  • Messages later identified as malicious

Core features include:

  • Safe Links
  • Safe Attachments
  • Anti-phishing policies
  • Impersonation protection
  • Spoof intelligence
  • Zero-hour auto purge
  • Threat Explorer and investigation capabilities
  • User submissions
  • Attack simulation and training in supported plans
  • Alerts and security reporting

The exact investigation, automation and reporting features vary between Defender for Office 365 Plan 1, Plan 2 and Microsoft 365 licence bundles.

Start With Preset Security Policies

The quickest route to a strong baseline is usually to enable Microsoft’s preset security policies.

The three main levels are:

Built-in Protection

Built-in protection provides basic Safe Links and Safe Attachments coverage for recipients who are not already covered by Standard, Strict or custom policies.

It is designed as a minimum safety net rather than a complete day-one configuration. 

Standard Protection

The Standard preset security policy is intended for most users.

It combines Microsoft-recommended settings for:

  • Anti-spam
  • Anti-malware
  • Anti-phishing
  • Safe Links
  • Safe Attachments

Microsoft recommends Standard preset protection for ordinary users instead of expecting every organisation to construct and maintain equivalent custom policies manually. 

Strict Protection

The Strict preset security policy applies more aggressive settings.

It is generally suitable for users at greater risk, such as:

  • Senior executives
  • Finance personnel
  • Payroll staff
  • Human resources
  • IT administrators
  • Security teams
  • Legal employees
  • Employees handling sensitive customer information

Strict policies can produce more false positives, so pilot them with representative users before expanding coverage.

A Practical Day-One Policy Structure

A sensible initial structure might be:

User group

Recommended starting point

Most employees

Standard preset security policy

Executives and finance

Strict preset security policy

IT and security administrators

Strict preset security policy

Newly acquired or test users

Standard, followed by review

Exceptional applications

Narrow custom policy only where necessary

Everyone else

At least Built-in protection

Do not leave most users protected only by Built-in protection merely because it is automatically enabled.

The preset policy assignment should be intentional and documented.

Understand Policy Precedence

Microsoft 365 email protection can involve:

  • Strict preset policies
  • Standard preset policies
  • Custom policies
  • Default policies
  • Built-in protection

A recipient affected by several policies does not simply receive every setting combined. Microsoft applies defined precedence rules, and preset or custom policies may take priority depending on the protection type and policy order. 

Before creating custom policies, understand:

  • Which users are already covered
  • Which policy has priority
  • Whether a custom exception weakens a preset policy
  • Whether the recipient appears in Standard and Strict assignments
  • Whether exclusions are broader than intended

A complicated collection of overlapping policies is difficult to troubleshoot and easy to weaken accidentally.

Configure Safe Attachments

Safe Attachments examines files in a virtual environment to determine what happens when they are opened.

This process—often called detonation—helps identify malicious behaviour that may not be detected by ordinary signature-based malware scanning. Safe Attachments is designed to detect threats such as malware, ransomware and weaponised phishing files. 

Choose the Correct Safe Attachments Action

Possible behaviours vary by policy and interface, but the objective should be to prevent users from receiving or opening known malicious files.

Review whether your selected preset or custom policy:

  • Blocks malicious attachments
  • Uses dynamic delivery where appropriate
  • Redirects files only to an actively monitored security mailbox
  • Applies to all required recipients
  • Protects SharePoint, OneDrive and Teams where supported
  • Enables post-delivery remediation

Avoid a configuration where malicious files are merely detected but still made conveniently available to the recipient.

Understand Dynamic Delivery

Dynamic delivery can allow the email body to reach the user while the attachment is still being analysed.

This may improve delivery speed, but users must understand that:

  • The attachment may initially be unavailable.
  • The file can later be replaced by a warning.
  • A message body arriving does not prove the attachment is safe.
  • They should not seek another copy from an unverified source.

Test the behaviour with desktop, browser and mobile clients before broad deployment.

Protect Collaboration Storage

Safe Attachments can also help protect files in supported Microsoft 365 collaboration services.

Review coverage for:

  • SharePoint
  • OneDrive
  • Microsoft Teams

A malicious file does not become safe merely because it entered through a Teams chat or shared folder instead of email.

Configure Safe Links

Safe Links analyses URLs and can evaluate them when users click.

