{"items":[{"children":[{"children":[{"href":"mdo-about","toc_title":"Microsoft Defender for Office 365 overview"},{"href":"eop-about","toc_title":"Overview of the built-in security features for all cloud mailboxes"},{"href":"defender-for-office-365-whats-new","toc_title":"What\u0027s new in Defender for Office 365"},{"href":"mdo-gov","toc_title":"Microsoft Defender for Office 365 for US Government customers"}],"toc_title":"Overview"},{"children":[{"href":"mdo-deployment-guide","toc_title":"Get started with Microsoft Defender for Office 365"},{"href":"protection-stack-microsoft-defender-for-office365","toc_title":"How threat protection works in Defender for Office 365"},{"href":"how-policies-and-protections-are-combined","toc_title":"How policies and protections are combined"},{"href":"secure-by-default","toc_title":"Secure by default"},{"href":"zero-trust-with-microsoft-365-defender-office-365","toc_title":"Zero Trust for Defender for Office 365"},{"href":"mail-flow-about","toc_title":"Mail flow in cloud organizations"},{"href":"mdo-support-teams-about","toc_title":"Defender for Office 365 in Microsoft Teams"},{"href":"/defender-xdr/microsoft-365-defender-portal","toc_title":"Microsoft Defender portal overview"},{"href":"mdo-integrate-security-service","toc_title":"Integrate non-Microsoft security services with Microsoft 365"}],"toc_title":"Get started"},{"children":[{"href":"try-microsoft-defender-for-office-365","toc_title":"Try Defender for Office 365"},{"href":"trial-user-guide-defender-for-office-365","toc_title":"Trial User Guide for Defender for Office 365"}],"toc_title":"Evaluate"},{"children":[{"href":"/defender-xdr/pilot-deploy-defender-office-365?toc=/defender-office-365/TOC.json\u0026bc=/defender-office-365/breadcrumb/toc.json","toc_title":"Pilot and deploy Defender for Office 365"},{"href":"mdo-deployment-guide","toc_title":"Get started with Microsoft Defender for Office 365"},{"children":[{"href":"email-authentication-about","toc_title":"About email authentication"},{"href":"email-authentication-spf-configure","toc_title":"Set up SPF"},{"href":"email-authentication-dkim-configure","toc_title":"Set up DKIM"},{"href":"email-authentication-dmarc-configure","toc_title":"Set up DMARC"},{"href":"email-authentication-arc-configure","toc_title":"Configure trusted ARC sealers"},{"href":"email-authentication-troubleshoot","toc_title":"Troubleshoot email authentication"}],"toc_title":"Step 1 - Configure email authentication"},{"children":[{"href":"preset-security-policies","toc_title":"Preset security policies"},{"href":"recommended-settings-for-eop-and-office365","toc_title":"Recommended email and collaboration threat policy settings for cloud organizations"},{"href":"mdo-support-teams-quick-configure","toc_title":"Quickly configure Microsoft Teams protection"}],"toc_title":"Step 2 - Configure threat policies"},{"children":[{"href":"mdo-portal-permissions","toc_title":"Defender for Office 365 permissions"},{"href":"defender-office-365-unified-rbac-permissions","toc_title":"Unified RBAC permissions for Defender for Office 365"},{"href":"scc-permissions","toc_title":"Permissions - Defender for Office 365 and Microsoft Purview"},{"href":"/defender-xdr/manage-rbac","toc_title":"Microsoft Defender XDR RBAC"}],"toc_title":"Step 3 - Assign permissions"},{"children":[{"href":"/microsoft-365/admin/setup/priority-accounts","toc_title":"Manage and monitor priority accounts"},{"href":"user-tags-about","toc_title":"User tags in Defender for Office 365"},{"href":"priority-accounts-turn-on-priority-account-protection","toc_title":"Configure and review priority account protection"}],"toc_title":"Step 4 - Apply priority account tags and user tags"},{"children":[{"href":"submissions-user-reported-messages-custom-mailbox","toc_title":"Email - user reported settings"},{"href":"submissions-users-report-message-add-in-configure","toc_title":"Transition from the Report Message and Report Phishing add-ins"},{"href":"submissions-teams","toc_title":"Teams - user reported settings"}],"toc_title":"Step 5 - Configure user reported settings"},{"children":[{"href":"tenant-allow-block-list-about","toc_title":"Manage the Tenant Allow/Block