Skip to main content
Defender for Office 365, India

The layer above Exchange Online Protection that stops phishing, invoice fraud, and malicious attachments.

Exchange Online Protection catches bulk spam. It does not catch the single well-written email that convinces your accounts team to pay a fraudulent invoice. Defender for Office 365 adds Safe Links, Safe Attachments, and impersonation protection at Plan 1, and investigation, automation, and phishing simulation at Plan 2. We deploy it, tune it so quarantine does not drown your users, and run it, remote-first from Gachibowli, Hyderabad, for organisations across India.

Microsoft
Microsoft
Defender
Cloud Solution Partner
  • Three tiersEOP, Plan 1, Plan 2
  • Plan 1Inside Business Premium
  • Plan 2Inside Microsoft 365 E5
  • 30 minManaged-client SLA
What each tier actually does

Eight things to understand before you touch a licence.

Microsoft describes email protection as a ladder with three rungs, not a product with two editions. Every organisation with cloud mailboxes already stands on the bottom rung. The question for an Indian business is not "do we have email security" but "which rung are we on, and is any of it configured". These eight points settle that.

Exchange Online Protection: what everyone already has

Every Microsoft 365 subscription with cloud mailboxes includes EOP: anti-malware, anti-spam with bulk mail handling, spoof intelligence, connection filtering, quarantine with quarantine policies, the Tenant Allow/Block List, message trace, and zero-hour auto purge. Microsoft positions it as protection against broad, volume-based, known attacks. It is genuinely good at that. Volume spam is not what costs Indian businesses money. Targeted impersonation is.

Safe Links: the URL is checked when clicked, not when delivered

Attackers routinely send a clean URL that turns malicious an hour after delivery, once filters have passed it. Safe Links rewrites URLs in email, Teams, and Office documents so every click is checked at click time against current intelligence. It arrives at Plan 1, and in a large share of the Indian tenants we review it is licensed and either disabled or scoped to a pilot group somebody forgot to expand.

Safe Attachments: detonation before delivery

Safe Attachments opens every inbound attachment in a sandbox and watches what it does before the user ever sees it, which is how zero-day malware in an innocuous-looking invoice PDF gets caught. It covers email at Plan 1, and, in a separately enabled setting most tenants miss, files in SharePoint, OneDrive, and Teams. If your teams share files through Teams more than email, that second setting matters more than the first.

Impersonation protection: the anti-BEC layer

Business email compromise arrives as a message pretending to be your managing director, your CFO, or a supplier, usually with no malware and no link, just an instruction about a payment. Impersonation protection at Plan 1 defends specific named users and specific domains, plus mailbox intelligence that learns who each person actually corresponds with. It ships with an empty list. Somebody has to name your executives and your critical supplier domains, and in most tenants nobody ever has.

Where the plans sit in subscriptions you may already hold

Microsoft gives Microsoft 365 Business Premium, E3, and G3 as examples of subscriptions that include Defender for Office 365 Plan 1, and A5, E5, and G5 as examples that include Plan 2. Both plans are also available as add-ons. So a company on Business Premium already owns Safe Links, Safe Attachments, and impersonation protection whether or not anyone configured them, and the first question is configuration, not purchase.

Plan 2: Threat Explorer and automated investigation

Plan 2 is the investigation tier. Threat Explorer answers "who else received this message, who clicked, and what happened next" in minutes. Campaigns groups related attacks so you see the whole wave, not one report. Automated Investigation and Response triages reported phishing and compromised-user signals without a human working every queue item. If CERT-In reporting timelines apply to you, this is the tier that lets you reconstruct an email incident fast enough to meet them.

Attack simulation training: test your staff before attackers do

Plan 2 includes attack simulation training: controlled phishing campaigns sent to your own staff from inside the platform, with automatic micro-training for anyone who clicks. Run quarterly, it turns "we did awareness training once" into a measured click-rate trend you can show leadership and auditors. We design the scenarios around what your staff actually receive, invoice themes for finance, courier notifications for operations, HR themes for everyone.

