Key Takeaways
- Microsoft 365 phishing protection is the set of Exchange Online Protection and Defender for Office 365 controls, including anti-phishing policies, Safe Links, Safe Attachments and zero-hour auto purge (ZAP), that block or remove phishing email.
- Defender's default anti-phishing policy takes no action on user or domain impersonation, while the Standard and Strict presets quarantine it.
- Strict raises the phishing email threshold from 3 to 4 and quarantines spoof and mailbox-intelligence detections that Standard sends to Junk.
- Preset policies take precedence over custom policies: Strict applies first, then Standard, then custom and default policies.
- ZAP moves phishing out of inboxes up to 48 hours after delivery, but allowlists and mail flow rules can override it.
- Defender for Office 365 Plan 1 comes with Microsoft 365 Business Premium and, since 1 July 2026, Office 365 E3 and Microsoft 365 E3; Plan 2 comes with E5.
Phishing protection in Microsoft 365 means blocking impersonation, spoofing and malicious links or attachments before users act, then cleaning up fast when one gets through. Many tenants already own the tools in Microsoft Defender for Office 365 but run them on default settings, which take no action on impersonation. The verdict: apply Microsoft's Standard preset to most users, Strict to high-value accounts, and tune from there.
How Do You Stop Phishing Attacks in Microsoft 365?
Apply Defender for Office 365's preset security policies and protect your key people and domains from impersonation. Then enforce email authentication and confirm that zero-hour auto purge and user reporting work.
- Confirm your plan. In the Microsoft Defender portal, Real-time detections means Plan 1 and Explorer means Plan 2. E3 tenants have been receiving Plan 1 since June 2026, so check what it switched on.
- Apply the presets. Assign Strict to priority users and Standard to everyone else. Both switch on Safe Links and Safe Attachments.
- Protect the people attackers copy. Add executives, finance staff and anyone who sends invoices to user impersonation protection, plus key partner domains. Your own domains are covered automatically.
- Enforce email authentication. Publish Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) records, then move DMARC (Domain-based Message Authentication, Reporting and Conformance) toward p=reject.
- Check zero-hour auto purge. In your anti-spam policies, confirm ZAP for phishing is on and the Phishing action is Quarantine or Move to Junk.
- Turn on user reporting. Keep the built-in Report button on in Outlook and review what users report every week.
- Require phishing-resistant multifactor authentication (MFA) for high-value accounts. In one CyberQuell investigation, session token theft bypassed app-based MFA, and the fix included FIDO2 security keys.
For the click-by-click setup behind each step, work through our Microsoft 365 email security deployment checklist.
What Phishing Attacks Get Past Default Microsoft 365 Protection?
Built-in protection handles spoofing, known malware and bulk mail, but it can't check for impersonation and has no Safe Links or Safe Attachments. Defender for Office 365 adds all three, yet its default policy still takes no action on impersonation.
Microsoft's recommended settings documentation confirms that the default policy leaves impersonation protection and phishing thresholds unconfigured. That gap matters. In August 2026, Microsoft tracked more than a million emails that impersonated CEOs in the display name and signature, used a lookalike vendor domain, and asked finance teams for payments of nearly $50,000.
For the wider picture of what Microsoft Defender protects you from, see our Defender for Office 365 guide.
Core Defender Features That Actually Stop Phishing, If You Set Them Up Right
Five controls do most of the work: impersonation protection, spoof intelligence with DMARC enforcement, Safe Links, Safe Attachments and zero-hour auto purge. Three of them run on default settings, but impersonation protection needs setting up and Safe Links stays weaker until you apply a preset.
Built-in protection covers anyone outside a preset, but it skips internal email, doesn't rewrite URLs and lets users click through blocked links. Move everyone onto Standard or Strict.
What Zero-Hour Auto Purge Can and Can't Do
Zero-hour auto purge pulls phishing out of mailboxes after delivery, but only within 48 hours and only when your policies let it act.
- It only searches email delivered in the last 48 hours.
