Microsoft certification badges banner
Headshot of Michael Korting

Blog

Microsoft 365 • Security • Compliance

Defender for Office 365 Plan 1: Building a Practical Baseline for Email Protection and Authentication

A practical baseline for preset security policies, anti-phishing, Safe Links, Safe Attachments, operational alerting, and SPF, DKIM, and DMARC.

Introduction

Email remains one of the most common entry points for cyberattacks. Whether the threat is phishing, malware, credential theft, business email compromise (BEC), invoice fraud, or executive impersonation, the attack typically starts with a message arriving in a user's inbox. Organizations often invest heavily in endpoint protection, identity security, and compliance initiatives, yet many tenants still rely on default email configuration and years of accumulated legacy settings.

Microsoft Defender for Office 365 Plan 1 provides a powerful set of protections that can significantly reduce risk when properly configured. However, simply owning the license does not automatically create a secure environment. The real protection comes from implementing a consistent baseline, understanding how Microsoft's recommendation framework works, and ensuring that email authentication standards are properly configured.

When I engage with a new Microsoft 365 customer, one of the first areas I review is their email security posture. In many cases, Defender for Office 365 has been licensed for months or years, but critical features such as impersonation protection, DKIM, and DMARC have never been configured, and Safe Links and Safe Attachments are still running only on Microsoft's minimal Built-in protection defaults. The result is an environment that has paid for advanced protection while still operating much closer to the default Exchange Online experience.

This article covers the baseline configuration approach I typically recommend for organizations using Defender for Office 365 Plan 1. It combines Microsoft's recommended settings with practical deployment considerations gathered from real-world implementations.

Understanding the Foundation

Before diving into configuration, it is important to understand the layers involved.

Exchange Online Protection (EOP)

Exchange Online Protection serves as Microsoft's foundational email filtering platform. Every Microsoft 365 tenant receives EOP protection, and it acts as the first line of defense against:

  • Spam
  • Malware
  • Known malicious senders
  • Bulk email
  • Spoofing attempts
  • Compromised sender activity

Even organizations without Defender for Office 365 rely heavily on EOP for filtering and message hygiene.

Defender for Office 365 Plan 1

Defender for Office 365 Plan 1 extends EOP by adding advanced protections including:

  • Safe Links for email, Microsoft Teams, and Office apps
  • Safe Attachments, including Safe Attachments for SharePoint, OneDrive, and Microsoft Teams
  • Anti-phishing policies with impersonation protection and adjustable phishing email thresholds
  • Real-time detections for investigating email threats
  • User tags, including priority accounts

These capabilities help address modern threats that often bypass traditional filtering mechanisms. Threat Explorer, automated investigation and response (AIR), and Attack simulation training require Plan 2.

Start with Microsoft Preset Security Policies

One of the biggest mistakes administrators make is attempting to build every security policy manually before understanding Microsoft's recommended baseline.

Microsoft provides preset security policies that implement recommended configurations across multiple protection technologies. There are three: Built-in protection, Standard, and Strict. Built-in protection is turned on automatically and provides only basic Safe Links and Safe Attachments coverage. Standard and Strict are the two you assign deliberately.

Standard Protection

The Standard baseline should be considered the absolute minimum for any organization using Defender for Office 365. Its benefits include:

  • Reduced configuration complexity
  • Faster implementation
  • Consistent Microsoft-recommended settings
  • Improved Secure Score alignment
  • Reduced deployment errors
  • Easier ongoing management

Strict Protection

The Strict baseline provides more aggressive enforcement. Its advantages include increased phishing detection, stronger impersonation protections, more aggressive quarantine actions, and better protection for high-value employees.

The potential drawbacks are increased false positives, more quarantine review activity, and greater administrative overhead.

Configuring Impersonation Protection

Business email compromise remains one of the most damaging forms of cyberattack because it targets trust rather than technology.

Attackers frequently impersonate CEOs, presidents, controllers, CFOs, HR managers, and IT leadership. Instead of using malicious links or attachments, these messages may attempt to convince recipients to wire money, purchase gift cards, share confidential information, change payment instructions, or approve fraudulent invoices.