List"},{"href":"submissions-admin","toc_title":"Admin submissions"}],"toc_title":"Step 6 - Block and allow"},{"children":[{"href":"attack-simulation-training-get-started","toc_title":"Get started using Attack simulation training"}],"toc_title":"Step 7 - Launch phishing simulations using Attack simulation training"},{"children":[{"href":"mdo-sec-ops-guide","toc_title":"Defender for Office 365 SecOps guide"}],"toc_title":"Step 8 - Protect, detect, and respond"}],"toc_title":"Deploy"},{"children":[{"href":"migrate-to-defender-for-office-365","toc_title":"Migrate to Defender for Office 365"},{"href":"migrate-to-defender-for-office-365-prepare","toc_title":"Step 1 - Prepare"},{"href":"migrate-to-defender-for-office-365-setup","toc_title":"Step 2 - Setup"},{"href":"migrate-to-defender-for-office-365-onboard","toc_title":"Step 3 - Onboard"}],"toc_title":"Migrate"},{"children":[{"href":"mdo-sec-ops-guide","toc_title":"Defender for Office 365 SecOps Guide"},{"href":"mdo-support-teams-sec-ops-guide","toc_title":"SecOps guide for Teams protection in Defender for Office 365"},{"href":"email-auth-sec-ops-guide","toc_title":"SecOps guide for email authentication in Microsoft 365"},{"href":"mdo-threat-classification","toc_title":"Threat classification"},{"href":"priority-accounts-security-recommendations","toc_title":"Security recommendations for priority accounts"},{"href":"mdo-usage-card-about","toc_title":"Usage card in Defender for Office 365"},{"children":[{"href":"preset-security-policies","toc_title":"Preset security policies"},{"href":"recommended-settings-for-eop-and-office365","toc_title":"Recommended email and collaboration threat policy settings for cloud organizations"},{"href":"configuration-analyzer-for-security-policies","toc_title":"Configuration analyzer for threat policies"},{"children":[{"href":"anti-malware-protection-about","toc_title":"Anti-malware protection"},{"href":"anti-malware-policies-configure","toc_title":"Configure anti-malware policies"},{"href":"anti-malware-protection-faq","toc_title":"Anti-malware protection FAQ"},{"href":"zero-hour-auto-purge","toc_title":"Zero-hour auto purge (ZAP)"},{"href":"anti-malware-protection-for-spo-odfb-teams-about","toc_title":"Virus detection in SharePoint"}],"toc_title":"Anti-malware in cloud organizations"},{"children":[{"href":"anti-spam-protection-about","toc_title":"Anti-spam protection"},{"href":"anti-spam-policies-configure","toc_title":"Configure anti-spam policies"},{"href":"anti-spam-policies-troubleshooting","toc_title":"Troubleshoot anti-spam policy issues"},{"href":"anti-spam-policies-asf-settings-about","toc_title":"Advanced Spam Filter (ASF) settings"},{"href":"anti-spam-spam-vs-bulk-about","toc_title":"What\u0027s the difference between junk email and bulk email?"},{"href":"anti-spam-spam-confidence-level-scl-about","toc_title":"Spam confidence level (SCL)"},{"href":"anti-spam-bulk-complaint-level-bcl-about","toc_title":"Bulk email detection and bulk complaint level (BCL)"},{"href":"anti-spam-bulk-senders-insight","toc_title":"Bulk senders insight"},{"href":"anti-spam-backscatter-about","toc_title":"Backscatter messages cloud organizations"},{"href":"configure-junk-email-settings-on-exo-mailboxes","toc_title":"Configure junk email settings on Exchange Online mailboxes"},{"href":"anti-spam-protection-faq","toc_title":"Anti-spam protection FAQ"},{"href":"zero-hour-auto-purge","toc_title":"Zero-hour auto purge (ZAP)"},{"href":"/exchange/standalone-eop/configure-eop-spam-protection-hybrid","toc_title":"Deliver cloud-detected spam to the Junk Email folder in on-premises mailboxes"}],"toc_title":"Anti-spam in cloud organizations"},{"children":[{"href":"anti-phishing-protection-about","toc_title":"Anti-phishing protection"},{"href":"anti-phishing-policies-about","toc_title":"Anti-phishing policies"},{"href":"anti-phishing-policies-eop-configure","toc_title":"Configure anti-phishing policies for all cloud mailboxes"},{"href":"anti-phishing-policies-mdo-configure","toc_title":"Configure anti-phishing policies in Defender for Office 365"},{"href":"anti-phishing-protection-spoofing-about","toc_title":"Anti-spoofing