This helps protect against attackers who:

  • Hide malicious destinations behind redirects
  • Change a previously harmless site after delivery
  • Use compromised websites
  • Send links that become malicious later
  • Target users through Teams or Office documents

Microsoft provides baseline Safe Links protection through Built-in protection, but organisations should review the Standard or Strict preset policies and confirm that the intended users and workloads are covered. 

Review Time-of-Click Protection

Email links may look safe when the message arrives but become malicious later.

Time-of-click checking allows Microsoft to reassess the destination when the user opens it.

Confirm that Safe Links applies to the workloads your organisation uses, which may include:

  • Email
  • Microsoft Teams
  • Supported Office applications

Avoid Broad “Do Not Rewrite” Lists

Administrators sometimes exclude large numbers of domains because rewritten links look unfamiliar or interfere with a particular workflow.

Every exclusion reduces inspection.

Only exclude a domain when:

  • There is a documented technical problem.
  • The domain is verified.
  • The business owner accepts the risk.
  • The exclusion is narrowly scoped.
  • The exception has a review date.

Do not exclude entire cloud-hosting or URL-shortening services.

Do Not Allow Users to Click Through Every Warning

Where policy options permit, consider preventing users from casually bypassing warnings for known malicious links.

A warning that always includes a convenient “continue anyway” option may become a speed bump rather than a security control.

Configure Anti-Phishing Protection

Anti-phishing policies combine several controls, including:

  • Spoof intelligence
  • Mailbox intelligence
  • User impersonation protection
  • Domain impersonation protection
  • Safety tips
  • Phishing thresholds
  • Actions for detected messages

Microsoft provides a default anti-phishing policy, but enhanced impersonation capabilities in Defender for Office 365 should be reviewed and intentionally configured. 

Enable User Impersonation Protection

User impersonation protection is especially important for people whose names carry authority or financial influence.

Protect users such as:

  • Chief executive
  • Finance director
  • Managing director
  • Payroll manager
  • Head of HR
  • IT director
  • Legal counsel
  • Procurement lead
  • Employees who authorise bank changes
  • Public-facing senior personnel

Attackers may use a similar display name or address to imitate these people.

The policy should define:

  • Which users are protected
  • What happens when impersonation is detected
  • Whether safety tips appear
  • Whether the message is quarantined
  • Who can release it

Do not protect only the chief executive. Attackers frequently impersonate mid-level employees involved in payments and account administration.

Protect Important Domains

Domain impersonation protection can identify messages that resemble:

  • Your own domains
  • Important suppliers
  • Customers
  • Legal partners
  • Payroll providers
  • Banks
  • Managed service providers

Microsoft Defender for Office 365 allows targeted domain protection within anti-phishing policy settings. 

Start with domains whose impersonation would create serious financial or operational risk.

Avoid adding enormous lists that nobody maintains.

Enable Mailbox Intelligence

Mailbox intelligence uses normal communication patterns to help distinguish familiar relationships from unusual or potentially impersonated senders.

This can improve detection when an attacker:

  • Uses a similar sender address
  • Impersonates a known contact
  • Creates a new lookalike domain
  • Targets a user with whom the supposed sender normally communicates

Mailbox intelligence should complement—not replace—SPF, DKIM, DMARC and payment verification controls.

Enable Appropriate Safety Tips

Safety tips can help users recognise:

  • Similar user names
  • Similar domains
  • Unusual sender relationships
  • Unauthenticated messages
  • First-time contacts

Microsoft exposes settings for similar-user and similar-domain safety tips within Defender for Office 365 anti-phishing protection. 

Safety tips are useful, but avoid relying on banners alone.

Users eventually stop noticing warnings that appear on too many legitimate messages.

Keep Spoof Intelligence Enabled

Spoof intelligence analyses senders that appear to use domains they may not be authorised to represent.

Microsoft provides spoofing protection across cloud mailboxes and allows administrators to review or control detected spoofed senders through anti-phishing policies and spoof intelligence. 

Review the spoof intelligence insight to identify:

  • Legitimate services incorrectly treated as spoofing
  • Unauthorised senders using your domain
  • Third-party platforms requiring proper authentication
  • Previous overrides that are no longer necessary

Do not permanently allow a sender simply to stop one support ticket. Correct its SPF, DKIM and DMARC configuration where possible.

Set a Sensible Phishing Threshold

Defender for Office 365 anti-phishing policies support different phishing sensitivity levels.

Higher sensitivity may detect more sophisticated messages but can also increase false positives.

A practical approach is:

  • Standard preset policy for most users
  • Strict preset policy for priority users
  • Custom settings only where a clear business need exists

Avoid manually turning every threshold to its maximum across the entire organisation on day one without a pilot.