Protected Users

One of the most important Defender configuration tasks is defining protected users. At a minimum, I recommend including:

  • Executive leadership
  • Human Resources leadership
  • Finance management
  • Payroll personnel
  • IT management
  • Department directors

Organizations often underestimate how valuable these protections are until they begin seeing impersonation attempts being quarantined.

Protected Domains

Defender also allows organizations to protect external domains. Examples include banking institutions, payroll providers, strategic suppliers, legal partners, corporate parent organizations, and major customers. These relationships are frequently targeted because users recognize them and may trust messages without hesitation.

Trusted Senders

Trusted senders should be used sparingly. Common use cases include personal email accounts belonging to executives, approved third-party service providers, and automated notification systems.

Anti-Malware Baseline

The anti-malware policy is one of the simplest and most impactful controls, and its key protections are on by default. The task is to confirm they are still in place, especially in older tenants with legacy custom policies.

What to Verify

  • The common attachments filter is on, with the action set to reject the message with a non-delivery report (NDR).
  • The blocked file types list covers executable and script types your organization never needs to receive.
  • Zero-hour auto purge (ZAP) for malware is on.
  • Malware detections use the AdminOnlyAccessPolicy quarantine policy, so only administrators can release them.
  • Unnecessary malware notifications are turned off.

Why This Matters

Modern malware no longer arrives solely as obvious executable files. Common delivery methods include ZIP archives, script files, password-protected attachments, document-based malware, remote access trojans, and ransomware loaders. Blocking dangerous attachment types before delivery reduces risk significantly.

Zero-Hour Auto Purge

One of Microsoft's most valuable capabilities is Zero-Hour Auto Purge. A message that initially appears legitimate may later be identified as malicious by Microsoft's intelligence systems.

ZAP enables Microsoft to detect new threats, remove messages after delivery, reduce dwell time, and protect users who have not yet opened the message. Without ZAP, organizations often rely on manual remediation.

Implementing Effective Anti-Spam Policies

Spam remains more than an annoyance. Modern spam campaigns frequently serve as the first stage of phishing and credential theft attempts.

Inbound Anti-Spam Policy

For the bulk email threshold, Microsoft's Standard value is 6 (the default is 7). Strict uses 5, which removes more unwanted marketing email but also catches more legitimate newsletters and vendor mail, so it fits best on the higher-risk users covered by Strict.

DetectionStandard actionStrict action
SpamMove to Junk EmailQuarantine
High Confidence SpamQuarantineQuarantine
PhishingQuarantineQuarantine
High Confidence PhishingQuarantine (admin-only release)Quarantine (admin-only release)
Bulk EmailMove to Junk EmailQuarantine

Quarantine Retention

Microsoft's Standard and Strict value is 30 days, which is also the maximum (the default is 15). That gives users and administrators enough time to review and release legitimate messages.

Security Features

  • Spam Safety Tips
  • ZAP protection
  • High-confidence filtering
  • User reporting capabilities

Why This Configuration Works

The goal is not to prevent all spam. The goal is to create layers of friction that make malicious messages increasingly difficult to reach end users. A well-designed anti-spam policy dramatically reduces credential harvesting attempts, malicious advertisements, scam messages, and supplier impersonation attacks.

Strengthening Outbound Protection

Inbound security receives most of the attention, but outbound protection is equally important. Compromised accounts often reveal themselves through unusual outbound behavior, such as large outbound message volumes, spam campaigns, external recipient spikes, and unusual sending patterns.

Benefits of Outbound Protection

  • Protect tenant reputation.
  • Prevent domain blocklisting.
  • Detect compromised users.
  • Reduce spam relay activity.
  • Limit account abuse.

Recommended Outbound Settings

Because outbound spam policies aren't part of the presets, configure these in the default outbound spam policy (or a custom one).

  • External message limit: 500 per hour (Strict: 400).
  • Internal message limit: 1,000 per hour (Strict: 800).
  • Daily message limit: 1,000 (Strict: 800).
  • When a user exceeds a limit: restrict the user from sending mail.
  • Automatic forwarding rules: Off. Attackers commonly use forwarding rules to quietly copy mail out of compromised mailboxes, so allow forwarding only for specific users with a documented business need.

Administrative Alerts

Rather than relying on end-user notifications, I strongly recommend directing alerts to security operations, IT administrators, and help desk teams. This creates a centralized response process and improves visibility into suspicious activity.

