The layer above Exchange Online Protection that stops phishing, invoice fraud, and malicious attachments.
Exchange Online Protection catches bulk spam. It does not catch the single well-written email that convinces your accounts team to pay a fraudulent invoice. Defender for Office 365 adds Safe Links, Safe Attachments, and impersonation protection at Plan 1, and investigation, automation, and phishing simulation at Plan 2. We deploy it, tune it so quarantine does not drown your users, and run it, remote-first from Gachibowli, Hyderabad, for organisations across India.
- Three tiersEOP, Plan 1, Plan 2
- Plan 1Inside Business Premium
- Plan 2Inside Microsoft 365 E5
- 30 minManaged-client SLA
Eight things to understand before you touch a licence.
Exchange Online Protection: what everyone already has
Every Microsoft 365 subscription with cloud mailboxes includes EOP: anti-malware, anti-spam with bulk mail handling, spoof intelligence, connection filtering, quarantine with quarantine policies, the Tenant Allow/Block List, message trace, and zero-hour auto purge. Microsoft positions it as protection against broad, volume-based, known attacks. It is genuinely good at that. Volume spam is not what costs Indian businesses money. Targeted impersonation is.
Safe Links: the URL is checked when clicked, not when delivered
Attackers routinely send a clean URL that turns malicious an hour after delivery, once filters have passed it. Safe Links rewrites URLs in email, Teams, and Office documents so every click is checked at click time against current intelligence. It arrives at Plan 1, and in a large share of the Indian tenants we review it is licensed and either disabled or scoped to a pilot group somebody forgot to expand.
Safe Attachments: detonation before delivery
Safe Attachments opens every inbound attachment in a sandbox and watches what it does before the user ever sees it, which is how zero-day malware in an innocuous-looking invoice PDF gets caught. It covers email at Plan 1, and, in a separately enabled setting most tenants miss, files in SharePoint, OneDrive, and Teams. If your teams share files through Teams more than email, that second setting matters more than the first.
Impersonation protection: the anti-BEC layer
Business email compromise arrives as a message pretending to be your managing director, your CFO, or a supplier, usually with no malware and no link, just an instruction about a payment. Impersonation protection at Plan 1 defends specific named users and specific domains, plus mailbox intelligence that learns who each person actually corresponds with. It ships with an empty list. Somebody has to name your executives and your critical supplier domains, and in most tenants nobody ever has.
Where the plans sit in subscriptions you may already hold
Microsoft gives Microsoft 365 Business Premium, E3, and G3 as examples of subscriptions that include Defender for Office 365 Plan 1, and A5, E5, and G5 as examples that include Plan 2. Both plans are also available as add-ons. So a company on Business Premium already owns Safe Links, Safe Attachments, and impersonation protection whether or not anyone configured them, and the first question is configuration, not purchase.
Plan 2: Threat Explorer and automated investigation
Plan 2 is the investigation tier. Threat Explorer answers "who else received this message, who clicked, and what happened next" in minutes. Campaigns groups related attacks so you see the whole wave, not one report. Automated Investigation and Response triages reported phishing and compromised-user signals without a human working every queue item. If CERT-In reporting timelines apply to you, this is the tier that lets you reconstruct an email incident fast enough to meet them.
Attack simulation training: test your staff before attackers do
Plan 2 includes attack simulation training: controlled phishing campaigns sent to your own staff from inside the platform, with automatic micro-training for anyone who clicks. Run quarterly, it turns "we did awareness training once" into a measured click-rate trend you can show leadership and auditors. We design the scenarios around what your staff actually receive, invoice themes for finance, courier notifications for operations, HR themes for everyone.
The tuning problem: protection users can live with
Turn everything to Strict on day one and your users will spend the week fishing legitimate vendor emails out of quarantine, and by week three they will distrust the system and you. Tuning is the real work: preset policies as the baseline, quarantine policies that let users release low-risk items themselves and request release for high-risk ones, allow-list hygiene for the Indian vendors and portals that trip filters, and a review cadence that keeps false positives falling instead of accumulating.
The email that empties a bank account does not look like spam.
Every rung of the ladder handles bulk spam well. The losses we see in Indian organisations come from one convincing message about a payment, and where you sit on the ladder decides whether you can stop it arriving and reconstruct it afterwards.
- Business email compromise usually carries no attachment, no link, and no malware, just a well-written instruction that impersonates somebody the recipient trusts. Volume-based filtering has almost nothing to work with. Impersonation protection, which starts at Plan 1, is the control aimed squarely at this, and it only works after somebody configures it with your executives and supplier domains.
- The harder variant is a genuine message from a genuinely compromised mailbox, often at a vendor rather than at you. Nothing is spoofed, so no filter flags it. The control that stops the loss is procedural: any change of bank details gets verified by phone to a previously known number before a rupee moves. We say that plainly because it outperforms every licence tier on this specific risk.
- Plan 2 earns its keep afterwards. When leadership asks what happened, who else received it, and whether anything was clicked, Threat Explorer, Campaigns, and automated investigation answer in minutes. That speed also matters for CERT-In, whose directions require covered incidents to be reported within six hours of noticing, and for DPDP Act breach notification, where you need to establish scope quickly and defensibly.