The tuning problem: protection users can live with

Turn everything to Strict on day one and your users will spend the week fishing legitimate vendor emails out of quarantine, and by week three they will distrust the system and you. Tuning is the real work: preset policies as the baseline, quarantine policies that let users release low-risk items themselves and request release for high-risk ones, allow-list hygiene for the Indian vendors and portals that trip filters, and a review cadence that keeps false positives falling instead of accumulating.

The attack that actually costs money

The email that empties a bank account does not look like spam.

Every rung of the ladder handles bulk spam well. The losses we see in Indian organisations come from one convincing message about a payment, and where you sit on the ladder decides whether you can stop it arriving and reconstruct it afterwards.

  • Business email compromise usually carries no attachment, no link, and no malware, just a well-written instruction that impersonates somebody the recipient trusts. Volume-based filtering has almost nothing to work with. Impersonation protection, which starts at Plan 1, is the control aimed squarely at this, and it only works after somebody configures it with your executives and supplier domains.
  • The harder variant is a genuine message from a genuinely compromised mailbox, often at a vendor rather than at you. Nothing is spoofed, so no filter flags it. The control that stops the loss is procedural: any change of bank details gets verified by phone to a previously known number before a rupee moves. We say that plainly because it outperforms every licence tier on this specific risk.
  • Plan 2 earns its keep afterwards. When leadership asks what happened, who else received it, and whether anything was clicked, Threat Explorer, Campaigns, and automated investigation answer in minutes. That speed also matters for CERT-In, whose directions require covered incidents to be reported within six hours of noticing, and for DPDP Act breach notification, where you need to establish scope quickly and defensibly.
  • And separately from every tier: publish and enforce SPF, DKIM, and DMARC. Microsoft states those records let it protect more accurately against spoofing, and they stop your own domain being used against your customers, which no inbound plan addresses.
Ask us to check your tier and your impersonation policies
How we approach it

Four things that matter more than which plan you buy.

Email security is where the gap between licensed capability and configured capability is widest, and where the most expensive attacks are the ones no filter was ever going to catch. Our engagement model is built around both facts.

We establish your tier before discussing upgrades

The Explorer versus Real-time detections check takes ten seconds and settles what you hold. In a meaningful share of engagements the organisation already owns Plan 1 through Business Premium or E3 and has configured none of it, which makes the work configuration rather than purchase. Recommending Plan 2 to a tenant running Plan 1 at defaults would be selling capacity to somebody not using what they have.

We configure impersonation protection around real people

Impersonation protection works on named users and named domains, so somebody has to decide who and what to protect: your directors, your finance team, anyone who can change payment details, your own domains, and your significant vendors. That is a short exercise, it is included from Plan 1, and it is the single most targeted control against the attack that actually costs Indian businesses money.

We tune until users stop noticing

A deployment that quarantines the tenant's legitimate vendor mail is a failed deployment, whatever the licence says. We baseline your mail flow first, start from the Standard preset, tune quarantine policies so users can self-release low-risk items, whitelist the Indian portals and banks that trip filters, and review false positives on a fixed cadence until the quarantine digest is boring. Boring is the goal.

We map it to DPDP and CERT-In, in writing

If you process personal data, the DPDP Act expects reasonable security safeguards and breach notification, and CERT-In directions expect covered incidents reported within six hours of noticing and logs retained for 180 days. We document how your Defender configuration, quarantine evidence, and investigation capability support each obligation, so the answer to an auditor or a client security questionnaire is a document, not a scramble.

Who needs this

Six Indian situations that justify doing this properly.

Invoice fraud is the common thread. It is the email attack that most reliably costs Indian organisations real money, and every one of these situations raises the odds of it landing.

Any business whose finance team pays invoices from email

Which is nearly all of them, and it is why this page exists. The impersonation protection that starts at Plan 1 is aimed squarely at the message pretending to be your director or your supplier asking for a payment or a bank-detail change. Configuring it around the specific people who authorise payments is a short piece of work with a direct line to the loss it prevents.

A company that has already seen a CEO-fraud attempt

A payment nearly went to the wrong account, or somebody received a convincing message from "the MD" that turned out to be a lookalike address. This is the right moment to act, because the organisation has just experienced the exact risk and the budget conversation is already won. The work is usually configuration plus a payment-verification process change, not a licence upgrade.