protection"},{"href":"anti-phishing-protection-spoofing-faq","toc_title":"Anti-spoofing protection FAQ"},{"href":"anti-phishing-from-email-address-validation","toc_title":"How Microsoft 365 validates the From address"},{"href":"anti-phishing-protection-tuning","toc_title":"Tune anti-phishing protection"},{"href":"anti-spoofing-spoof-intelligence","toc_title":"Spoof intelligence insight"},{"href":"anti-phishing-mdo-impersonation-insight","toc_title":"Impersonation insight"}],"toc_title":"Anti-phishing for all cloud mailboxes and Defender for Office 365"},{"children":[{"href":"safe-attachments-about","toc_title":"Safe Attachments in Defender for Office 365"},{"href":"safe-attachments-policies-configure","toc_title":"Set up Safe Attachments policies in Defender for Office 365"},{"href":"safe-attachments-for-spo-odfb-teams-about","toc_title":"Safe Attachments for SharePoint, OneDrive, and Microsoft Teams"},{"href":"safe-attachments-for-spo-odfb-teams-configure","toc_title":"Turn on Safe Attachments for SharePoint, OneDrive, and Microsoft Teams"}],"toc_title":"Safe Attachments in Defender for Office 365"},{"children":[{"href":"safe-links-about","toc_title":"Safe Links in Defender for Office 365"},{"href":"safe-links-policies-configure","toc_title":"Set up Safe Links policies in Defender for Office 365"}],"toc_title":"Safe Links in Defender for Office 365"},{"children":[{"href":"outbound-spam-protection-about","toc_title":"Outbound spam protection"},{"href":"outbound-spam-policies-configure","toc_title":"Configure outbound spam policies"},{"href":"outbound-spam-policies-external-email-forwarding","toc_title":"Control automatic external email forwarding"},{"href":"outbound-spam-high-risk-delivery-pool-about","toc_title":"Outbound delivery pools"},{"href":"outbound-spam-restore-restricted-users","toc_title":"Restore restricted users"},{"href":"outbound-spam-sending-limits-troubleshoot","toc_title":"Troubleshoot outbound sending limits"}],"toc_title":"Outbound spam protection in cloud organizations"},{"children":[{"href":"connection-filter-policies-configure","toc_title":"Configure the connection filtering policy"}],"toc_title":"Connection filtering in cloud organizations"}],"toc_title":"Threat policies"},{"children":[{"href":"audit-log-search-defender-portal","toc_title":"Search the audit log"}],"toc_title":"Audit log search"},{"children":[{"href":"advanced-delivery-policy-configure","toc_title":"Configure SecOps mailboxes and phishing simulation URLs"}],"toc_title":"Advanced delivery policy"},{"children":[{"href":"alert-policies-defender-portal","toc_title":"Alert policies"}],"toc_title":"Alert policies"},{"children":[{"children":[{"href":"tenant-allow-block-list-about","toc_title":"About the Tenant Allow/Block List"},{"href":"tenant-allow-block-list-email-spoof-configure","toc_title":"Allow or block email using the Tenant Allow/Block List"},{"href":"tenant-allow-block-list-files-configure","toc_title":"Allow or block files using the Tenant Allow/Block List"},{"href":"tenant-allow-block-list-urls-configure","toc_title":"Allow or block URLs using the Tenant Allow/Block List"},{"href":"tenant-allow-block-list-ip-addresses-configure","toc_title":"Allow or block IPv6 addresses using the Tenant Allow/Block List"},{"href":"tenant-allow-block-list-teams-domains-configure","toc_title":"Block domains in Microsoft Teams using the Tenant Allow/Block List"}],"toc_title":"Tenant Allow/Block List"},{"href":"submissions-admin","toc_title":"Admin submissions"},{"href":"create-block-sender-lists-in-office-365","toc_title":"Create block sender lists"},{"href":"create-safe-sender-lists-in-office-365","toc_title":"Create safe sender lists"}],"toc_title":"Allow and block"},{"children":[{"href":"attack-simulation-training-get-started","toc_title":"Get started using Attack simulation training"},{"href":"attack-simulation-training-simulations","toc_title":"Simulate a phishing attack with Attack simulation training"},{"href":"attack-simulation-training-simulation-automations","toc_title":"Simulation automations in Attack simulation training"},{"href":"attack-simulation-training-payload-automations","toc_title":"Payload automations in Attack simulation