- And separately from every tier: publish and enforce SPF, DKIM, and DMARC. Microsoft states those records let it protect more accurately against spoofing, and they stop your own domain being used against your customers, which no inbound plan addresses.
Four things that matter more than which plan you buy.
We establish your tier before discussing upgrades
The Explorer versus Real-time detections check takes ten seconds and settles what you hold. In a meaningful share of engagements the organisation already owns Plan 1 through Business Premium or E3 and has configured none of it, which makes the work configuration rather than purchase. Recommending Plan 2 to a tenant running Plan 1 at defaults would be selling capacity to somebody not using what they have.
We configure impersonation protection around real people
Impersonation protection works on named users and named domains, so somebody has to decide who and what to protect: your directors, your finance team, anyone who can change payment details, your own domains, and your significant vendors. That is a short exercise, it is included from Plan 1, and it is the single most targeted control against the attack that actually costs Indian businesses money.
We tune until users stop noticing
A deployment that quarantines the tenant's legitimate vendor mail is a failed deployment, whatever the licence says. We baseline your mail flow first, start from the Standard preset, tune quarantine policies so users can self-release low-risk items, whitelist the Indian portals and banks that trip filters, and review false positives on a fixed cadence until the quarantine digest is boring. Boring is the goal.
We map it to DPDP and CERT-In, in writing
If you process personal data, the DPDP Act expects reasonable security safeguards and breach notification, and CERT-In directions expect covered incidents reported within six hours of noticing and logs retained for 180 days. We document how your Defender configuration, quarantine evidence, and investigation capability support each obligation, so the answer to an auditor or a client security questionnaire is a document, not a scramble.
Six Indian situations that justify doing this properly.
Any business whose finance team pays invoices from email
Which is nearly all of them, and it is why this page exists. The impersonation protection that starts at Plan 1 is aimed squarely at the message pretending to be your director or your supplier asking for a payment or a bank-detail change. Configuring it around the specific people who authorise payments is a short piece of work with a direct line to the loss it prevents.
A company that has already seen a CEO-fraud attempt
A payment nearly went to the wrong account, or somebody received a convincing message from "the MD" that turned out to be a lookalike address. This is the right moment to act, because the organisation has just experienced the exact risk and the budget conversation is already won. The work is usually configuration plus a payment-verification process change, not a licence upgrade.
A business on Microsoft 365 Business Premium or E3
Both include Defender for Office 365 Plan 1, so you already own impersonation protection, Safe Links, and Safe Attachments whether or not anyone switched them on. The useful question is not "should we buy email security" but "is the email security we pay for actually configured", and the answer, in most tenants we review, is not yet.
DPDP data fiduciaries and processors
If you hold personal data of Indian data principals, email is your most likely breach vector, and the DPDP Act expects reasonable security safeguards and breach notification to the Data Protection Board. A tuned Defender for Office 365 deployment is a demonstrable safeguard, and Plan 2 investigation capability is what lets you establish breach scope quickly enough to notify defensibly.
Exporters and firms with foreign clients
IT services companies, exporters, and anyone answering client security questionnaires from the US, EU, or elsewhere. "What email threat protection do you run, and can you investigate an incident" appears on nearly every vendor assessment. A configured MDO deployment with documented policies turns that question from a liability into a checkbox, and often keeps a deal alive.
Organisations replacing or reviewing a third-party gateway
Many Indian tenants still route mail through a legacy email security gateway bought before Defender matured. Running both means two filtering layers, two quarantines, and double administration, and the gateway often breaks the authentication signals Defender relies on. We review honestly whether the gateway still earns its cost, and decommission it safely when it does not.
Three positions, and the middle one is the most common.
| Feature | Tier known and tuned | Licensed, default settings | EOP only |
|---|---|---|---|
Knows which plan it holds | Yes | Assumes | Correct by default |
Safe Links and Safe Attachments enabled | Yes | Partly | Not available |
Impersonation protection has names in it | Yes | No | Not available |
Quarantine policies users can live with | Yes | Defaults | Defaults |
Safe Attachments covers SharePoint and Teams | Yes | Rarely | Not available |
External sender warning in place | Yes | Sometimes | Sometimes |
Phishing simulations run on staff | Quarterly | No | No |
Could reconstruct who else got a message | Minutes | Hours to days | Barely |
Payment changes verified out of band | Yes | Sometimes | Rarely |
Frequency in the Indian market | Uncommon | Very common | Common in SMEs |
The three rungs side by side.
| Capability | EOP built-in | Plan 1 | Plan 2 | |
|---|---|---|---|---|
| Anti-malware, anti-spam, spoof intelligence | Yes | Yes | Yes | |
| Quarantine, Tenant Allow/Block List, message trace | Yes | Yes | Yes | |
| Zero-hour auto purge for email | Yes | Yes | Yes | |
| User and domain impersonation protection | No | Yes | Yes | |
| Mailbox intelligence, contact-graph impersonation | No | Yes | Yes | |
| Safe Attachments, email plus SharePoint, OneDrive, Teams | No | Yes | Yes | |
| Safe Links in email, Office clients, and Teams | No | Yes | Yes | |
| Real-time detections view | No | Yes | Replaced by Explorer | |
| Email entity page and user tags | No | Yes | Yes | |
| Threat Explorer | No | No | Yes | |
| Threat Trackers and Campaigns | No | No | Yes | |
| Attack simulation training | No | No | Yes | |
| Automated Investigation and Response | No | No | Yes | |
| Priority account protection | No | No | Yes | |
| Safe Documents | No | No | No, needs A5 or Defender Suite |
Five steps, starting with a ten-second check.
