FREE STUDY NOTES · SC-200

Defender for Office 365 Plan 1 vs Plan 2: Safe Attachments, Safe Links, anti-phishing and ZAP

Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.

From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)

Every Microsoft 365 cloud mailbox gets built-in protection (anti-malware, anti-spam, basic anti-phishing and zero-hour auto purge). Defender for Office 365 adds advanced protection in Plan 1 and investigation and response tools in Plan 2. Knowing which plan includes a tool tells you at once whether an organisation can use it.

Capability Plan 1 Plan 2
Safe Attachments (including SharePoint, OneDrive and Teams) Yes Yes
Safe Links (email, Teams, Office apps) Yes Yes
Anti-phishing with impersonation protection and phishing thresholds Yes Yes
Real-time detections Yes Replaced by Threat Explorer
Email entity page, user tags (including Priority account) Yes Yes
Threat Explorer, Campaigns, Threat Trackers No Yes
Automated investigation and response (AIR) No Yes
Advanced hunting, incidents and alerts in Defender XDR No Yes
Attack simulation training, priority account protection No Yes

Plan 2 is included in Microsoft 365 E5/A5/G5 and Office 365 E5/A5/G5. Plan 1 is included in Microsoft 365 Business Premium and, since 1 July 2026, in Office 365 E3 and Microsoft 365 E3. A quick way to tell the plans apart in the portal is whether Email & collaboration > Explorer exists (Plan 2) or only Real-time detections (Plan 1).

Safe Attachments

Safe Attachments detonates attachments in a virtual environment after anti-malware scanning and before delivery; scanning typically completes within 15 minutes. There’s no default Safe Attachments policy, but the Built-in protection preset security policy covers every recipient not in a Standard, Strict or custom policy. A new custom policy takes about 30 minutes to take effect.

Unknown malware response Behaviour
Off No detonation (anti-malware still runs); ZAP doesn’t quarantine if no threat signal arrives
Monitor Delivers, then tracks detected threats; can redirect detected messages to an address
Block (default; Standard and Strict) Quarantines messages with detected attachments and blocks future instances
Dynamic Delivery Delivers the body immediately with placeholders for attachments until scanning finishes; malicious messages are quarantined

Dynamic Delivery works only for Exchange Online mailboxes; most PDFs and Office documents can be previewed in safe mode while scanning runs. A separate setting quarantines messages with password-protected attachments that can’t be scanned; users can then release their own message by entering the attachment password once, which triggers a fresh detonation.

Common trap: Choosing Monitor to avoid delays - Monitor still delivers after scanning, so safe messages can be delayed. Dynamic Delivery is the option that delivers the body at once and swaps in the attachment after scanning.

Safe Links scans URLs during mail flow and checks them again at time of click in email, Teams and supported Office apps. In email, URLs are rewritten to safelinks.protection.outlook.com by default; in Teams and Office apps they aren’t rewritten. If rewriting is turned off, Outlook checks unwrapped URLs through a Safe Links API at click time. Key policy settings are Apply real-time URL scanning for suspicious links and links that point to files, Wait for URL scanning to complete before delivering the message, Track user clicks and Let users click through to the original URL (recommended off). Clicks on wrapped URLs appear in the UrlClickEvents table with AppName = Mail.

Common trap: Using a policy’s “Do not rewrite the following URLs” list to allow a URL everywhere - those URLs aren’t wrapped during mail flow but can still be blocked at time of click. An allow entry in the Tenant Allow/Block List (added by reporting the URL as clean) is the way to stop scanning in both places.

Anti-phishing: spoofing versus impersonation

Anti-phishing policies exist for all cloud mailboxes, but only Defender for Office 365 adds impersonation protection and phishing email thresholds.

Zero-hour auto purge

Zero-hour auto purge (ZAP) retroactively acts on malicious messages already delivered to Exchange Online mailboxes, including the Deleted Items folder, using the action configured for each verdict. Its search covers the last 48 hours of delivered email, users aren’t notified, and it doesn’t work for on-premises mailboxes.

Verdict after delivery ZAP action
Malware Quarantines read or unread messages
High confidence phishing Quarantines read or unread messages
Phishing Follows the anti-spam policy action (Move to Junk by default; Quarantine in Standard and Strict)
Spam, high confidence spam Unread messages only; follows the anti-spam policy action

ZAP doesn’t quarantine messages still in Dynamic Delivery; it falls back to Move to Junk.

Get the whole book

This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-200 terms in the glossary · All SC-200 study notes

More SC-200 study notes