Defender for Office 365 Policies Worth Configuring on Day One
Microsoft Defender for Office 365 can provide strong protection against phishing, malicious links, weaponised attachments, sender impersonation and threats discovered after email delivery.
However, buying the licence does not automatically mean every organisation is using the most appropriate protection.
Microsoft enables Built-in protection to provide baseline Safe Links and Safe Attachments coverage, but businesses should still review recipient coverage, preset security policies, impersonation settings, quarantine behaviour, user reporting and operational monitoring. Microsoft generally recommends using its Standard and Strict preset security policies rather than manually recreating dozens of individual settings.
This guide explains the Defender for Office 365 policies worth configuring from day one and how to introduce them without creating unnecessary disruption.
What Is Microsoft Defender for Office 365?
Microsoft Defender for Office 365 is Microsoft’s cloud-based protection for email and collaboration services.
Depending on the organisation’s licence and configuration, it can help protect:
- Exchange Online email
- Microsoft Teams
- SharePoint Online
- OneDrive for Business
- Office applications
- Links and attachments
- Users targeted by impersonation
- Messages later identified as malicious
Core features include:
- Safe Links
- Safe Attachments
- Anti-phishing policies
- Impersonation protection
- Spoof intelligence
- Zero-hour auto purge
- Threat Explorer and investigation capabilities
- User submissions
- Attack simulation and training in supported plans
- Alerts and security reporting
The exact investigation, automation and reporting features vary between Defender for Office 365 Plan 1, Plan 2 and Microsoft 365 licence bundles.
Start With Preset Security Policies
The quickest route to a strong baseline is usually to enable Microsoft’s preset security policies.
The three main levels are:
Built-in Protection
Built-in protection provides basic Safe Links and Safe Attachments coverage for recipients who are not already covered by Standard, Strict or custom policies.
It is designed as a minimum safety net rather than a complete day-one configuration.
Standard Protection
The Standard preset security policy is intended for most users.
It combines Microsoft-recommended settings for:
- Anti-spam
- Anti-malware
- Anti-phishing
- Safe Links
- Safe Attachments
Microsoft recommends Standard preset protection for ordinary users instead of expecting every organisation to construct and maintain equivalent custom policies manually.
Strict Protection
The Strict preset security policy applies more aggressive settings.
It is generally suitable for users at greater risk, such as:
- Senior executives
- Finance personnel
- Payroll staff
- Human resources
- IT administrators
- Security teams
- Legal employees
- Employees handling sensitive customer information
Strict policies can produce more false positives, so pilot them with representative users before expanding coverage.
A Practical Day-One Policy Structure
A sensible initial structure might be:
User group | Recommended starting point |
Most employees | Standard preset security policy |
Executives and finance | Strict preset security policy |
IT and security administrators | Strict preset security policy |
Newly acquired or test users | Standard, followed by review |
Exceptional applications | Narrow custom policy only where necessary |
Everyone else | At least Built-in protection |
Do not leave most users protected only by Built-in protection merely because it is automatically enabled.
The preset policy assignment should be intentional and documented.
Understand Policy Precedence
Microsoft 365 email protection can involve:
- Strict preset policies
- Standard preset policies
- Custom policies
- Default policies
- Built-in protection
A recipient affected by several policies does not simply receive every setting combined. Microsoft applies defined precedence rules, and preset or custom policies may take priority depending on the protection type and policy order.
Before creating custom policies, understand:
- Which users are already covered
- Which policy has priority
- Whether a custom exception weakens a preset policy
- Whether the recipient appears in Standard and Strict assignments
- Whether exclusions are broader than intended
A complicated collection of overlapping policies is difficult to troubleshoot and easy to weaken accidentally.
Configure Safe Attachments
Safe Attachments examines files in a virtual environment to determine what happens when they are opened.
This process—often called detonation—helps identify malicious behaviour that may not be detected by ordinary signature-based malware scanning. Safe Attachments is designed to detect threats such as malware, ransomware and weaponised phishing files.
Choose the Correct Safe Attachments Action
Possible behaviours vary by policy and interface, but the objective should be to prevent users from receiving or opening known malicious files.
Review whether your selected preset or custom policy:
- Blocks malicious attachments
- Uses dynamic delivery where appropriate
- Redirects files only to an actively monitored security mailbox
- Applies to all required recipients
- Protects SharePoint, OneDrive and Teams where supported
- Enables post-delivery remediation
Avoid a configuration where malicious files are merely detected but still made conveniently available to the recipient.