training"},{"href":"attack-simulation-training-end-user-notifications","toc_title":"End-user notifications for Attack simulation training"},{"href":"attack-simulation-training-login-pages","toc_title":"Login pages in Attack simulation training"},{"href":"attack-simulation-training-payloads","toc_title":"Payloads in Attack simulation training"},{"href":"attack-simulation-training-landing-pages","toc_title":"Landing pages in Attack simulation training"},{"href":"attack-simulation-training-training-campaigns","toc_title":"Training campaigns in Attack simulation training"},{"href":"attack-simulation-training-training-modules","toc_title":"Training modules in Attack simulation training"},{"href":"attack-simulation-training-insights","toc_title":"Insights and reporting in Attack simulation training"},{"href":"attack-simulation-training-settings","toc_title":"Global settings in Attack simulation training"},{"href":"attack-simulation-training-faq","toc_title":"Attack simulation training deployment considerations and FAQ"}],"toc_title":"Attack simulation training in Defender for Office 365"},{"children":[{"href":"/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/use-connectors-to-configure-mail-flow","toc_title":"Configure mail flow using connectors"},{"href":"connectors-detect-respond-to-compromise","toc_title":"Respond to a compromised connector"},{"href":"connectors-remove-blocked","toc_title":"Remove blocked connectors"}],"toc_title":"Connectors for mail flow"},{"children":[{"href":"delegated-administration-faq","toc_title":"Delegated administration FAQ"}],"toc_title":"Delegated administration"},{"children":[{"href":"/exchange/security-and-compliance/mail-flow-rules/mail-flow-rules","toc_title":"About mail flow rules"},{"href":"/exchange/security-and-compliance/mail-flow-rules/conditions-and-exceptions","toc_title":"Mail flow rule conditions and exceptions"},{"href":"/exchange/security-and-compliance/mail-flow-rules/mail-flow-rule-actions","toc_title":"Mail flow rule actions"},{"href":"/exchange/security-and-compliance/mail-flow-rules/manage-mail-flow-rules","toc_title":"Manage mail flow rules"},{"href":"/exchange/security-and-compliance/mail-flow-rules/configuration-best-practices","toc_title":"Mail flow rule configuration best practices"},{"href":"/exchange/security-and-compliance/mail-flow-rules/test-mail-flow-rules","toc_title":"Test mail flow rules"},{"children":[{"href":"/exchange/security-and-compliance/mail-flow-rules/mail-flow-rule-procedures","toc_title":"Mail flow rule procedures"},{"href":"/exchange/security-and-compliance/mail-flow-rules/use-rules-to-set-scl","toc_title":"Use rules to set the SCL"},{"href":"/exchange/security-and-compliance/mail-flow-rules/common-attachment-blocking-scenarios","toc_title":"Use rules for attachment blocking scenarios"},{"href":"/exchange/security-and-compliance/mail-flow-rules/use-rules-to-block-executable-attachments","toc_title":"Use rules to block messages with executable attachments"},{"href":"/exchange/security-and-compliance/mail-flow-rules/inspect-message-attachments","toc_title":"Use rules to inspect message attachments"},{"href":"/exchange/security-and-compliance/mail-flow-rules/use-rules-to-filter-bulk-mail","toc_title":"Use mail flow rules to filter bulk mail"}],"toc_title":"Mail flow rule procedures"}],"toc_title":"Exchange mail flow rules (transport rules)"},{"children":[{"href":"message-trace-defender-portal","toc_title":"Message trace"}],"toc_title":"Message trace"},{"children":[{"href":"quarantine-about","toc_title":"Quarantine"},{"href":"quarantine-admin-manage-messages-files","toc_title":"Admin quarantine"},{"href":"quarantine-end-user","toc_title":"End-user quarantine"},{"href":"quarantine-policies","toc_title":"Quarantine policies"},{"href":"quarantine-shared-mailbox-messages","toc_title":"Release quarantined messages from shared mailboxes"},{"href":"quarantine-quarantine-notifications","toc_title":"Quarantine notifications"},{"href":"quarantine-faq","toc_title":"Quarantine FAQ"}],"toc_title":"Quarantine"},{"children":[{"href":"reports-email-security","toc_title":"Email security reports"},{"href":"reports-defender-for-office-365","toc_title":"Defender for Office 365 