FREE STUDY NOTES · SC-900

Microsoft Defender for Office 365: Plan 1 vs Plan 2

The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.

From Ultra Transcenders SC-900 by Tony Rough (publishing soon)

Email remains the most common way into an organisation, and collaboration tools such as Teams carry the same risks. Defender for Office 365 is the primary email and collaboration security solution for Microsoft 365.

Microsoft describes a protection ladder with three rungs:

  1. Built-in security features for all cloud mailboxes: included with every Microsoft 365 subscription that has cloud mailboxes, and long known as Exchange Online Protection (EOP). They stop broad, volume-based, known email attacks with anti-malware, anti-spam, anti-phishing (spoofing) protection, connection filtering, quarantine and zero-hour auto purge (ZAP), which removes malicious messages after delivery. The default policies are on for all recipients and can’t be turned off, only overridden.
  2. Defender for Office 365 Plan 1: protects email and collaboration from zero-day malware, phishing and business email compromise (BEC). Included in Microsoft 365 Business Premium and, since 1 July 2026, in Microsoft 365 E3 and Office 365 E3.
  3. Defender for Office 365 Plan 2: adds phishing simulation, post-breach investigation, hunting, response and automation. Included in Microsoft 365 E5 (and A5 and G5).

Either plan can also be bought as an add-on.

Key Plan 1 features:

Capability Built-in (all cloud mailboxes) Plan 1 Plan 2
Anti-malware, anti-spam, spoofing protection, ZAP for email Yes Yes Yes
Safe Attachments and Safe Links No Yes Yes
Impersonation-aware anti-phishing No Yes Yes
Real-time detections No Yes Replaced by Threat Explorer
Threat Explorer No No Yes
Threat Trackers No No Yes
Campaigns view No No Yes
Attack simulation training No No Yes
Automated investigation and response (AIR) No No Yes
Advanced hunting and Defender XDR incidents No No Yes

Attack simulation training runs phishing simulations against the organisation’s own users so that awareness can be measured and improved. Threat Explorer is the Plan 2 investigation tool that replaces Real-time detections, and seeing Explorer rather than Real-time detections in the portal is a quick way to tell the plans apart. Threat Trackers and Campaigns views add further post-breach investigation in Plan 2.

Common trap: Expecting Attack simulation training or Threat Explorer with Plan 1 - both are Plan 2 features. Plan 1 gives prevention (Safe Attachments, Safe Links, impersonation protection) plus Real-time detections; Plan 2 adds investigation, simulation and automation.

Get the whole book

This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · SC-900 terms in the glossary · All SC-900 study notes

More SC-900 study notes