Skip to main content
Defender for Office 365, India

The layer above Exchange Online Protection that stops phishing, invoice fraud, and malicious attachments.

Exchange Online Protection catches bulk spam. It does not catch the single well-written email that convinces your accounts team to pay a fraudulent invoice. Defender for Office 365 adds Safe Links, Safe Attachments, and impersonation protection at Plan 1, and investigation, automation, and phishing simulation at Plan 2. We deploy it, tune it so quarantine does not drown your users, and run it, remote-first from Gachibowli, Hyderabad, for organisations across India.

Microsoft
Microsoft
Defender
Cloud Solution Partner
  • Three tiersEOP, Plan 1, Plan 2
  • Plan 1Inside Business Premium
  • Plan 2Inside Microsoft 365 E5
  • 30 minManaged-client SLA
What each tier actually does

Eight things to understand before you touch a licence.

Microsoft describes email protection as a ladder with three rungs, not a product with two editions. Every organisation with cloud mailboxes already stands on the bottom rung. The question for an Indian business is not "do we have email security" but "which rung are we on, and is any of it configured". These eight points settle that.

Exchange Online Protection: what everyone already has

Every Microsoft 365 subscription with cloud mailboxes includes EOP: anti-malware, anti-spam with bulk mail handling, spoof intelligence, connection filtering, quarantine with quarantine policies, the Tenant Allow/Block List, message trace, and zero-hour auto purge. Microsoft positions it as protection against broad, volume-based, known attacks. It is genuinely good at that. Volume spam is not what costs Indian businesses money. Targeted impersonation is.

Safe Links: the URL is checked when clicked, not when delivered

Attackers routinely send a clean URL that turns malicious an hour after delivery, once filters have passed it. Safe Links rewrites URLs in email, Teams, and Office documents so every click is checked at click time against current intelligence. It arrives at Plan 1, and in a large share of the Indian tenants we review it is licensed and either disabled or scoped to a pilot group somebody forgot to expand.

Safe Attachments: detonation before delivery

Safe Attachments opens every inbound attachment in a sandbox and watches what it does before the user ever sees it, which is how zero-day malware in an innocuous-looking invoice PDF gets caught. It covers email at Plan 1, and, in a separately enabled setting most tenants miss, files in SharePoint, OneDrive, and Teams. If your teams share files through Teams more than email, that second setting matters more than the first.

Impersonation protection: the anti-BEC layer

Business email compromise arrives as a message pretending to be your managing director, your CFO, or a supplier, usually with no malware and no link, just an instruction about a payment. Impersonation protection at Plan 1 defends specific named users and specific domains, plus mailbox intelligence that learns who each person actually corresponds with. It ships with an empty list. Somebody has to name your executives and your critical supplier domains, and in most tenants nobody ever has.

Where the plans sit in subscriptions you may already hold

Microsoft gives Microsoft 365 Business Premium, E3, and G3 as examples of subscriptions that include Defender for Office 365 Plan 1, and A5, E5, and G5 as examples that include Plan 2. Both plans are also available as add-ons. So a company on Business Premium already owns Safe Links, Safe Attachments, and impersonation protection whether or not anyone configured them, and the first question is configuration, not purchase.

Plan 2: Threat Explorer and automated investigation

Plan 2 is the investigation tier. Threat Explorer answers "who else received this message, who clicked, and what happened next" in minutes. Campaigns groups related attacks so you see the whole wave, not one report. Automated Investigation and Response triages reported phishing and compromised-user signals without a human working every queue item. If CERT-In reporting timelines apply to you, this is the tier that lets you reconstruct an email incident fast enough to meet them.

Attack simulation training: test your staff before attackers do

Plan 2 includes attack simulation training: controlled phishing campaigns sent to your own staff from inside the platform, with automatic micro-training for anyone who clicks. Run quarterly, it turns "we did awareness training once" into a measured click-rate trend you can show leadership and auditors. We design the scenarios around what your staff actually receive, invoice themes for finance, courier notifications for operations, HR themes for everyone.

The tuning problem: protection users can live with

Turn everything to Strict on day one and your users will spend the week fishing legitimate vendor emails out of quarantine, and by week three they will distrust the system and you. Tuning is the real work: preset policies as the baseline, quarantine policies that let users release low-risk items themselves and request release for high-risk ones, allow-list hygiene for the Indian vendors and portals that trip filters, and a review cadence that keeps false positives falling instead of accumulating.

The attack that actually costs money

The email that empties a bank account does not look like spam.