Understand Dynamic Delivery
Dynamic delivery can allow the email body to reach the user while the attachment is still being analysed.
This may improve delivery speed, but users must understand that:
- The attachment may initially be unavailable.
- The file can later be replaced by a warning.
- A message body arriving does not prove the attachment is safe.
- They should not seek another copy from an unverified source.
Test the behaviour with desktop, browser and mobile clients before broad deployment.
Protect Collaboration Storage
Safe Attachments can also help protect files in supported Microsoft 365 collaboration services.
Review coverage for:
- SharePoint
- OneDrive
- Microsoft Teams
A malicious file does not become safe merely because it entered through a Teams chat or shared folder instead of email.
Configure Safe Links
Safe Links analyses URLs and can evaluate them when users click.
This helps protect against attackers who:
- Hide malicious destinations behind redirects
- Change a previously harmless site after delivery
- Use compromised websites
- Send links that become malicious later
- Target users through Teams or Office documents
Microsoft provides baseline Safe Links protection through Built-in protection, but organisations should review the Standard or Strict preset policies and confirm that the intended users and workloads are covered.
Review Time-of-Click Protection
Email links may look safe when the message arrives but become malicious later.
Time-of-click checking allows Microsoft to reassess the destination when the user opens it.
Confirm that Safe Links applies to the workloads your organisation uses, which may include:
- Microsoft Teams
- Supported Office applications
Avoid Broad “Do Not Rewrite” Lists
Administrators sometimes exclude large numbers of domains because rewritten links look unfamiliar or interfere with a particular workflow.
Every exclusion reduces inspection.
Only exclude a domain when:
- There is a documented technical problem.
- The domain is verified.
- The business owner accepts the risk.
- The exclusion is narrowly scoped.
- The exception has a review date.
Do not exclude entire cloud-hosting or URL-shortening services.
Do Not Allow Users to Click Through Every Warning
Where policy options permit, consider preventing users from casually bypassing warnings for known malicious links.
A warning that always includes a convenient “continue anyway” option may become a speed bump rather than a security control.
Configure Anti-Phishing Protection
Anti-phishing policies combine several controls, including:
- Spoof intelligence
- Mailbox intelligence
- User impersonation protection
- Domain impersonation protection
- Safety tips
- Phishing thresholds
- Actions for detected messages
Microsoft provides a default anti-phishing policy, but enhanced impersonation capabilities in Defender for Office 365 should be reviewed and intentionally configured.
Enable User Impersonation Protection
User impersonation protection is especially important for people whose names carry authority or financial influence.
Protect users such as:
- Chief executive
- Finance director
- Managing director
- Payroll manager
- Head of HR
- IT director
- Legal counsel
- Procurement lead
- Employees who authorise bank changes
- Public-facing senior personnel
Attackers may use a similar display name or address to imitate these people.
The policy should define:
- Which users are protected
- What happens when impersonation is detected
- Whether safety tips appear
- Whether the message is quarantined
- Who can release it
Do not protect only the chief executive. Attackers frequently impersonate mid-level employees involved in payments and account administration.
Protect Important Domains
Domain impersonation protection can identify messages that resemble:
- Your own domains
- Important suppliers
- Customers
- Legal partners
- Payroll providers
- Banks
- Managed service providers
Microsoft Defender for Office 365 allows targeted domain protection within anti-phishing policy settings.
Start with domains whose impersonation would create serious financial or operational risk.
Avoid adding enormous lists that nobody maintains.
Enable Mailbox Intelligence
Mailbox intelligence uses normal communication patterns to help distinguish familiar relationships from unusual or potentially impersonated senders.
This can improve detection when an attacker:
- Uses a similar sender address
- Impersonates a known contact
- Creates a new lookalike domain
- Targets a user with whom the supposed sender normally communicates
Mailbox intelligence should complement—not replace—SPF, DKIM, DMARC and payment verification controls.
Enable Appropriate Safety Tips
Safety tips can help users recognise:
- Similar user names
- Similar domains
- Unusual sender relationships
- Unauthenticated messages
- First-time contacts
Microsoft exposes settings for similar-user and similar-domain safety tips within Defender for Office 365 anti-phishing protection.
Safety tips are useful, but avoid relying on banners alone.
Users eventually stop noticing warnings that appear on too many legitimate messages.
Keep Spoof Intelligence Enabled
Spoof intelligence analyses senders that appear to use domains they may not be authorised to represent.
Microsoft provides spoofing protection across cloud mailboxes and allows administrators to review or control detected spoofed senders through anti-phishing policies and spoof intelligence.
