Introduction

Completed

Relecloud's collaboration workloads—email, Teams, SharePoint, and OneDrive—carry the daily back-and-forth with Woodgrove Bank about regulated wire transfers and account data, so those workloads need protection you configure with precision, not generic defaults left to chance.

Consider a case that lands on your desk: Relecloud's finance team is a live phishing target right now, in daily, active correspondence with Woodgrove Bank about those regulated transfers. You built protection specifically for that team: a custom anti-spam policy with its priority set to 0, the highest value a custom policy can have, certain that setting would guarantee it wins. It doesn't. The tenant keeps enforcing the same generic Standard preset security policy for that group instead, as if your custom policy doesn't exist at all. The highest-priority custom policy loses, and nothing in the policy configuration explains why.

What you'll learn

  • Order preset security policies (Strict, then Standard) with custom threat policies so priority actually produces the outcome you expect.
  • Configure anti-phishing, anti-spam, anti-malware, Safe Attachments, Safe Links, and quarantine policies for email and collaboration threats.
  • Investigate a specific threat with Threat Explorer and the Email entity page, and manage alert status and classification through the response workflow.
  • Use automated investigation and response (AIR) to remediate malicious clusters, and run attack simulation training campaigns to reinforce the lesson with people.
  • Recognize how Defender for Office 365 fits inside the broader Microsoft Defender estate alongside Microsoft Defender XDR, Defender for Cloud Apps, Security Copilot, and posture-management tools.

By the end of this module, you can configure, investigate, and report on Microsoft Defender for Office 365 protections so Relecloud's finance team, and the rest of the organization, stays defended against targeted email and collaboration threats.