Every rung of the ladder handles bulk spam well. The losses we see in Indian organisations come from one convincing message about a payment, and where you sit on the ladder decides whether you can stop it arriving and reconstruct it afterwards.

  • Business email compromise usually carries no attachment, no link, and no malware, just a well-written instruction that impersonates somebody the recipient trusts. Volume-based filtering has almost nothing to work with. Impersonation protection, which starts at Plan 1, is the control aimed squarely at this, and it only works after somebody configures it with your executives and supplier domains.
  • The harder variant is a genuine message from a genuinely compromised mailbox, often at a vendor rather than at you. Nothing is spoofed, so no filter flags it. The control that stops the loss is procedural: any change of bank details gets verified by phone to a previously known number before a rupee moves. We say that plainly because it outperforms every licence tier on this specific risk.
  • Plan 2 earns its keep afterwards. When leadership asks what happened, who else received it, and whether anything was clicked, Threat Explorer, Campaigns, and automated investigation answer in minutes. That speed also matters for CERT-In, whose directions require covered incidents to be reported within six hours of noticing, and for DPDP Act breach notification, where you need to establish scope quickly and defensibly.
  • And separately from every tier: publish and enforce SPF, DKIM, and DMARC. Microsoft states those records let it protect more accurately against spoofing, and they stop your own domain being used against your customers, which no inbound plan addresses.
Ask us to check your tier and your impersonation policies
How we approach it

Four things that matter more than which plan you buy.

Email security is where the gap between licensed capability and configured capability is widest, and where the most expensive attacks are the ones no filter was ever going to catch. Our engagement model is built around both facts.

We establish your tier before discussing upgrades

The Explorer versus Real-time detections check takes ten seconds and settles what you hold. In a meaningful share of engagements the organisation already owns Plan 1 through Business Premium or E3 and has configured none of it, which makes the work configuration rather than purchase. Recommending Plan 2 to a tenant running Plan 1 at defaults would be selling capacity to somebody not using what they have.

We configure impersonation protection around real people

Impersonation protection works on named users and named domains, so somebody has to decide who and what to protect: your directors, your finance team, anyone who can change payment details, your own domains, and your significant vendors. That is a short exercise, it is included from Plan 1, and it is the single most targeted control against the attack that actually costs Indian businesses money.

We tune until users stop noticing

A deployment that quarantines the tenant's legitimate vendor mail is a failed deployment, whatever the licence says. We baseline your mail flow first, start from the Standard preset, tune quarantine policies so users can self-release low-risk items, whitelist the Indian portals and banks that trip filters, and review false positives on a fixed cadence until the quarantine digest is boring. Boring is the goal.

We map it to DPDP and CERT-In, in writing

If you process personal data, the DPDP Act expects reasonable security safeguards and breach notification, and CERT-In directions expect covered incidents reported within six hours of noticing and logs retained for 180 days. We document how your Defender configuration, quarantine evidence, and investigation capability support each obligation, so the answer to an auditor or a client security questionnaire is a document, not a scramble.

Who needs this

Six Indian situations that justify doing this properly.

Invoice fraud is the common thread. It is the email attack that most reliably costs Indian organisations real money, and every one of these situations raises the odds of it landing.

Any business whose finance team pays invoices from email

Which is nearly all of them, and it is why this page exists. The impersonation protection that starts at Plan 1 is aimed squarely at the message pretending to be your director or your supplier asking for a payment or a bank-detail change. Configuring it around the specific people who authorise payments is a short piece of work with a direct line to the loss it prevents.

A company that has already seen a CEO-fraud attempt

A payment nearly went to the wrong account, or somebody received a convincing message from "the MD" that turned out to be a lookalike address. This is the right moment to act, because the organisation has just experienced the exact risk and the budget conversation is already won. The work is usually configuration plus a payment-verification process change, not a licence upgrade.

A business on Microsoft 365 Business Premium or E3

Both include Defender for Office 365 Plan 1, so you already own impersonation protection, Safe Links, and Safe Attachments whether or not anyone switched them on. The useful question is not "should we buy email security" but "is the email security we pay for actually configured", and the answer, in most tenants we review, is not yet.

DPDP data fiduciaries and processors

If you hold personal data of Indian data principals, email is your most likely breach vector, and the DPDP Act expects reasonable security safeguards and breach notification to the Data Protection Board. A tuned Defender for Office 365 deployment is a demonstrable safeguard, and Plan 2 investigation capability is what lets you establish breach scope quickly enough to notify defensibly.

Exporters and firms with foreign clients

IT services companies, exporters, and anyone answering client security questionnaires from the US, EU, or elsewhere. "What email threat protection do you run, and can you investigate an incident" appears on nearly every vendor assessment. A configured MDO deployment with documented policies turns that question from a liability into a checkbox, and often keeps a deal alive.