Enhancing Anti-Phishing Protection

Phishing remains one of the most common threats facing Microsoft 365 users. Modern phishing messages frequently bypass traditional spam detection, use compromised accounts, leverage trusted brands, and mimic internal communications.

Recommended Anti-Phishing Settings

Phishing email threshold: Use 3 (More aggressive) for the Standard baseline and 4 (Most aggressive) for Strict users. The default is 1.

User impersonation: Add executives, finance staff, Human Resources, and IT personnel as protected users, and quarantine detected messages.

Domain impersonation: Include the domains you own, add partner and strategic supplier domains as custom protected domains, and quarantine detected messages.

Mailbox Intelligence

Mailbox Intelligence learns each user's normal communication patterns and frequent contacts. With mailbox intelligence for impersonation turned on, Defender can better tell real contacts from impersonators, which improves detection and reduces false positives. Standard moves these detections to Junk Email; Strict quarantines them.

Spoof Intelligence

Spoof Intelligence helps distinguish legitimate senders from malicious spoofing attempts. Both presets also honor the sender domain's DMARC policy and show the first contact safety tip. Combined with Mailbox Intelligence, these create a significantly stronger detection framework.

Safe Attachments Protection

Traditional antivirus depends on known signatures. The challenge is that attackers constantly develop new techniques.

How Safe Attachments Works

Safe Attachments uses sandbox analysis to detonate files, observe behavior, identify unknown threats, and block malicious content.

Recommended Configuration

  • Confirm Safe Attachments applies to all users (Standard and Strict cover this).
  • Use Block mode.
  • Quarantine detected threats with the AdminOnlyAccessPolicy quarantine policy, so only administrators can release them.
  • Turn on Safe Attachments for SharePoint, OneDrive, and Microsoft Teams. This is a separate global setting that the presets don't control.

Many successful attacks rely on weaponized documents that initially appear benign. Safe Attachments provides a critical layer of protection against zero-day malware, unknown ransomware, malicious Office files, and script-based attacks.

Safe Links Protection

Email filtering evaluates messages at delivery time. However, attackers regularly modify websites after delivery. A harmless URL at 9:00 AM may become malicious by 2:00 PM.

Time-of-Click Protection

Safe Links evaluates URLs when users click rather than only when email is delivered. Benefits include real-time URL analysis, protection against delayed attacks, detection of newly compromised websites, and enhanced visibility into user activity.

Recommended Configuration

  • Turn on time-of-click URL checking for email.
  • Apply Safe Links to messages sent within the organization.
  • Apply real-time URL scanning, and wait for scanning to complete before delivering the message.
  • Keep URL rewriting on (leave "Do not rewrite URLs" cleared).
  • Track user clicks.
  • Turn off "Let users click through to the original URL."
  • Turn on Safe Links for Microsoft Teams and Office apps.

Built-in protection lets users click through warnings and doesn't scan internal messages, which is why tenants relying only on it remain exposed.

Improving Operations Through Alert Policies

Security controls are only effective when organizations can respond appropriately. One frequently overlooked configuration area is alerting.

User Restricted from Sending Email

The built-in User restricted from sending email alert policy notifies Global Administrators by default when a user is blocked for exceeding outbound limits. Microsoft recommends using this alert rather than the notification settings in the outbound spam policy. I recommend adding the Help Desk, Service Desk, Security Team, and appropriate shared support mailboxes as recipients.

This integration creates a more structured incident response workflow for compromised accounts, outbound spam campaigns, policy violations, and sending restrictions. Proper alert routing often reduces remediation time significantly.

Implementing Email Authentication Standards

Email authentication is foundational to modern email security. Without SPF, DKIM, and DMARC, organizations become significantly more susceptible to spoofing attacks.

SPF (Sender Policy Framework)

SPF identifies authorized sending systems. A basic Microsoft-only SPF record resembles:

v=spf1 include:spf.protection.outlook.com -all

DKIM (DomainKeys Identified Mail)

DKIM cryptographically signs outgoing email. Benefits include message integrity validation, reduced spoofing risk, improved sender reputation, and stronger DMARC alignment.

The deployment process is generally straightforward:

  1. In the Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings, and open the DKIM tab.
  2. Select the custom domain and copy the two CNAME records Microsoft generates (selector1 and selector2).
  3. Publish both CNAME records at your DNS host.
  4. Allow time for the DNS changes to propagate.
  5. Enable DKIM signing for the domain.