Review the spoof intelligence insight to identify:
- Legitimate services incorrectly treated as spoofing
- Unauthorised senders using your domain
- Third-party platforms requiring proper authentication
- Previous overrides that are no longer necessary
Do not permanently allow a sender simply to stop one support ticket. Correct its SPF, DKIM and DMARC configuration where possible.
Set a Sensible Phishing Threshold
Defender for Office 365 anti-phishing policies support different phishing sensitivity levels.
Higher sensitivity may detect more sophisticated messages but can also increase false positives.
A practical approach is:
- Standard preset policy for most users
- Strict preset policy for priority users
- Custom settings only where a clear business need exists
Avoid manually turning every threshold to its maximum across the entire organisation on day one without a pilot.
Review Anti-Spam Policies
Anti-spam policies control how Microsoft handles:
- Spam
- High-confidence spam
- Bulk email
- Outbound spam
- Automatic forwarding
- Suspicious sending behaviour
Microsoft recommends using Standard or Strict preset security policies in preference to manually maintaining custom anti-spam policies for most users.
Review Bulk Email Handling
Bulk email is not always malicious.
It may include:
- Newsletters
- Supplier updates
- Marketing messages
- Automated notifications
- Industry publications
Choose a bulk threshold that reduces inbox noise without quarantining important communications.
Use Defender reporting and user feedback to tune the configuration.
Restrict Automatic External Forwarding
Automatic forwarding can be abused after mailbox compromise to send business email outside the organisation.
Review outbound spam settings and ensure external forwarding is:
- Blocked by default where practical
- Allowed only for documented business cases
- Monitored
- Reviewed regularly
A hidden forwarding rule can allow an attacker to maintain visibility even after the user changes their password.
Review Anti-Malware Policies
Exchange Online Protection already scans email for malware, but administrators should still review anti-malware policy behaviour.
Important settings include:
- Malware actions
- File-type filtering
- Administrator notifications
- Zero-hour auto purge
- Recipient coverage
Microsoft documents enabling ZAP for malware so messages discovered as malicious after delivery can be quarantined.
Avoid relying on an attachment’s file extension alone. Attackers can use archives, renamed files and compound file types.
Keep Zero-Hour Auto Purge Enabled
Zero-hour auto purge, or ZAP, allows Microsoft to take action after a message has already been delivered.
This matters because threat intelligence changes.
A message may initially appear safe, then later be classified as:
- Malware
- Spam
- High-confidence phishing
For high-confidence phishing, ZAP can move delivered messages into quarantine. It can act on read and unread messages according to Microsoft’s documented behaviour and the actions defined in the relevant protection policies.
Why ZAP Matters
Without post-delivery protection:
- A message reaches several inboxes.
- Microsoft later confirms it is malicious.
- The message remains available unless an administrator removes it manually.
With ZAP, Microsoft can retrospectively neutralise the message.
Review ZAP Quarantine Behaviour
Check:
- Which policy action applies
- Whether users are notified
- Whether users can request release
- Whether only administrators can release high-confidence phishing
- How the security team investigates ZAP actions
Users should not be able to self-release the most dangerous message categories casually.
Configure Quarantine Policies
Quarantine policies control what users can do with quarantined messages.
They can govern:
- Whether users receive notifications
- Whether they can preview a message
- Whether they can release it
- Whether they can request release
- Which categories remain administrator-controlled
Microsoft allows administrators to define user permissions through quarantine policies rather than treating every quarantined message identically.
Recommended Day-One Approach
Consider allowing users to manage lower-risk categories such as ordinary bulk or spam while retaining administrator control over:
- Malware
- High-confidence phishing
- Safe Attachments detections
- Impersonation detections involving senior users
- Messages associated with active incidents
The exact balance depends on support capacity and business risk.
Configure Notifications Carefully
Quarantine notifications can reduce help-desk demand, but they can also train users to click release buttons.
Use clear instructions:
- Confirm the sender independently.
- Do not release messages requesting passwords or payment changes.
- Report suspicious content.
- Request security review where uncertain.
Configure User-Reported Settings
Employees should have a clear method for reporting:
- Phishing
- Spam
- Legitimate messages incorrectly classified
- Suspicious Teams content where supported
The reporting process should send useful evidence into a monitored security workflow.
A day-one deployment should answer:
- Is the Report button available?
- Where do submissions go?
- Are messages sent to Microsoft, an internal mailbox or both?
- Who reviews them?