Review Anti-Spam Policies

Anti-spam policies control how Microsoft handles:

  • Spam
  • High-confidence spam
  • Bulk email
  • Outbound spam
  • Automatic forwarding
  • Suspicious sending behaviour

Microsoft recommends using Standard or Strict preset security policies in preference to manually maintaining custom anti-spam policies for most users. 

Review Bulk Email Handling

Bulk email is not always malicious.

It may include:

  • Newsletters
  • Supplier updates
  • Marketing messages
  • Automated notifications
  • Industry publications

Choose a bulk threshold that reduces inbox noise without quarantining important communications.

Use Defender reporting and user feedback to tune the configuration.

Restrict Automatic External Forwarding

Automatic forwarding can be abused after mailbox compromise to send business email outside the organisation.

Review outbound spam settings and ensure external forwarding is:

  • Blocked by default where practical
  • Allowed only for documented business cases
  • Monitored
  • Reviewed regularly

A hidden forwarding rule can allow an attacker to maintain visibility even after the user changes their password.

Review Anti-Malware Policies

Exchange Online Protection already scans email for malware, but administrators should still review anti-malware policy behaviour.

Important settings include:

  • Malware actions
  • File-type filtering
  • Administrator notifications
  • Zero-hour auto purge
  • Recipient coverage

Microsoft documents enabling ZAP for malware so messages discovered as malicious after delivery can be quarantined. 

Avoid relying on an attachment’s file extension alone. Attackers can use archives, renamed files and compound file types.

Keep Zero-Hour Auto Purge Enabled

Zero-hour auto purge, or ZAP, allows Microsoft to take action after a message has already been delivered.

This matters because threat intelligence changes.

A message may initially appear safe, then later be classified as:

  • Malware
  • Spam
  • High-confidence phishing

For high-confidence phishing, ZAP can move delivered messages into quarantine. It can act on read and unread messages according to Microsoft’s documented behaviour and the actions defined in the relevant protection policies. 

Why ZAP Matters

Without post-delivery protection:

  1. A message reaches several inboxes.
  2. Microsoft later confirms it is malicious.
  3. The message remains available unless an administrator removes it manually.

With ZAP, Microsoft can retrospectively neutralise the message.

Review ZAP Quarantine Behaviour

Check:

  • Which policy action applies
  • Whether users are notified
  • Whether users can request release
  • Whether only administrators can release high-confidence phishing
  • How the security team investigates ZAP actions

Users should not be able to self-release the most dangerous message categories casually.

Configure Quarantine Policies

Quarantine policies control what users can do with quarantined messages.

They can govern:

  • Whether users receive notifications
  • Whether they can preview a message
  • Whether they can release it
  • Whether they can request release
  • Which categories remain administrator-controlled

Microsoft allows administrators to define user permissions through quarantine policies rather than treating every quarantined message identically. 

Recommended Day-One Approach

Consider allowing users to manage lower-risk categories such as ordinary bulk or spam while retaining administrator control over:

  • Malware
  • High-confidence phishing
  • Safe Attachments detections
  • Impersonation detections involving senior users
  • Messages associated with active incidents

The exact balance depends on support capacity and business risk.

Configure Notifications Carefully

Quarantine notifications can reduce help-desk demand, but they can also train users to click release buttons.

Use clear instructions:

  • Confirm the sender independently.
  • Do not release messages requesting passwords or payment changes.
  • Report suspicious content.
  • Request security review where uncertain.

Configure User-Reported Settings

Employees should have a clear method for reporting:

  • Phishing
  • Spam
  • Legitimate messages incorrectly classified
  • Suspicious Teams content where supported

The reporting process should send useful evidence into a monitored security workflow.

A day-one deployment should answer:

  • Is the Report button available?
  • Where do submissions go?
  • Are messages sent to Microsoft, an internal mailbox or both?
  • Who reviews them?
  • How quickly are reports investigated?
  • Can the team search for matching messages across the tenant?
  • Can malicious messages be removed?

A reporting button without an owner is merely a decorative control.

Protect the Reporting Mailbox

When user-reported messages are delivered to an internal security mailbox, configure the advanced delivery settings appropriately.

Security operations mailboxes and third-party phishing simulation systems may require carefully scoped exceptions so Microsoft does not treat intentionally submitted samples as genuine attacks.

Keep these exceptions narrow. Do not create broad mail-flow rules that bypass filtering for ordinary users.