- 1
Establish the tier and what is configured
Days 1-2
The Explorer versus Real-time detections check, then a review of what is actually enabled: Safe Links, Safe Attachments including SharePoint, OneDrive, and Teams coverage, anti-phishing policies, quarantine policies, and whether preset security policies are in use or custom policies nobody has reviewed since they were created.
- 2
Configure impersonation protection and priority accounts
Week 1
Your executives and finance team named in user impersonation protection, your own domains and significant vendor domains in domain impersonation protection, mailbox intelligence enabled, priority accounts tagged, external sender warnings on. This step needs a business decision about who to protect, not just an administrator, and we run that conversation with you.
- 3
Enable Safe Links and Safe Attachments, then tune
Weeks 1-2
Policies rolled out from the Standard preset, extended to SharePoint, OneDrive, and Teams, then a deliberate false-positive burn-in: quarantine policies set so users can release low-risk items themselves, allow-list entries for the legitimate Indian senders that trip filters, and daily triage until the noise settles. We do not hand over a quarantine your users hate.
- 4
Stand up investigation and simulation, if Plan 2
Weeks 2-3
Threat Explorer walkthrough with whoever will use it, automated investigation enabled for user-reported phishing, the report-phishing button tested end to end, and the first attack simulation training campaign designed around lures your staff actually receive. If you are on Plan 1, we activate the 90-day Plan 2 trial here so you can judge the difference on your own tenant.
- 5
Handover or managed operation
Week 4 onward
Documented configuration, a tuning runbook, and a monthly report format for leadership. Organisations without a security function usually move to our managed service: we watch the queues, triage reported phishing, run the quarterly simulations and tuning reviews, and respond to P1 email incidents within the 30 minutes managed-client SLA.
What Indian organisations ask about Defender for Office 365.
Fifteen checks, and the first one takes ten seconds.
What you have
- Does Email and collaboration in the Defender portal show Explorer, or Real-time detections?Explorer means Plan 2, Real-time detections means Plan 1. Microsoft publishes this as the quick differentiator.
- Are Safe Links and Safe Attachments actually enabled for all users?Included at Plan 1 and frequently disabled or scoped to a forgotten pilot group.
- Does Safe Attachments cover SharePoint, OneDrive, and Teams?A separate setting from email, and the one most tenants miss.
- Are you on preset security policies, or custom policies nobody reviews?Standard and Strict presets are maintained by Microsoft; stale custom policies are frozen at whoever left last.
- Have you used the Plan 2 trial to see what Explorer adds?Microsoft offers a 90-day trial through the Defender portal trials hub.
The payment-fraud layer
- Is user impersonation protection configured with your executives named?It protects named people, so somebody has to name them. Default is an empty list.
- Is domain impersonation protection configured for your domains and key vendors?Lookalike domains are the standard invoice-fraud vehicle.
- Are priority accounts tagged?Finance, directors, anyone who can change payment details.
- Do external emails carry a visible warning tag?Cheap, and effective against display-name tricks.
- Does a bank-detail change require phone verification to a known number?The one control no licence tier can replace.
Could you investigate afterwards
- Could you find everyone else who received a given message?Threat Explorer at Plan 2, a narrower view at Plan 1.
- Would you know whether a link was clicked?URL trace and the email entity page start at Plan 1.
- Does your log retention meet the CERT-In 180-day expectation?A separate question from your Defender plan, and audited in our email security audit.
- Are SPF, DKIM, and DMARC published and enforced for your domains?Microsoft states these improve its own spoofing protection.
- Has anyone tested the report-phishing flow end to end?A report button that goes nowhere trains staff to stop using it.
The pages around this one.
Email Security Audit India
The assessment version of this work: a point-in-time review of your mail flow, authentication records, Defender configuration, and log retention against DPDP and CERT-In expectations, with a written findings report.
Learn moreMicrosoft Defender
The family page. Defender for Office 365 is one pillar; Endpoint, Identity, and Cloud Apps are the others, and the cross-signal correlation between them is where the suite outperforms point products.
Learn moreMicrosoft Security Services India
The full Microsoft security practice: Defender deployment and tuning, Entra identity hardening, Sentinel monitoring, and compliance mapping for Indian regulatory frameworks.
Learn moreOpen the Defender portal and look at Email and collaboration.
Explorer means Plan 2, Real-time detections means Plan 1. Then check whether impersonation protection has any names in it. Those two answers tell you whether your next move is a purchase or a fortnight of configuration, and in most Indian tenants we review, it is the second. Tell us what you found and we will reply within 4 business hours.
Related Services
Explore more solutions that work great with this service