- How quickly are reports investigated?
- Can the team search for matching messages across the tenant?
- Can malicious messages be removed?
A reporting button without an owner is merely a decorative control.
Protect the Reporting Mailbox
When user-reported messages are delivered to an internal security mailbox, configure the advanced delivery settings appropriately.
Security operations mailboxes and third-party phishing simulation systems may require carefully scoped exceptions so Microsoft does not treat intentionally submitted samples as genuine attacks.
Keep these exceptions narrow. Do not create broad mail-flow rules that bypass filtering for ordinary users.
Configure Alerting
Day-one alerts should focus on events that require action rather than producing an unmanageable volume of noise.
Useful categories may include:
- User reported phishing
- Suspicious email forwarding
- Malware campaigns
- Impersonation detections
- Unusual outbound email
- Messages removed by ZAP
- Potentially compromised users
- Administrative policy changes
- Safe Links clicks involving malicious destinations
Define:
- Alert owner
- Severity
- Notification recipients
- Response time
- Escalation route
- Closure criteria
An alert nobody investigates provides little protection.
Use Threat Explorer Where Licensed
Threat Explorer can help security teams investigate:
- Who received a message
- Where it was originally delivered
- Whether ZAP moved it later
- Which users clicked a link
- Which attachments were detected
- Whether similar messages reached other recipients
Microsoft recommends reviewing original and final delivery locations to understand the complete lifecycle of a message, including post-delivery actions.
Create an investigation procedure before the first serious phishing incident.
Review Email Security Reports
Microsoft Defender provides reporting for events such as:
- Malware detections
- Phishing
- Safe Links blocks
- Safe Attachments detections
- ZAP actions
- Impersonation protection
- Spam and bulk email
These reports help identify both attack trends and policy problems.
Review them regularly for:
- Users receiving the most targeted attacks
- Domains frequently impersonated
- Repeated false positives
- Safe Links clicks
- Messages reaching inboxes before ZAP
- Unusual outbound activity
- Policy gaps
Protect Priority Accounts More Aggressively
Not every user carries the same risk.
Create a priority-user group for employees such as:
- Board members
- Executives
- Finance approvers
- Payroll
- HR leadership
- IT administrators
- Security administrators
- Legal teams
- Public-facing senior employees
Assign them Strict preset protection where practical.
Also combine Defender for Office 365 with:
- Phishing-resistant MFA
- Conditional Access
- Managed devices
- Endpoint detection and response
- Payment-verification procedures
- Separate privileged accounts
Email security cannot compensate for weak identity and finance controls.
Do Not Forget Shared Mailboxes
Shared mailboxes often receive:
- Invoices
- Supplier changes
- Customer requests
- Job applications
- Legal correspondence
- Support tickets
Examples include:
accounts@company.com
finance@company.com
hr@company.com
support@company.com
Confirm that the users accessing these mailboxes are covered by the appropriate policies and that security teams understand how detections and quarantine behaviour affect shared-mailbox workflows.
Attackers frequently target functional addresses because several employees monitor them and responsibility is less clear.
Review Allow Lists and Overrides
Allow lists are dangerous when they become permanent.
Review:
- Allowed senders
- Allowed domains
- Tenant Allow/Block List entries
- Mail-flow rules bypassing spam filtering
- Safe Links exclusions
- Safe Attachments exceptions
- Spoof intelligence overrides
- Connection-filter exceptions
For every allow entry, document:
- Reason
- Owner
- Date created
- Scope
- Risk
- Review date
- Removal condition
An allow rule can override or weaken sophisticated detection.
Fix authentication and sender configuration rather than bypassing protection whenever possible.
Do Not Create Broad Mail-Flow Bypass Rules
Rules that set spam confidence to bypass filtering can create major security gaps.
Be especially cautious with rules based on:
- Display name
- Subject line
- Message headers controlled by the sender
- Broad IP ranges
- Entire cloud-service domains
- Partner claims that cannot be authenticated
An attacker may imitate the same condition and receive the bypass.
Use connectors, certificate validation and restricted scopes where a trusted mail flow genuinely requires special handling.
Roll Out Safely
Phase 1: Inventory
Identify:
- Licence coverage
- User groups
- Priority accounts
- Shared mailboxes
- Third-party gateways
- Existing policies
- Allow lists
- Reporting mailboxes
- Phishing simulation platforms
Phase 2: Enable Preset Protection
- Assign Standard to most users.
- Assign Strict to a pilot group of high-risk users.