Configure Alerting

Day-one alerts should focus on events that require action rather than producing an unmanageable volume of noise.

Useful categories may include:

  • User reported phishing
  • Suspicious email forwarding
  • Malware campaigns
  • Impersonation detections
  • Unusual outbound email
  • Messages removed by ZAP
  • Potentially compromised users
  • Administrative policy changes
  • Safe Links clicks involving malicious destinations

Define:

  • Alert owner
  • Severity
  • Notification recipients
  • Response time
  • Escalation route
  • Closure criteria

An alert nobody investigates provides little protection.

Use Threat Explorer Where Licensed

Threat Explorer can help security teams investigate:

  • Who received a message
  • Where it was originally delivered
  • Whether ZAP moved it later
  • Which users clicked a link
  • Which attachments were detected
  • Whether similar messages reached other recipients

Microsoft recommends reviewing original and final delivery locations to understand the complete lifecycle of a message, including post-delivery actions. 

Create an investigation procedure before the first serious phishing incident.

Review Email Security Reports

Microsoft Defender provides reporting for events such as:

  • Malware detections
  • Phishing
  • Safe Links blocks
  • Safe Attachments detections
  • ZAP actions
  • Impersonation protection
  • Spam and bulk email

These reports help identify both attack trends and policy problems. 

Review them regularly for:

  • Users receiving the most targeted attacks
  • Domains frequently impersonated
  • Repeated false positives
  • Safe Links clicks
  • Messages reaching inboxes before ZAP
  • Unusual outbound activity
  • Policy gaps

Protect Priority Accounts More Aggressively

Not every user carries the same risk.

Create a priority-user group for employees such as:

  • Board members
  • Executives
  • Finance approvers
  • Payroll
  • HR leadership
  • IT administrators
  • Security administrators
  • Legal teams
  • Public-facing senior employees

Assign them Strict preset protection where practical.

Also combine Defender for Office 365 with:

  • Phishing-resistant MFA
  • Conditional Access
  • Managed devices
  • Endpoint detection and response
  • Payment-verification procedures
  • Separate privileged accounts

Email security cannot compensate for weak identity and finance controls.

Do Not Forget Shared Mailboxes

Shared mailboxes often receive:

  • Invoices
  • Supplier changes
  • Customer requests
  • Job applications
  • Legal correspondence
  • Support tickets

Examples include:

accounts@company.com

finance@company.com

hr@company.com

support@company.com

Confirm that the users accessing these mailboxes are covered by the appropriate policies and that security teams understand how detections and quarantine behaviour affect shared-mailbox workflows.

Attackers frequently target functional addresses because several employees monitor them and responsibility is less clear.

Review Allow Lists and Overrides

Allow lists are dangerous when they become permanent.

Review:

  • Allowed senders
  • Allowed domains
  • Tenant Allow/Block List entries
  • Mail-flow rules bypassing spam filtering
  • Safe Links exclusions
  • Safe Attachments exceptions
  • Spoof intelligence overrides
  • Connection-filter exceptions

For every allow entry, document:

  • Reason
  • Owner
  • Date created
  • Scope
  • Risk
  • Review date
  • Removal condition

An allow rule can override or weaken sophisticated detection.

Fix authentication and sender configuration rather than bypassing protection whenever possible.

Do Not Create Broad Mail-Flow Bypass Rules

Rules that set spam confidence to bypass filtering can create major security gaps.

Be especially cautious with rules based on:

  • Display name
  • Subject line
  • Message headers controlled by the sender
  • Broad IP ranges
  • Entire cloud-service domains
  • Partner claims that cannot be authenticated

An attacker may imitate the same condition and receive the bypass.

Use connectors, certificate validation and restricted scopes where a trusted mail flow genuinely requires special handling.

Roll Out Safely

Phase 1: Inventory

Identify:

  • Licence coverage
  • User groups
  • Priority accounts
  • Shared mailboxes
  • Third-party gateways
  • Existing policies
  • Allow lists
  • Reporting mailboxes
  • Phishing simulation platforms

Phase 2: Enable Preset Protection

  • Assign Standard to most users.
  • Assign Strict to a pilot group of high-risk users.
  • Confirm Built-in protection covers anything not yet assigned.
  • Review exclusions.

Phase 3: Configure Operations

  • Set quarantine policies.
  • Enable reporting.
  • Configure alert recipients.
  • Document investigation steps.
  • Confirm ZAP behaviour.
  • Train the help desk.