reports"},{"href":"reports-mdo-email-collaboration-dashboard","toc_title":"Defender for Office 365 Overview dashboard"}],"toc_title":"Reports"},{"href":"safe-documents-in-e5-plus-security-about","toc_title":"Safe Documents in Microsoft 365 A5/E5/G5 or Microsoft Defender Suite"}],"toc_title":"Protect and Detect"},{"children":[{"href":"mdo-sec-ops-manage-incidents-and-alerts","toc_title":"Manage incidents and alerts in Microsoft Defender XDR"},{"href":"office-365-ti","toc_title":"How threat investigation and response works"},{"href":"mdo-sec-ops-guide","toc_title":"Defender for Office 365 SecOps Guide"},{"href":"mdo-support-teams-sec-ops-guide","toc_title":"SecOps guide for Teams protection in Defender for Office 365"},{"children":[{"href":"campaigns","toc_title":"Campaign Views"},{"children":[{"href":"submissions-report-messages-files-to-microsoft","toc_title":"Report suspicious email, Teams messages, or files to Microsoft"},{"href":"submissions-admin","toc_title":"Admin submissions"},{"href":"submissions-users-report-message-add-in-configure","toc_title":"Transition from the Report Message and Report Phishing add-ins"},{"href":"submissions-outlook-report-messages","toc_title":"Report phishing and suspicious emails in Outlook for admins"},{"href":"submissions-user-reported-messages-custom-mailbox","toc_title":"User reported settings"},{"href":"submissions-teams","toc_title":"User reported message settings in Teams"},{"href":"submissions-submit-files-to-microsoft","toc_title":"Submit malware and non-malware to Microsoft"},{"href":"submissions-admin-review-user-reported-messages","toc_title":"Admin review for user reported messages"},{"href":"submissions-result-definitions","toc_title":"Submission result definitions"}],"toc_title":"Report suspicious messages and files"},{"children":[{"href":"threat-explorer-real-time-detections-about","toc_title":"About Threat Explorer and Real-time detections"},{"href":"threat-explorer-threat-hunting","toc_title":"Threat hunting in Threat Explorer and Real-time detections"},{"href":"threat-explorer-email-security","toc_title":"Email security with Threat Explorer and Real-time detections"},{"href":"threat-explorer-investigate-delivered-malicious-email","toc_title":"Investigate delivered malicious email with Threat Explorer and Real-time detections"},{"href":"mdo-email-entity-page","toc_title":"Email entity page"},{"href":"teams-message-entity-panel","toc_title":"Teams message entity panel"}],"toc_title":"Threat Explorer and real-time detections"},{"children":[{"href":"anti-spam-bulk-senders-insight","toc_title":"Bulk senders insight"},{"href":"anti-spoofing-spoof-intelligence","toc_title":"Spoof intelligence insight"},{"href":"anti-phishing-mdo-impersonation-insight","toc_title":"Impersonation insight"}],"toc_title":"Insights"},{"href":"audit-log-search-defender-portal","toc_title":"Search the audit log"},{"children":[{"href":"reports-email-security","toc_title":"Email security reports"},{"href":"reports-defender-for-office-365","toc_title":"Defender for Office 365 reports"}],"toc_title":"Reports"},{"children":[{"href":"message-trace-defender-portal","toc_title":"Message trace"}],"toc_title":"Message trace"},{"children":[{"href":"threat-trackers","toc_title":"Threat trackers"}],"toc_title":"Threat Trackers"}],"toc_title":"Analyze and classify"},{"children":[{"href":"siem-server-integration","toc_title":"SIEM server integration"},{"href":"siem-integration-with-office-365-ti","toc_title":"SIEM threat intelligence integration"}],"toc_title":"SIEM server integration"},{"children":[{"href":"responding-to-a-compromised-email-account","toc_title":"Responding to a Compromised Email Account in Office 365"},{"href":"remediate-malicious-email-delivered-office-365","toc_title":"Remediate malicious email"},{"children":[{"children":[{"href":"air-about","toc_title":"AIR overview"},{"href":"air-examples","toc_title":"AIR examples"}],"toc_title":"AIR overview and permissions"},{"href":"air-review-approve-pending-completed-actions","toc_title":"Review and approve (or reject) pending actions"},{"href":"air-report-false-positives-negatives","toc_title":"Manage false positives and false negatives in