- Confirm Built-in protection covers anything not yet assigned.
- Review exclusions.
Phase 3: Configure Operations
- Set quarantine policies.
- Enable reporting.
- Configure alert recipients.
- Document investigation steps.
- Confirm ZAP behaviour.
- Train the help desk.
Phase 4: Pilot and Tune
- Monitor false positives.
- Review blocked business messages.
- Fix third-party sender authentication.
- Remove unnecessary allow rules.
- Expand Strict protection.
Phase 5: Review Regularly
- Check reports.
- Review policy assignments.
- Audit exclusions.
- Update priority users.
- Test incident response.
- Review Microsoft’s recommended settings after product changes.
Common Day-One Mistakes
Assuming Built-in Protection Is the Final Configuration
It is a baseline, not necessarily the correct protection level for the whole organisation.
Building Everything Manually
Custom policies can drift away from Microsoft’s recommendations and become difficult to maintain.
Putting Everyone Into Strict Immediately
This may produce disruption and lead to broad emergency exclusions.
Protecting Only Executives From Impersonation
Finance, payroll and procurement staff are also attractive impersonation targets.
Allowing Users to Release High-Confidence Phishing
The most dangerous messages should remain under administrator control.
Ignoring Teams and Collaboration Files
Threats do not arrive only through Exchange email.
Leaving User Reports Unmonitored
Employees believe they have reported a threat, but nobody acts.
Creating Broad Allow Rules
One exception can undermine several layers of protection.
Ignoring Messages After Delivery
ZAP and investigation capabilities matter because detections change over time.
Never Reviewing Reports
A policy cannot be tuned effectively without operational evidence.
Day-One Configuration Checklist
Protection Baseline
- Assign Standard preset protection to most users.
- Assign Strict preset protection to high-risk users.
- Confirm Built-in protection remains available as a safety net.
- Review policy precedence and exclusions.
Safe Links
- Confirm time-of-click protection.
- Cover email, Teams and supported Office applications.
- Restrict warning bypass where appropriate.
- Minimise exclusions.
Safe Attachments
- Block malicious attachments.
- Review dynamic delivery.
- Protect SharePoint, OneDrive and Teams where available.
- Confirm quarantine and alert behaviour.
Anti-Phishing
- Enable spoof intelligence.
- Enable mailbox intelligence.
- Protect priority users.
- Protect important domains.
- Configure appropriate actions and safety tips.
Post-Delivery Protection
- Keep ZAP enabled.
- Review ZAP actions.
- Confirm how security teams investigate removed messages.
Quarantine
- Define user permissions.
- Keep malware and high-confidence phishing administrator-controlled.
- Configure notifications.
- Test release-request workflows.
Operations
- Enable user reporting.
- Monitor the submissions queue.
- Configure alerts.
- Assign incident owners.
- Review email-security reports.
- Test Threat Explorer investigations where licensed.
Final Thoughts
Microsoft Defender for Office 365 is most effective when organisations use it as a managed security service rather than a collection of default settings.
A strong day-one configuration begins with Microsoft’s preset security policies:
- Standard for most employees
- Strict for high-risk users
- Built-in protection as a minimum safety net
Then verify the operational details:
- Safe Links checks dangerous destinations.
- Safe Attachments analyses suspicious files.
- Anti-phishing policies protect important users and domains.
- Spoof and mailbox intelligence identify deceptive senders.
- ZAP removes threats discovered after delivery.
- Quarantine policies prevent unsafe self-release.
- User reporting feeds a monitored investigation process.
Do not weaken the environment with broad allow lists merely to eliminate support tickets. Investigate why legitimate mail is being blocked, correct its authentication and create only the narrowest necessary exception.
Most importantly, review the configuration regularly. Microsoft updates its protection stack, attackers change tactics and your business continuously adds new users, suppliers and applications.
The best Defender for Office 365 policy is not one that was configured once.
It is one that is actively monitored, tested and maintained.
Need Help Configuring Defender for Office 365?
Hamilton Group can help your business deploy and optimise Microsoft Defender for Office 365.
Our experts can help you:
- Configure Standard and Strict preset security policies
- Protect priority users and important domains
- Deploy Safe Links and Safe Attachments
- Tune anti-phishing and impersonation protection
- Configure quarantine and user reporting
- Review allow lists and mail-flow bypasses
- Set up alerts and investigation processes
- Investigate delivered phishing and malware
- Improve Microsoft Teams and SharePoint protection
- Train employees to report suspicious messages
Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to strengthen your Microsoft 365 email security.