Summary

Completed

In this module, you configure Microsoft Defender for Office 365 to protect a finance team's email and collaboration content from a spoofed vendor, then investigate, remediate, and train against the threat end to end. You now recognize how policies, protection, alerts, and response fit together across the wider Microsoft Defender estate.

What you learned

  • Preset security policies (Strict, then Standard) always evaluate before custom threat policies, so a custom policy's priority only decides the winner once you exclude the recipient from any preset that already covers them.
  • Anti-phishing, anti-spam, anti-malware, and quarantine policies each control a distinct part of a threat, from impersonation protection and mailbox intelligence to outbound sending limits and who can release a quarantined message.
  • A single tenant-wide setting extends Safe Attachments and Safe Links scanning to files shared in Microsoft Teams, SharePoint, and OneDrive, separate from any mail-flow policy you configure for email.
  • Alert status (New, In progress, Resolved) and classification track your workflow and findings, while Threat Explorer, not the Threat protection status report, is how you search for and act on one specific message.
  • Automated investigation and response (AIR) soft-deletes confirmed malicious clusters pending SecOps approval, and attack simulation training or a training campaign reinforces the lesson with people, with the training threshold controlling reassignment.
  • Microsoft Defender for Office 365 signals feed into Microsoft Defender XDR, Defender for Cloud Apps, Security Copilot, and the Secure Score, Exposure Management, and Threat Intelligence posture tools across the broader security estate.

Learn more