AIR"},{"href":"air-view-investigation-results","toc_title":"View details and results of an automated investigation"},{"href":"air-user-automatic-feedback-response","toc_title":"Automatic user notifications for user reported phishing results"},{"children":[{"href":"air-remediation-actions","toc_title":"Remediation actions"},{"href":"air-review-approve-pending-completed-actions","toc_title":"Review and approve (or reject) pending actions"},{"href":"air-auto-remediation","toc_title":"Automated remediation in AIR"}],"toc_title":"Remediation in AIR"},{"href":"address-compromised-users-quickly","toc_title":"Detect and address compromised user accounts in AIR"},{"href":"air-custom-reporting","toc_title":"Integrate AIR with a custom solution or non-Microsoft solution"},{"href":"email-analysis-investigations","toc_title":"Email analysis in investigations"}],"toc_title":"Automated Investigation and Response (AIR)"},{"href":"detect-and-remediate-illicit-consent-grants","toc_title":"Detect and Remediate Illicit Consent Grants in Office 365"},{"href":"detect-and-remediate-outlook-rules-forms-attack","toc_title":"Detect and Remediate Outlook Rules and Custom Forms Injections Attacks in Office 365"}],"toc_title":"Respond and remediate"}],"toc_title":"Investigate and Respond"},{"children":[{"href":"message-headers-eop-mdo","toc_title":"Anti-spam message headers"},{"href":"app-guard-for-office-install","toc_title":"Application Guard for Office"},{"href":"mdo-data-retention","toc_title":"Data retention in Defender for Office 365"},{"href":"mdo-privacy","toc_title":"Privacy in Defender for Office 365"},{"href":"mdo-ices-vendor-ecosystem","toc_title":"Defender for Office 365 ICES Vendor Ecosystem integration guide"},{"children":[{"href":"external-senders-microsoft-365-services","toc_title":"Microsoft 365 services for external email senders"},{"href":"external-senders-mail-flow-troubleshooting","toc_title":"External senders - Troubleshooting email sent to Microsoft 365"},{"href":"external-senders-use-the-delist-portal-to-unblock-yourself","toc_title":"External senders - Remove yourself from the blocked senders list"},{"href":"external-senders-policies-practices-guidelines","toc_title":"Policies, practices, and guidelines"}],"toc_title":"External email senders - Microsoft 365 resources"},{"href":"pim-in-mdo-configure","toc_title":"Privileged identity management in Defender for Office 365"}],"toc_title":"Reference"},{"children":[{"href":"/defender","toc_title":"Microsoft Defender XDR"},{"href":"/defender-endpoint","toc_title":"Defender for Endpoint"},{"href":"/defender-for-identity","toc_title":"Defender for Identity"},{"href":"/cloud-app-security","toc_title":"Defender for Cloud Apps"},{"href":"/defender-business","toc_title":"Defender for Business"},{"href":"/defender-vulnerability-management","toc_title":"Defender Vulnerability Management"}],"toc_title":"Microsoft Defender XDR docs"},{"children":[{"href":"step-by-step-guides/step-by-step-guide-overview","toc_title":"Microsoft Defender for Office 365 step-by-step guides and how to use them"},{"children":[{"href":"step-by-step-guides/defense-in-depth-guide","toc_title":"Getting started with defense in-depth configuration for email security"},{"href":"step-by-step-guides/tune-microsoft-defender-for-office-365","toc_title":"Tune Microsoft Defender for Office 365"},{"href":"step-by-step-guides/how-to-configure-quarantine-permissions-with-quarantine-policies","toc_title":"How to configure quarantine permissions and policies"},{"href":"step-by-step-guides/ensuring-you-always-have-the-optimal-security-controls-with-preset-security-policies","toc_title":"Set up steps for the Standard or Strict preset security policies in Microsoft Defender for Office 365"},{"href":"step-by-step-guides/reducing-attack-surface-in-microsoft-teams","toc_title":"Reduce the attack surface for Microsoft Teams"},{"href":"step-by-step-guides/connect-microsoft-defender-for-office-365-to-microsoft-sentinel","toc_title":"Connect Microsoft Defender for Office 365 to Microsoft Sentinel"},{"href":"step-by-step-guides/how-to-enable-dmarc-reporting-for-microsoft-online-email-routing-address-moera-and-parked-domains","toc_title":"How