Microsoft's protection service for email and collaboration tools. Its basic plan covers impersonation, Safe Attachments, Real-time detections and Safe Links; the higher plan layers on Attack simulation training, automated investigation and response, and Threat Explorer.
Also called MDO.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender for Office 365 in context, with comparison tables and the common traps.
Terms in this definition
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
- Safe Attachments
Part of Microsoft Defender for Office 365: before delivering a message, it detonates attached files in a sandbox to catch previously unseen malware, and it also scans files stored in SharePoint, OneDrive and Teams.
- Real-time detections
Plan 1 customers of Defender for Office 365 use this Defender portal report to look into recent email threats. Plan 2 customers get Threat Explorer in its place.
- Safe Links
Part of Microsoft Defender for Office 365: whenever someone selects a web address in an email, a Teams message or an Office document, it checks that address at that moment and stops access to harmful sites.
- Attack simulation training
A Defender for Office 365 Plan 2 tool, also part of Microsoft 365 E5, that runs safe but convincing phishing exercises against staff and enrols anyone who falls for them in training.
- AIR
Automated investigation and response in Microsoft Defender: alerts are examined without an analyst, each item of evidence gets a verdict, and fixes are carried out or suggested in the Action center. For Office 365 protection it requires Defender for Office 365 Plan 2.
- Threat Explorer
Organisations licensed for Plan 2 of Microsoft Defender for Office 365 use this tool to find and deal with email and collaboration threats almost as they happen. Plan 1 includes a cut-down version called Real-time detections.