Organisations replacing or reviewing a third-party gateway

Many Indian tenants still route mail through a legacy email security gateway bought before Defender matured. Running both means two filtering layers, two quarantines, and double administration, and the gateway often breaks the authentication signals Defender relies on. We review honestly whether the gateway still earns its cost, and decommission it safely when it does not.

What we find in Indian tenants

Three positions, and the middle one is the most common.

The middle column is the pattern we see most across India: the licence includes impersonation protection, Safe Links, and Safe Attachments, none of it is configured, and the organisation is effectively running bare EOP while paying for more. The fix there is configuration and tuning, not a purchase.
Feature
Tier known and tuned
Licensed, default settings
EOP only
Knows which plan it holds
YesAssumesCorrect by default
Safe Links and Safe Attachments enabled
YesPartlyNot available
Impersonation protection has names in it
YesNoNot available
Quarantine policies users can live with
YesDefaultsDefaults
Safe Attachments covers SharePoint and Teams
YesRarelyNot available
External sender warning in place
YesSometimesSometimes
Phishing simulations run on staff
QuarterlyNoNo
Could reconstruct who else got a message
MinutesHours to daysBarely
Payment changes verified out of band
YesSometimesRarely
Frequency in the Indian market
UncommonVery commonCommon in SMEs
EOP vs Plan 1 vs Plan 2

The three rungs side by side.

Reproduced from Microsoft published comparison. The EOP column applies to every Microsoft 365 subscription with cloud mailboxes, so it is what you have even if you have never bought anything extra. Plan 1 ships inside Business Premium, E3, and G3. Plan 2 ships inside A5, E5, and G5.
CapabilityEOP built-inPlan 1Plan 2
Anti-malware, anti-spam, spoof intelligenceYesYesYes
Quarantine, Tenant Allow/Block List, message traceYesYesYes
Zero-hour auto purge for emailYesYesYes
User and domain impersonation protectionNoYesYes
Mailbox intelligence, contact-graph impersonationNoYesYes
Safe Attachments, email plus SharePoint, OneDrive, TeamsNoYesYes
Safe Links in email, Office clients, and TeamsNoYesYes
Real-time detections viewNoYesReplaced by Explorer
Email entity page and user tagsNoYesYes
Threat ExplorerNoNoYes
Threat Trackers and CampaignsNoNoYes
Attack simulation trainingNoNoYes
Automated Investigation and ResponseNoNoYes
Priority account protectionNoNoYes
Safe DocumentsNoNoNo, needs A5 or Defender Suite
How an engagement runs

Five steps, starting with a ten-second check.

Typically two to four weeks end to end, run remotely from our Gachibowli, Hyderabad base for organisations anywhere in India. Most of the value is configuration of capability you already hold, so the licence question is settled first and frequently turns out not to be the issue. You get an initial reply to any enquiry within 4 business hours.
  1. 1

    Establish the tier and what is configured

    Days 1-2

    The Explorer versus Real-time detections check, then a review of what is actually enabled: Safe Links, Safe Attachments including SharePoint, OneDrive, and Teams coverage, anti-phishing policies, quarantine policies, and whether preset security policies are in use or custom policies nobody has reviewed since they were created.

  2. 2

    Configure impersonation protection and priority accounts

    Week 1

    Your executives and finance team named in user impersonation protection, your own domains and significant vendor domains in domain impersonation protection, mailbox intelligence enabled, priority accounts tagged, external sender warnings on. This step needs a business decision about who to protect, not just an administrator, and we run that conversation with you.

  3. 3

    Enable Safe Links and Safe Attachments, then tune

    Weeks 1-2

    Policies rolled out from the Standard preset, extended to SharePoint, OneDrive, and Teams, then a deliberate false-positive burn-in: quarantine policies set so users can release low-risk items themselves, allow-list entries for the legitimate Indian senders that trip filters, and daily triage until the noise settles. We do not hand over a quarantine your users hate.

  4. 4

    Stand up investigation and simulation, if Plan 2

    Weeks 2-3

    Threat Explorer walkthrough with whoever will use it, automated investigation enabled for user-reported phishing, the report-phishing button tested end to end, and the first attack simulation training campaign designed around lures your staff actually receive. If you are on Plan 1, we activate the 90-day Plan 2 trial here so you can judge the difference on your own tenant.