to enable DMARC Reporting for Microsoft Online Email Routing Address (MOERA) and parked Domains"},{"href":"step-by-step-guides/utilize-microsoft-defender-for-office-365-in-sharepoint-online","toc_title":"Use Microsoft Defender for Office 365 in SharePoint"},{"href":"step-by-step-guides/tune-bulk-mail-filtering-walkthrough","toc_title":"Tune bulk email filtering"},{"href":"step-by-step-guides/configure-unified-rbac-defender-office-365","toc_title":"Configure Unified RBAC for Defender for Office 365"}],"toc_title":"Configure"},{"children":[{"href":"step-by-step-guides/track-and-respond-to-emerging-threats-with-campaigns","toc_title":"Track and respond to emerging security threats with campaigns view in Microsoft Defender for Office 365"},{"href":"step-by-step-guides/stay-informed-with-message-center","toc_title":"Set up a digest notification of changes to Microsoft Defender for Office 365 from the message center"},{"href":"step-by-step-guides/how-to-prioritize-manage-investigate-and-respond-to-incidents-in-microsoft-365-defender","toc_title":"How to prioritize, Manage, Investigate \u0026 Respond to Incidents in Microsoft Defender XDR"},{"href":"step-by-step-guides/how-to-run-attack-simulations-for-your-team","toc_title":"How to run attack simulations for your team"},{"href":"step-by-step-guides/how-to-setup-attack-simulation-training-for-automated-attacks-and-training","toc_title":"How to setup automated attacks and training within Attack simulation training"},{"href":"step-by-step-guides/optimize-and-correct-security-policies-with-configuration-analyzer","toc_title":"Optimize and correct threat policies with configuration analyzer"},{"href":"step-by-step-guides/search-for-emails-and-remediate-threats","toc_title":"Search for emails and remediate threats using Threat Explorer in Microsoft Defender XDR"},{"href":"step-by-step-guides/how-to-prioritize-and-manage-automated-investigations-and-response-air","toc_title":"How to prioritize and manage Automated Investigations and Response (AIR)"},{"href":"step-by-step-guides/add-advanced-hunting-community-queries","toc_title":"Add Advanced Hunting community queries to Microsoft Defender XDR and Microsoft Sentinel"},{"href":"step-by-step-guides/prompt-injection-protection-defender-for-office-365","toc_title":"Prompt injection protection in Microsoft Defender for Office 365"}],"toc_title":"Use"},{"children":[{"href":"step-by-step-guides/understand-overrides-in-email-entity","toc_title":"Understanding overrides within the email entity page in Microsoft Defender for Office 365"},{"href":"step-by-step-guides/how-to-handle-false-negatives-in-microsoft-defender-for-office-365","toc_title":"(False Negatives) How to handle malicious emails that are delivered to recipients using Microsoft Defender for Office 365"},{"href":"step-by-step-guides/how-to-handle-false-positives-in-microsoft-defender-for-office-365","toc_title":"(False Positives) How to handle legitimate emails getting blocked from delivery using Microsoft Defender for Office 365"},{"href":"step-by-step-guides/understand-detection-technology-in-email-entity","toc_title":"Understanding detection technology in the email entity page of Microsoft Defender for Office 365"},{"href":"step-by-step-guides/assess-the-impact-of-security-configuration-changes-with-explorer","toc_title":"Assess the impact of security configuration changes with Explorer"},{"href":"step-by-step-guides/review-allow-entries","toc_title":"Review and remove unnecessary allow list entries with Advanced Hunting in Microsoft Defender for Office 365"}],"toc_title":"Diagnose"}],"toc_title":"Step-by-step guides"}],"expanded":true,"href":"./","toc_title":"Office 365 security"}],"metadata":{"breadcrumb_path":"/defender-office-365/breadcrumb/toc.json","count_of_node_with_href":237,"feedback_product_url":"https://techcommunity.microsoft.com/t5/security-compliance-and-identity/ct-p/MicrosoftSecurityandCompliance","feedback_system":"Standard","manager":"bagol","open_to_public_contributors":true,"permissioned-type":"public","searchScope":["Microsoft Defender Office 365"],"titleSuffix":"Microsoft Defender for Office 365","uhfHeaderId":"MSDocsHeader-MicrosoftDefender"}}