Introduction
Email is still one of the easiest ways for attackers to get into an organization. Phishing, business email compromise, malicious attachments, credential theft, and impersonation attacks continue to evolve faster than traditional spam filtering can keep up.
Microsoft Defender for Office 365 adds advanced protection on top of Exchange Online Protection, including Safe Links, Safe Attachments, anti-phishing controls, investigation tools, automation, and reporting. In Microsoft 365 tenant assessments, the licensing question comes up constantly:
The answer is no longer just a feature comparison. It now depends on licensing, operational maturity, security staffing, compliance needs, and how much investigation capability the organization truly needs.
What Is Defender for Office 365?
Microsoft Defender for Office 365 builds on Exchange Online Protection, the native email hygiene service included with Exchange Online.
Exchange Online Protection provides:
- Anti-spam filtering
- Anti-malware protection
- Connection filtering
- Transport rules
- Basic spoof detection
- Mail flow protection
Defender for Office 365 adds protection layers needed for more modern email threats, including Safe Attachments, Safe Links, anti-phishing protection, impersonation detection, real-time detonation analysis, Threat Explorer, automated investigation and response, and Attack Simulation Training.
The Defender platform also aligns closely with Secure Score recommendations and Microsoft security baselines. In practical assessments, the biggest gains often come from enabling Safe Attachments, Safe Links, anti-phishing policies, impersonation protection, and foundational authentication controls such as SPF, DKIM, and DMARC.
Defender for Office 365 Plan 1
Plan 1 is the preventative protection tier. It is aimed at organizations that need strong phishing, malware, URL, attachment, and impersonation controls but do not need full threat hunting, automated investigation, or attack simulation capabilities. Since the July 2026 licensing changes, Plan 1 is now part of Microsoft 365 E3 and Office 365 E3, making deployment and configuration the real priority for many E3 tenants.
Safe Attachments
Safe Attachments detonates suspicious files in a secure environment before users interact with them. Suspicious files can be blocked, quarantined, replaced, or monitored. For most tenants, Safe Attachments should be more than licensed; it should be enforced. Block mode and appropriate quarantine settings can prevent malicious files from ever reaching end users.
Safe Links
Safe Links protects users when they click URLs in email and supported Office content. URLs are checked in real time, malicious sites can be blocked, and users can receive warning messages before proceeding. This is especially useful against phishing sites that appear after the original message is delivered.
Anti-Phishing Protection
Plan 1 includes user and domain impersonation detection, mailbox intelligence, spoof intelligence, and phishing safety tips. High-value targets such as executives, finance, HR, administrators, and help desk teams should be protected explicitly.
Preset Security Policies
Preset security policies are one of the fastest ways to raise the baseline. Standard should generally be treated as the minimum modern baseline. Strict provides more aggressive filtering and phishing controls for organizations that can support stronger enforcement.
Defender for Office 365 Plan 2
Plan 2 includes Plan 1 and adds the tools security teams need to investigate, respond, hunt, train, and report at a deeper level. This is where Defender for Office 365 becomes less about prevention alone and more about security operations.
Threat Explorer
Threat Explorer gives analysts deeper visibility into email-borne threats across the tenant. Security teams can search messages, analyze phishing campaigns, investigate malware detections, review delivery actions, and track impacted users.
Automated Investigation and Response
Automated investigation and response can investigate suspicious activity, examine related indicators, identify compromised content, and recommend remediation actions. For lean security teams, this automation can reduce the manual work required to triage routine incidents.
Attack Simulation Training
Attack Simulation Training is one of the strongest Plan 2 differentiators because it brings phishing simulation and user training directly into the Microsoft Defender portal. If Defender for Office 365 Plan 2 is already licensed, Attack Simulation Training should be evaluated before renewing or expanding a separate phishing simulation subscription.
The value is not just licensing consolidation. Attack Simulation Training is connected to the Microsoft security ecosystem that already handles email protection, detections, reporting, user risk context, and remediation workflows.
Microsoft also supports training campaigns, simulation automations, payload libraries, and payload automations. Organizations can run one-time simulations, assign training, automate recurring exercises, and use payloads based on real-world attack patterns observed in the tenant.
Campaign Views
Campaign analysis groups related messages so security teams can investigate the broader attack, not just individual emails. Security teams can review attack origin, delivery patterns, impersonated users, and impacted recipients.
Threat Trackers
Threat Trackers provide intelligence about emerging attack campaigns, active phishing trends, industry-wide threats, and Microsoft threat research.
Side-by-Side Comparison
| Feature | Plan 1 | Plan 2 |
|---|---|---|
| Safe Attachments | Yes | Yes |
| Safe Links | Yes | Yes |
| Anti-Phishing Protection | Yes | Yes |
| Impersonation Protection | Yes | Yes |
| Preset Security Policies | Yes | Yes |
| Threat Explorer | No | Yes |
| Campaign Views | No | Yes |
| Attack Simulation Training | No | Yes |
| Automated Investigation and Response | No | Yes |
| Threat Trackers | No | Yes |
| Advanced Hunting Capabilities | No | Yes |
Which License Is Right for Your Organization?
Plan 1 Is Often Sufficient When:
- The organization is small to mid-sized
- Security operations are outsourced
- Compliance requirements are moderate
- Security staffing is limited
- Budget constraints are significant
Plan 1 is a major step up from EOP-only protection, especially now that it is included with E3 suites. For E3 customers, the immediate priority should be validation: confirm Plan 1 entitlement, enable the core policies, review quarantine behavior, protect high-value users, and monitor detections.
Plan 2 Is Recommended When:
- Regulatory requirements are strict
- Security incidents must be investigated rapidly
- A dedicated security team exists
- Threat hunting is required
- Security automation is a priority
- Executive impersonation attacks are a common concern
- The organization is evaluating consolidation of a separate phishing simulation or awareness platform
Do Not Forget Email Authentication
Licensing matters, but it does not replace proper email authentication. Three technologies should be deployed together:
- SPF: validates authorized mail servers.
- DKIM: digitally signs messages to verify authenticity.
- DMARC: tells receiving systems how to handle authentication failures.
Lessons Learned from Real-World Deployments
- Standard security presets are frequently disabled or partially configured.
- Safe Links and Safe Attachments are often licensed but not deployed.
- Executive impersonation protection is commonly overlooked.
- SPF, DKIM, and DMARC are frequently incomplete.
- Organizations purchase Plan 2 but never use Attack Simulation Training, even while paying separately for third-party phishing simulation tools.
- Security awareness programs are often disconnected from the email security telemetry used by the operations team.
The biggest security gains often come from fully deploying and operationalizing what the organization already owns.
Final Thoughts
Defender for Office 365 is now a core part of the Microsoft 365 security conversation, especially for E3 customers. After the July 2026 licensing update, many Microsoft 365 E3 and Office 365 E3 tenants now have Plan 1 protections included. That makes configuration the key question: are Safe Links, Safe Attachments, anti-phishing policies, impersonation protection, and authentication controls actually deployed and monitored?
Plan 2 is still the right conversation for organizations that need deeper investigations, automated response, attack simulation, and stronger security operations workflows. It is also worth a serious look when an organization already owns or is considering a standalone phishing simulation platform.
The license matters, but the outcome depends on execution. Security improves when the capabilities are enabled, tuned, reviewed, and used.
References
Core Microsoft Defender for Office 365 Resources
- Microsoft Defender for Office 365 Documentation
- Recommended Settings for EOP and Defender for Office 365
- Microsoft Defender for Office 365 Service Description
- Microsoft Defender for Office 365 Product Page