A business on Microsoft 365 Business Premium or E3

Both include Defender for Office 365 Plan 1, so you already own impersonation protection, Safe Links, and Safe Attachments whether or not anyone switched them on. The useful question is not "should we buy email security" but "is the email security we pay for actually configured", and the answer, in most tenants we review, is not yet.

DPDP data fiduciaries and processors

If you hold personal data of Indian data principals, email is your most likely breach vector, and the DPDP Act expects reasonable security safeguards and breach notification to the Data Protection Board. A tuned Defender for Office 365 deployment is a demonstrable safeguard, and Plan 2 investigation capability is what lets you establish breach scope quickly enough to notify defensibly.

Exporters and firms with foreign clients

IT services companies, exporters, and anyone answering client security questionnaires from the US, EU, or elsewhere. "What email threat protection do you run, and can you investigate an incident" appears on nearly every vendor assessment. A configured MDO deployment with documented policies turns that question from a liability into a checkbox, and often keeps a deal alive.

Organisations replacing or reviewing a third-party gateway

Many Indian tenants still route mail through a legacy email security gateway bought before Defender matured. Running both means two filtering layers, two quarantines, and double administration, and the gateway often breaks the authentication signals Defender relies on. We review honestly whether the gateway still earns its cost, and decommission it safely when it does not.

What we find in Indian tenants

Three positions, and the middle one is the most common.

The middle column is the pattern we see most across India: the licence includes impersonation protection, Safe Links, and Safe Attachments, none of it is configured, and the organisation is effectively running bare EOP while paying for more. The fix there is configuration and tuning, not a purchase.
Feature
Tier known and tuned
Licensed, default settings
EOP only
Knows which plan it holds
YesAssumesCorrect by default
Safe Links and Safe Attachments enabled
YesPartlyNot available
Impersonation protection has names in it
YesNoNot available
Quarantine policies users can live with
YesDefaultsDefaults
Safe Attachments covers SharePoint and Teams
YesRarelyNot available
External sender warning in place
YesSometimesSometimes
Phishing simulations run on staff
QuarterlyNoNo
Could reconstruct who else got a message
MinutesHours to daysBarely
Payment changes verified out of band
YesSometimesRarely
Frequency in the Indian market
UncommonVery commonCommon in SMEs
EOP vs Plan 1 vs Plan 2

The three rungs side by side.

Reproduced from Microsoft published comparison. The EOP column applies to every Microsoft 365 subscription with cloud mailboxes, so it is what you have even if you have never bought anything extra. Plan 1 ships inside Business Premium, E3, and G3. Plan 2 ships inside A5, E5, and G5.
CapabilityEOP built-inPlan 1Plan 2
Anti-malware, anti-spam, spoof intelligenceYesYesYes
Quarantine, Tenant Allow/Block List, message traceYesYesYes
Zero-hour auto purge for emailYesYesYes
User and domain impersonation protectionNoYesYes
Mailbox intelligence, contact-graph impersonationNoYesYes
Safe Attachments, email plus SharePoint, OneDrive, TeamsNoYesYes
Safe Links in email, Office clients, and TeamsNoYesYes
Real-time detections viewNoYesReplaced by Explorer
Email entity page and user tagsNoYesYes
Threat ExplorerNoNoYes
Threat Trackers and CampaignsNoNoYes
Attack simulation trainingNoNoYes
Automated Investigation and ResponseNoNoYes
Priority account protectionNoNoYes
Safe DocumentsNoNoNo, needs A5 or Defender Suite
How an engagement runs

Five steps, starting with a ten-second check.

Typically two to four weeks end to end, run remotely from our Gachibowli, Hyderabad base for organisations anywhere in India. Most of the value is configuration of capability you already hold, so the licence question is settled first and frequently turns out not to be the issue. You get an initial reply to any enquiry within 4 business hours.
  1. 1

    Establish the tier and what is configured

    Days 1-2

    The Explorer versus Real-time detections check, then a review of what is actually enabled: Safe Links, Safe Attachments including SharePoint, OneDrive, and Teams coverage, anti-phishing policies, quarantine policies, and whether preset security policies are in use or custom policies nobody has reviewed since they were created.