Phase 4: Pilot and Tune

  • Monitor false positives.
  • Review blocked business messages.
  • Fix third-party sender authentication.
  • Remove unnecessary allow rules.
  • Expand Strict protection.

Phase 5: Review Regularly

  • Check reports.
  • Review policy assignments.
  • Audit exclusions.
  • Update priority users.
  • Test incident response.
  • Review Microsoft’s recommended settings after product changes.

Common Day-One Mistakes

Assuming Built-in Protection Is the Final Configuration

It is a baseline, not necessarily the correct protection level for the whole organisation.

Building Everything Manually

Custom policies can drift away from Microsoft’s recommendations and become difficult to maintain.

Putting Everyone Into Strict Immediately

This may produce disruption and lead to broad emergency exclusions.

Protecting Only Executives From Impersonation

Finance, payroll and procurement staff are also attractive impersonation targets.

Allowing Users to Release High-Confidence Phishing

The most dangerous messages should remain under administrator control.

Ignoring Teams and Collaboration Files

Threats do not arrive only through Exchange email.

Leaving User Reports Unmonitored

Employees believe they have reported a threat, but nobody acts.

Creating Broad Allow Rules

One exception can undermine several layers of protection.

Ignoring Messages After Delivery

ZAP and investigation capabilities matter because detections change over time.

Never Reviewing Reports

A policy cannot be tuned effectively without operational evidence.

Day-One Configuration Checklist

Protection Baseline

  • Assign Standard preset protection to most users.
  • Assign Strict preset protection to high-risk users.
  • Confirm Built-in protection remains available as a safety net.
  • Review policy precedence and exclusions.

Safe Links

  • Confirm time-of-click protection.
  • Cover email, Teams and supported Office applications.
  • Restrict warning bypass where appropriate.
  • Minimise exclusions.

Safe Attachments

  • Block malicious attachments.
  • Review dynamic delivery.
  • Protect SharePoint, OneDrive and Teams where available.
  • Confirm quarantine and alert behaviour.

Anti-Phishing

  • Enable spoof intelligence.
  • Enable mailbox intelligence.
  • Protect priority users.
  • Protect important domains.
  • Configure appropriate actions and safety tips.

Post-Delivery Protection

  • Keep ZAP enabled.
  • Review ZAP actions.
  • Confirm how security teams investigate removed messages.

Quarantine

  • Define user permissions.
  • Keep malware and high-confidence phishing administrator-controlled.
  • Configure notifications.
  • Test release-request workflows.

Operations

  • Enable user reporting.
  • Monitor the submissions queue.
  • Configure alerts.
  • Assign incident owners.
  • Review email-security reports.
  • Test Threat Explorer investigations where licensed.

Final Thoughts

Microsoft Defender for Office 365 is most effective when organisations use it as a managed security service rather than a collection of default settings.

A strong day-one configuration begins with Microsoft’s preset security policies:

  • Standard for most employees
  • Strict for high-risk users
  • Built-in protection as a minimum safety net

Then verify the operational details:

  • Safe Links checks dangerous destinations.
  • Safe Attachments analyses suspicious files.
  • Anti-phishing policies protect important users and domains.
  • Spoof and mailbox intelligence identify deceptive senders.
  • ZAP removes threats discovered after delivery.
  • Quarantine policies prevent unsafe self-release.
  • User reporting feeds a monitored investigation process.

Do not weaken the environment with broad allow lists merely to eliminate support tickets. Investigate why legitimate mail is being blocked, correct its authentication and create only the narrowest necessary exception.

Most importantly, review the configuration regularly. Microsoft updates its protection stack, attackers change tactics and your business continuously adds new users, suppliers and applications.

The best Defender for Office 365 policy is not one that was configured once.

It is one that is actively monitored, tested and maintained.

Need Help Configuring Defender for Office 365?

Hamilton Group can help your business deploy and optimise Microsoft Defender for Office 365.

Our experts can help you:

  • Configure Standard and Strict preset security policies
  • Protect priority users and important domains
  • Deploy Safe Links and Safe Attachments
  • Tune anti-phishing and impersonation protection
  • Configure quarantine and user reporting
  • Review allow lists and mail-flow bypasses
  • Set up alerts and investigation processes
  • Investigate delivered phishing and malware
  • Improve Microsoft Teams and SharePoint protection
  • Train employees to report suspicious messages

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to strengthen your Microsoft 365 email security.