Once enabled, outbound messages from the domain will be digitally signed. Until then, mail from a custom domain isn't DKIM-signed by that domain, so DKIM can't pass DMARC for it. Domains added since May 2025 use a newer CNAME format ending in dkim.mail.microsoft, so always copy the values from the portal rather than from older guides.

DMARC (Domain-based Message Authentication, Reporting, and Conformance)

DMARC builds upon SPF and DKIM. It provides policy enforcement, reporting, alignment validation, and spoofing prevention.

Starting Point

Microsoft recommends starting in monitoring mode, with aggregate reports sent to a dedicated mailbox. The record is published as a TXT record at _dmarc.yourdomain:

v=DMARC1; p=none; rua=mailto:[email protected]

This record doesn't change delivery. The reports show every service sending mail as your domain, so you can fix SPF and DKIM for legitimate senders before enforcing. Review them weekly during the rollout.

Moving to Enforcement

Once the reports show legitimate mail passing, move to quarantine. You can use pct to phase it in (for example 10, 25, 50, then 100):

v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected]
Long-Term Goal

Once all legitimate senders are validated, organizations can work toward:

v=DMARC1; p=reject; rua=mailto:[email protected]

This can provide significantly stronger protection. Without DMARC enforcement, attackers can send mail that uses your exact domain in the From address, making messages that appear to come from executives or finance staff look legitimate. DMARC doesn't stop display-name tricks or lookalike domains; that is the job of impersonation protection.

Also publish v=DMARC1; p=reject for domains that never send mail, including your *.onmicrosoft.com domain if you don't use it for email (that record is added in the Microsoft 365 admin center).

Validate Everything with the Defender Configuration Analyzer

One of my favorite Defender tools remains the Configuration Analyzer. It compares your custom and default threat policies against the Standard and Strict preset settings and flags anything less secure. It doesn't analyze the preset policies themselves, since those already match Microsoft's recommendations.

The analyzer can identify configuration gaps, highlight weak settings, recommend improvements, and check whether DKIM is configured for your domains. It also complements Microsoft Secure Score, security reviews, tenant assessments, and compliance initiatives.

My Recommended Deployment Strategy

For customers implementing Defender for Office 365 Plan 1, I usually recommend a phased rollout.

Phase 1: Establish the Foundation

  • Turn on Standard preset protection for all recipients.
  • Apply Strict preset protection to high-risk users.
  • Configure SPF.
  • Enable DKIM.
  • Publish DMARC with p=none and reporting.

Phase 2: Complete Advanced Protections

  • Add protected users and domains for impersonation protection.
  • Set outbound spam limits and turn off automatic forwarding.
  • Turn on Safe Attachments for SharePoint, OneDrive, and Teams.
  • Confirm Safe Links and Safe Attachments apply to everyone.

Phase 3: Operational Review

  • Monitor quarantine activity.
  • Review user feedback.
  • Adjust trusted senders.
  • Tune policies as necessary.

Phase 4: Optimization

  • Run Configuration Analyzer.
  • Review Secure Score.
  • Move DMARC to quarantine, then reject.
  • Expand Strict and protected domain coverage as needed.

Final Thoughts

Defender for Office 365 Plan 1 provides an impressive collection of capabilities that can dramatically reduce organizational risk when properly configured. The challenge is rarely licensing. The challenge is implementation.

Organizations that simply turn on email services and accept default settings often remain vulnerable to phishing, impersonation, malware delivery, and business email compromise attacks. In contrast, organizations that establish a well-defined baseline gain the benefits of Microsoft's threat intelligence, modern phishing protection, advanced attachment analysis, and email authentication standards.

My recommendation is simple: start with Microsoft's Standard preset for everyone and Strict for high-risk users, add impersonation entries, implement SPF, DKIM, and DMARC, and then continuously improve through Secure Score and the Defender Configuration Analyzer. This approach creates a strong security foundation without overwhelming users or administrators.

Email will continue to be a primary attack vector for years to come. A properly configured Defender for Office 365 Plan 1 deployment ensures that your organization is prepared to meet that challenge with a modern, layered defense strategy.

References