Secure email and collaboration with Microsoft Defender for Office 365

Intermediate
Administrator
Microsoft 365
Microsoft 365 Admin Center

Defend email and collaboration workloads using Microsoft Defender for Office 365—configure threat protection policies, manage alerts, investigate and respond to threats, and run attack simulation training—and understand how it fits the broader Microsoft Defender security estate.

Learning objectives

After completing this module, you will be able to:

  • Manage the Microsoft Defender for Office 365 alert queue, including updating alert status.
  • Configure threat protection policies and their per-policy settings, and scope custom policies correctly around presets.
  • Investigate and respond to email and collaboration threats using Threat Explorer, the Email entity page, and automated investigation and response (AIR).
  • Configure and manage attack simulation training, including training campaigns.
  • Describe how Microsoft Defender for Office 365 fits within the broader Microsoft Defender security estate.

Prerequisites

  • Experience with Microsoft 365 workloads and Microsoft Entra ID.
  • Understanding of Microsoft Defender XDR capabilities.
  • Familiarity with Microsoft Graph PowerShell.
  • Access to a Microsoft 365 E5 tenant (or standalone Defender for Office 365 Plan 2 add-on) for attack simulation training and full response-feature labs.