3rd party security tools for Exchange Online

crib bar 841 Reputation points
2024-01-11T08:30:07.1133333+00:00

Is it still common practice to have to invest in a 3rd party security tool for protecting Exchange Online data/users, or are the anti-malware/anti-spam/anti-phishing features available within Exchange Online Protection (EOP) generally seen as sufficient without requiring additional investment in 3rd party commercial tools. If there is a requirement to look into additional 3rd party security for an exchange online instance, any recommendations on good products would be useful. Secondly, are the security features & rules in Exchange Online Protection (EOP) configurable/customisable to each customer, or are they an out-of-the-box set of protections that cannot be readily altered?

Microsoft Exchange Online
Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,444 questions
Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,745 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
680 questions
0 comments No comments
{count} votes

Accepted answer
  1. Kael Yao-MSFT 37,696 Reputation points Microsoft Vendor
    2024-01-12T01:49:02.6333333+00:00

    Hi @crib bar

    Please kindly note that due to policy, we cannot make recommendations of third-party products for you.

    In this case I would suggest we mainly focus on EOP and its features.

    Thanks for your understanding.


    For features in EOP please refer to this link:

    Exchange Online Protection overview

    If the main purpose to prevent your organization from malware, spam and phishing, EOP is a powerful product for that.

    Secondly, are the security features & rules in Exchange Online Protection (EOP) configurable/customisable to each customer, or are they an out-of-the-box set of protections that cannot be readily altered?

    Most features you can see in the Microsoft Defender portal are customizable.

    Let's take anti-spam policies for example.

    Direct link to the page (require admin permission): https://security.microsoft.com/antispam

    We can see there are three default policies: 01

    Anti-spam inbound policy applies to inbound emails to your organization.

    Connection filter policy checks the senders' reputation to determine if the sender sends spam messages.

    Anti-spam outbound policy applies to outbound emails to external sent from your organization.

    These default policies are all customizable and by default applied to all users in your organization.

    You can also create new policies which override the default policies.

    For example, you can create a new inbound anti-spam policy with stricter criteria and apply it to specific users to offer them better protection from spam.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".  Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.