  5. 5

    Handover or managed operation

    Week 4 onward

    Documented configuration, a tuning runbook, and a monthly report format for leadership. Organisations without a security function usually move to our managed service: we watch the queues, triage reported phishing, run the quarterly simulations and tuning reviews, and respond to P1 email incidents within the 30 minutes managed-client SLA.

Straight answers

What Indian organisations ask about Defender for Office 365.

For bulk spam and known malware, yes, and it is included with every cloud mailbox: anti-malware, anti-spam, spoof intelligence, quarantine, message trace, and zero-hour auto purge. What it lacks is the targeted-attack layer. It has no user or domain impersonation protection, no attachment detonation, and no click-time URL checking. The attacks that cost Indian businesses money, invoice fraud and credential phishing aimed at specific people, are precisely the ones EOP is weakest against. If your finance team pays invoices that arrive by email, EOP alone is not enough.

Plan 1 is prevention: Safe Links, Safe Attachments including SharePoint, OneDrive, and Teams coverage, and impersonation protection for named users and domains. Plan 2 is everything in Plan 1 plus investigation and response: Threat Explorer, Threat Trackers, Campaigns, Automated Investigation and Response, priority account protection, and attack simulation training. The practical test: if an employee reports a phishing email, Plan 1 lets you see the message and its verdict; Plan 2 lets you find every other recipient, see who clicked, purge it from all mailboxes, and trigger an automated investigation, in minutes rather than a day of manual message traces. Plan 1 ships inside Business Premium, E3, and G3; Plan 2 inside A5, E5, and G5.

Open the Microsoft Defender portal and look under Email and collaboration. If you see Explorer, you have Plan 2. If you see Real-time detections, you have Plan 1. Microsoft publishes this as the quick way to differentiate the plans, it takes ten seconds, and it needs no licensing expertise. It is worth doing before any purchase conversation, because a surprising number of organisations discover they already hold more than they thought, especially those on Business Premium who assume it is a basic bundle.

Untuned, yes, and that is the most common reason MDO deployments quietly get watered down. The fix is quarantine policies matched to risk: users receive a daily quarantine digest, can release low-risk items like bulk mail themselves, and can request release for higher-risk verdicts with an admin approving. Combined with a two-week false-positive burn-in where we whitelist the legitimate senders your filters trip on, most tenants settle at a level where users check the digest occasionally and rarely find anything they wanted. If your users are fishing real vendor mail out of quarantine weekly, the deployment is mistuned, not too strict by design.

Yes, and done properly it is one of the most defensible security controls you can run. Attack simulation training in Plan 2 is a sanctioned Microsoft feature operating inside your own tenant on your own employees. The ethical guardrails matter: get leadership sign-off, frame it as training rather than a trap, never use cruel lures like fake salary revisions or job terminations, attach immediate micro-training to a click instead of naming and shaming, and report click rates as team-level trends rather than individual blacklists. Run that way, it measurably drops click rates quarter over quarter and gives you an answer when a client questionnaire asks whether staff are tested.

First, stop any payment in motion: phone the bank, and phone the counterparty on a previously known number, not a number from the suspicious email. Second, preserve the evidence: do not delete the message, and note who received it. Third, contain: if a mailbox looks compromised, reset the password, revoke active sessions, and check for attacker-added forwarding rules, which are the classic persistence trick. Fourth, investigate scope, which is where Threat Explorer earns its licence, and remember CERT-In directions require covered incidents to be reported within six hours of noticing. If you are a managed client, raise it as a P1 and a senior engineer is on it within 30 minutes. If you are not, contact us and you will get an initial reply within 4 business hours.

They can, but usually badly. Routing mail through a gateway before Exchange Online breaks the sending-IP signals EOP and Defender use, so you must configure enhanced filtering for connectors or Defender misjudges every message. You also run two quarantines, two policy sets, and two allow lists, which doubles administration and creates gaps where each layer assumes the other caught something. Our honest review question is what the gateway still does that your Defender licence does not. Where the answer is nothing, and post-2020 it often is, we decommission the gateway in a controlled cutover. Where it covers non-Microsoft mail flows or a specific contractual requirement, we keep it and fix the connector configuration so Defender still works.

Weekly triage in the first month, then a monthly rhythm: review false positives and false negatives, prune allow-list entries that have expired their justification, check that impersonation lists still match the current executive team and vendor set, and re-verify that Safe Links and Safe Attachments still cover all users after licence and group changes. Quarterly, we run an attack simulation campaign and a policy review against Microsoft's current preset baselines, which move as the threat picture moves. Email protection is not fire-and-forget; a tenant tuned eighteen months ago and untouched since drifts back toward noisy or blind, usually both.

