The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
Email remains the most common way into an organisation, and collaboration tools such as Teams carry the same risks. Defender for Office 365 is the primary email and collaboration security solution for Microsoft 365.
Microsoft describes a protection ladder with three rungs:
Either plan can also be bought as an add-on.
Key Plan 1 features:
| Capability | Built-in (all cloud mailboxes) | Plan 1 | Plan 2 |
|---|---|---|---|
| Anti-malware, anti-spam, spoofing protection, ZAP for email | Yes | Yes | Yes |
| Safe Attachments and Safe Links | No | Yes | Yes |
| Impersonation-aware anti-phishing | No | Yes | Yes |
| Real-time detections | No | Yes | Replaced by Threat Explorer |
| Threat Explorer | No | No | Yes |
| Threat Trackers | No | No | Yes |
| Campaigns view | No | No | Yes |
| Attack simulation training | No | No | Yes |
| Automated investigation and response (AIR) | No | No | Yes |
| Advanced hunting and Defender XDR incidents | No | No | Yes |
Attack simulation training runs phishing simulations against the organisation’s own users so that awareness can be measured and improved. Threat Explorer is the Plan 2 investigation tool that replaces Real-time detections, and seeing Explorer rather than Real-time detections in the portal is a quick way to tell the plans apart. Threat Trackers and Campaigns views add further post-breach investigation in Plan 2.
Common trap: Expecting Attack simulation training or Threat Explorer with Plan 1 - both are Plan 2 features. Plan 1 gives prevention (Safe Attachments, Safe Links, impersonation protection) plus Real-time detections; Plan 2 adds investigation, simulation and automation.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.