12.1 Threat Policies & Rules in Defender for Office 365

Key Takeaways

  • Defender for Office 365 Plan 2 adds advanced hunting, Threat Trackers, Campaign Views, and automated investigation and response (AIR) on top of Plan 1's Safe Links, Safe Attachments, and anti-phishing impersonation protection
  • Preset security policies (Standard and Strict) bundle Safe Links, Safe Attachments, and anti-phishing settings into a single baseline that Microsoft recommends applying to all users before tuning custom policies
  • Anti-spam verdicts use the Spam Confidence Level (SCL 0-9) and Bulk Complaint Level (BCL 0-9); higher values route mail to Junk or Quarantine based on policy thresholds
  • Safe Attachments detonates attachments in a sandbox and supports Dynamic Delivery, which placeholders the attachment until scanning completes without delaying the message body
  • The Tenant Allow/Block List is the unified list for sender, domain, URL, and file allow or block entries that override filtering verdicts across the tenant
Last updated: August 2026

Quick Answer: Defender for Office 365 is configured in the Microsoft Defender portal under Email & collaboration → Policies & rules. The five policy families you must know for MS-102 are anti-malware, anti-spam, anti-phishing, Safe Links, and Safe Attachments, plus the connection filter, Tenant Allow/Block List, outbound spam, and the Standard/Strict preset security policies that bundle a recommended baseline.

Plan 1 versus Plan 2

Microsoft Defender for Office 365 ships in two plans. Plan 1 (included in Microsoft 365 Business Premium, and — effective 1 July 2026 — in Office 365 E3 and Microsoft 365 E3; also sold standalone) provides protective policies — Safe Links, Safe Attachments, anti-phishing with spoof and impersonation protection, and the rich reporting dashboards. Plan 2 (included in Microsoft 365 E5 and Office 365 E5) adds the hunting and response tier: Threat Explorer real-time detections, Threat Trackers, Campaign Views, advanced hunting (Kusto queries over 30 days of email events), and automated investigation and response (AIR) playbooks. Knowing which feature belongs to which plan is a common MS-102 distinction question.

CapabilityPlan 1Plan 2
Safe Links, Safe Attachments, anti-phishing impersonationYesYes
Real-time detections reportYesYes
Threat Explorer (multi-day pivots, drill-down)NoYes
Threat Trackers and Campaign ViewsNoYes
Advanced hunting (KQL)NoYes
Automated investigation and response (AIR)NoYes

Where Policies Live

In the Defender portal (https://security.microsoft.com), navigate to Email & collaboration → Policies & rules → Threat policies. This single blade surfaces every policy family below. Each policy is created from a default Microsoft template that you then tune, or you apply a preset and layer exceptions on top.

The Policy Families

Anti-malware policy

Scans every inbound and outbound message and attachment using the Microsoft anti-malware engine plus the Common Attachments Filter, which blocks file types commonly used by malware (for example .exe, .js, .vbs) regardless of content. You configure the action for malware detections (quarantine or remove), recipient notification text, sender and admin notification addresses, the Zero-hour Auto Purge (ZAP) behavior for already-delivered malware, and the quarantine retention period (default 30 days).

Anti-spam policy

Anti-spam is split into inbound and outbound policy entries. Inbound anti-spam assigns a Spam Confidence Level (SCL) of 0 through 9 to each message; you map each SCL band to an action — move to Junk, redirect, quarantine, or delete. Bulk mail is scored separately via the Bulk Complaint Level (BCL) 0-9, with a configurable threshold that determines when bulk senders are treated as spam. Outbound anti-spam controls messages your users send to the internet, including automatic blocking of a user who exceeds the hourly send limit and notification of admins when an outbound sender is blocked.

Anti-phishing policy

Every tenant has the default anti-phishing policy that enables spoof intelligence (detecting forged sender addresses and cross-tenant spoofing). With Defender for Office 365, anti-phishing adds mailbox intelligence (learning a user's typical contacts to flag unfamiliar senders) and impersonation protection for protected domains and protected users — the controls that defend against BEC and CEO-fraud attacks where the attacker spoofs a trusted executive's display name. Each impersonation detection can be quarantined, delivered with a safety tip, or redirected to the user's Junk folder.

Safe Links

Safe Links rewrites URLs in inbound email, internal email (if configured), Microsoft Teams chats and channels, and supported Office desktop/web/mobile apps, then scans the destination at click time. Key settings include URL & click protection (rewrite and scan), Do not rewrite the following URLs (tenant allow-list for known-good destinations), Track user clicks (for reporting), On-click protection (recheck at click even if the message was delivered clean), and the action for malicious clicks (block or allow with warning). A separate Safe Links policy applies to Teams.

Safe Attachments

Safe Attachments routes attachments into an isolated detonation sandbox where the file is executed and observed for malicious behavior before delivery. Policy settings include the malware response (block, replace, dynamic delivery), Dynamic Delivery (writes a placeholder attachment into the message body so the email arrives immediately and the real attachment is swapped in once scanning completes — useful for large files), Redirect (send detected attachments to a specified mailbox for analyst review), and the timeout action if the sandbox can't complete in time.

Connection filter and Tenant Allow/Block List

The connection filter policy holds the legacy IP Allow and IP Block lists for edge-level decisions before content filtering. The modern, preferred mechanism is the Tenant Allow/Block List (TABL), a single list with separate tabs for senders, domains, URLs, and files. Entries can be allow or block, have optional expiration dates, and override other filtering verdicts tenant-wide. Admins can also configure allow/block with sender authentication so an allow entry does not suppress SPF/DKIM/DMARC failure reporting.

Outbound spam

Outbound spam policy defines the per-user send limits, the action when a limit is exceeded (block the user, notify admins), and whether a copy of suspicious outbound messages is BCC'd to an admin mailbox. It is the control that prevents a compromised account from flooding the internet and getting the tenant's IP ranges listed on blocklists.

Preset Security Policies

Preset security policies apply a Microsoft-curated bundle of Safe Links, Safe Attachments, and anti-phishing settings to a population of users with one click. There are two presets:

  • Standard protection — recommended baseline for most users; enables Safe Links and Safe Attachments with default thresholds and anti-phishing spoof and impersonation protection.
  • Strict protection — tighter thresholds and more aggressive actions (for example, delivering impersonation detections straight to quarantine) for high-risk users such as executives, finance, and security admins.

Presets are applied in priority order, and a custom policy with higher priority overrides a preset for the same user. Microsoft recommends applying Standard to all users as the first configuration step, then carving high-risk groups into Strict, then building custom policies only for edge cases that the presets don't cover. The protection policies page in the Defender portal shows which presets are on and which recipient groups they cover.

Building a Baseline Configuration

A defensible rollout order for MS-102 is: (1) enable the Standard preset for all users; (2) create a Strict preset assignment for executives, finance, and security teams; (3) tune the default anti-spam and anti-malware policies for quarantine retention and admin notifications; (4) configure outbound spam limits and admin alerts; (5) build the Tenant Allow/Block List from known-good partners and known-bad senders; (6) add custom Safe Links and Safe Attachments policies only where a preset does not meet a specific need. Each policy change should be validated in Threat Explorer and the protection reports before being widened to the tenant.

Minimum Defender for Office 365 plan required per feature (1 = Plan 1, 2 = Plan 2)
Test Your Knowledge

A customer has Microsoft 365 E5 and wants to use Campaign Views and advanced hunting. Which Defender for Office 365 plan is required, and where is it configured?

A
B
C
D
Test Your Knowledge

What is the purpose of Dynamic Delivery in a Safe Attachments policy?

A
B
C
D