  2. 2

    Configure impersonation protection and priority accounts

    Week 1

    Your executives and finance team named in user impersonation protection, your own domains and significant vendor domains in domain impersonation protection, mailbox intelligence enabled, priority accounts tagged, external sender warnings on. This step needs a business decision about who to protect, not just an administrator, and we run that conversation with you.

  3. 3

    Enable Safe Links and Safe Attachments, then tune

    Weeks 1-2

    Policies rolled out from the Standard preset, extended to SharePoint, OneDrive, and Teams, then a deliberate false-positive burn-in: quarantine policies set so users can release low-risk items themselves, allow-list entries for the legitimate Indian senders that trip filters, and daily triage until the noise settles. We do not hand over a quarantine your users hate.

  4. 4

    Stand up investigation and simulation, if Plan 2

    Weeks 2-3

    Threat Explorer walkthrough with whoever will use it, automated investigation enabled for user-reported phishing, the report-phishing button tested end to end, and the first attack simulation training campaign designed around lures your staff actually receive. If you are on Plan 1, we activate the 90-day Plan 2 trial here so you can judge the difference on your own tenant.

  5. 5

    Handover or managed operation

    Week 4 onward

    Documented configuration, a tuning runbook, and a monthly report format for leadership. Organisations without a security function usually move to our managed service: we watch the queues, triage reported phishing, run the quarterly simulations and tuning reviews, and respond to P1 email incidents within the 30 minutes managed-client SLA.

Straight answers

What Indian organisations ask about Defender for Office 365.

Check your own tenant

Fifteen checks, and the first one takes ten seconds.

The first group establishes what you hold and whether it is switched on. The second is the impersonation and payment-fraud layer specifically. The third is what you could actually do after an incident, which is where DPDP and CERT-In obligations get decided.

What you have

  • Does Email and collaboration in the Defender portal show Explorer, or Real-time detections?
    Explorer means Plan 2, Real-time detections means Plan 1. Microsoft publishes this as the quick differentiator.
  • Are Safe Links and Safe Attachments actually enabled for all users?
    Included at Plan 1 and frequently disabled or scoped to a forgotten pilot group.
  • Does Safe Attachments cover SharePoint, OneDrive, and Teams?
    A separate setting from email, and the one most tenants miss.
  • Are you on preset security policies, or custom policies nobody reviews?
    Standard and Strict presets are maintained by Microsoft; stale custom policies are frozen at whoever left last.
  • Have you used the Plan 2 trial to see what Explorer adds?
    Microsoft offers a 90-day trial through the Defender portal trials hub.

The payment-fraud layer

  • Is user impersonation protection configured with your executives named?
    It protects named people, so somebody has to name them. Default is an empty list.
  • Is domain impersonation protection configured for your domains and key vendors?
    Lookalike domains are the standard invoice-fraud vehicle.
  • Are priority accounts tagged?
    Finance, directors, anyone who can change payment details.
  • Do external emails carry a visible warning tag?
    Cheap, and effective against display-name tricks.
  • Does a bank-detail change require phone verification to a known number?
    The one control no licence tier can replace.

Could you investigate afterwards

  • Could you find everyone else who received a given message?
    Threat Explorer at Plan 2, a narrower view at Plan 1.
  • Would you know whether a link was clicked?
    URL trace and the email entity page start at Plan 1.
  • Does your log retention meet the CERT-In 180-day expectation?
    A separate question from your Defender plan, and audited in our email security audit.
  • Are SPF, DKIM, and DMARC published and enforced for your domains?
    Microsoft states these improve its own spoofing protection.
  • Has anyone tested the report-phishing flow end to end?
    A report button that goes nowhere trains staff to stop using it.
Next step

Open the Defender portal and look at Email and collaboration.

Explorer means Plan 2, Real-time detections means Plan 1. Then check whether impersonation protection has any names in it. Those two answers tell you whether your next move is a purchase or a fortnight of configuration, and in most Indian tenants we review, it is the second. Tell us what you found and we will reply within 4 business hours.