A monthly one-page summary in plain language: messages blocked by category (phishing, malware, spoof, bulk), impersonation attempts against named executives, top targeted users, quarantine false-positive rate and trend, user-reported phishing volume and outcomes, and simulation click rates against the previous quarter. For boards and audit committees we add a compliance view: how the configuration maps to DPDP reasonable-safeguard expectations and CERT-In readiness, and any incidents with response timelines. The goal is that a director who reads nothing else about security can see in two minutes whether email risk is rising or falling.

Yes, and this is one of the most missed settings. Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is included from Plan 1 but enabled separately from email protection. Safe Links coverage extends to links in Teams messages and Office clients. Since a large share of file sharing has moved out of email into Teams, an organisation that enabled Safe Attachments for email only has protected the channel people use less and left open the one they use more. We enable and verify collaboration coverage in every deployment.

No, they address different directions. Defender for Office 365 protects mail arriving at your organisation. SPF, DKIM, and DMARC govern whether somebody can send mail that appears to come from your domain to your customers, banks, and partners. Microsoft states directly that those DNS records let Microsoft 365 protect more accurately against spoofing, so they improve your inbound protection too, but the main benefit is outbound, and no Defender plan substitutes for it. We treat authentication as part of the same engagement, and our email security audit covers it in depth.

Two to four weeks for a typical Indian organisation, and yes, entirely remotely. Defender for Office 365 is cloud configuration, there is nothing to install on site, so we run every engagement remote-first from Gachibowli, Hyderabad for clients across India. The elapsed time is not technical work; it is the false-positive burn-in, which cannot be compressed without hurting users, and the impersonation-list decisions, which need someone in your leadership to confirm who counts as protected and which vendor domains matter.

Yes. Microsoft offers a 90-day Defender for Office 365 Plan 2 trial through the trials hub in the Defender portal. That is the sensible way to decide, because the Plan 2 question is really "would anybody here use the investigation tooling". Use the trial to run one real investigation on one real reported message and one simulation campaign, then judge whether the answers you got were worth having permanently. We set the trial up as part of any Plan 1 engagement so the decision is made on evidence from your own tenant rather than a feature list.
Check your own tenant

Fifteen checks, and the first one takes ten seconds.

The first group establishes what you hold and whether it is switched on. The second is the impersonation and payment-fraud layer specifically. The third is what you could actually do after an incident, which is where DPDP and CERT-In obligations get decided.

What you have

  • Does Email and collaboration in the Defender portal show Explorer, or Real-time detections?
    Explorer means Plan 2, Real-time detections means Plan 1. Microsoft publishes this as the quick differentiator.
  • Are Safe Links and Safe Attachments actually enabled for all users?
    Included at Plan 1 and frequently disabled or scoped to a forgotten pilot group.
  • Does Safe Attachments cover SharePoint, OneDrive, and Teams?
    A separate setting from email, and the one most tenants miss.
  • Are you on preset security policies, or custom policies nobody reviews?
    Standard and Strict presets are maintained by Microsoft; stale custom policies are frozen at whoever left last.
  • Have you used the Plan 2 trial to see what Explorer adds?
    Microsoft offers a 90-day trial through the Defender portal trials hub.

The payment-fraud layer

  • Is user impersonation protection configured with your executives named?
    It protects named people, so somebody has to name them. Default is an empty list.
  • Is domain impersonation protection configured for your domains and key vendors?
    Lookalike domains are the standard invoice-fraud vehicle.
  • Are priority accounts tagged?
    Finance, directors, anyone who can change payment details.
  • Do external emails carry a visible warning tag?
    Cheap, and effective against display-name tricks.
  • Does a bank-detail change require phone verification to a known number?
    The one control no licence tier can replace.

Could you investigate afterwards

  • Could you find everyone else who received a given message?
    Threat Explorer at Plan 2, a narrower view at Plan 1.
  • Would you know whether a link was clicked?
    URL trace and the email entity page start at Plan 1.
  • Does your log retention meet the CERT-In 180-day expectation?
    A separate question from your Defender plan, and audited in our email security audit.
  • Are SPF, DKIM, and DMARC published and enforced for your domains?
    Microsoft states these improve its own spoofing protection.
  • Has anyone tested the report-phishing flow end to end?
    A report button that goes nowhere trains staff to stop using it.
Next step

Open the Defender portal and look at Email and collaboration.

Explorer means Plan 2, Real-time detections means Plan 1. Then check whether impersonation protection has any names in it. Those two answers tell you whether your next move is a purchase or a fortnight of configuration, and in most Indian tenants we review, it is the second. Tell us what you found and we will reply within 4 business hours.