- It acts on phishing whether or not the message has been read.
- The phishing action comes from your anti-spam policy, not your anti-phishing policy.
- It takes no action if that action is Add X-Header, Prepend subject, Redirect or Delete.
- Allowlists and mail flow rules can override it.
- High-confidence phishing is quarantined, and by default only admins can manage it.
- Users aren't notified when it moves a message.
- ZAP for Teams needs Plan 1 or Plan 2 and doesn't cover external chats or private channels.
Moving a message doesn't undo a click. If someone opened the link before ZAP acted, treat it as a possible compromise and follow the response steps below. To see what ZAP moved, check the Mailflow status report or filter Threat Explorer for the ZAP action.
Standard vs Strict: The Exact Anti-Phishing Settings Microsoft Recommends
Use Standard for most users and Strict for high-value targets. Strict raises the phishing threshold from 3 to 4 and quarantines spoof and mailbox-intelligence detections. The default policy takes no action on impersonation at all. Apply both under Threat policies > Preset security policies in the Microsoft Defender portal.
Default vs Standard vs Strict, Setting by Setting
Microsoft publishes exact values for all three levels, and the gap between Default and Standard is far bigger than the gap between Standard and Strict.
Default is weaker than Standard on 10 of these 12 settings; only the spoof action and DMARC honouring match. Strict differs from Standard on just 3: the threshold, the mailbox-intelligence action and the spoof action.
The presets tighten bulk mail too. The bulk complaint level threshold drops from 7 by default to 6 in Standard and 5 in Strict. Threshold level 1 is labelled "Standard" in Microsoft's scale, which is different from the Standard preset. All values come from Microsoft's recommended settings.
Why Custom Policies Don't Override Presets
Preset policies always win: Strict applies first, then Standard, then any custom or default policy.
- You can't change the individual settings inside a preset.
- If some users need different values, leave them out of the preset and cover them with a custom policy.
- Keep recipient groups unambiguous, so the order of precedence doesn't decide the outcome for you.
Who Belongs in Strict?
Put the accounts attackers most want to impersonate or compromise in Strict, and leave everyone else on Standard:
- Executives
- Finance and payment approvers
- Shared accounts-payable mailboxes
- IT administrators
- Priority accounts (Plan 2 adds extra priority account protection)
Microsoft also recommends adding senders in key roles to user impersonation protection. Include staff who send invoices or payment instructions, since theirs are the names attackers copy. Strict quarantines more, so expect more release requests. For the five configurations to set first, see our Defender for Office 365 guide.
If you're not sure how far your tenant sits from these values, CyberQuell's free email security assessment reviews your current email security settings and licence coverage.
How to Reduce False Positives Without Weakening Phishing Protection
Fix false positives with narrow, time-limited exceptions. Broad allowlists and mail flow rules also let phishing through, and they can stop zero-hour auto purge from removing it later.
- Do report false positives as admin submissions. The allow entry this creates in the Tenant Allow/Block List covers only that sender, domain, file or URL and expires 45 days after last use.
- Do use the Advanced Delivery policy for third-party phishing simulation URLs and security team mailboxes.
- Do add partners that keep getting flagged as impersonation to the trusted senders and domains in your impersonation settings.
- Don't create mail flow rules that bypass filtering, or allow whole domains in anti-spam policies. They stay until someone removes them, and both can override ZAP.
- Don't pull a user out of the presets because Strict is too tight. Move them to Standard.
Even submission allow entries stop ZAP acting on malware and high-confidence phishing for that item, so use them only for messages you've confirmed are clean.
What to Do When a Phishing Email Gets Through
Find everyone who received the message, pull it from every mailbox, and secure any account that clicked or entered credentials. Then check for persistence before closing the incident, because a password reset won't remove an attacker who has built another way back in.
Phishing Response Checklist
- Scope every recipient using Real-time detections (Plan 1) or Threat Explorer (Plan 2).
- Remove the message from all mailboxes.
- If anyone clicked or entered credentials, reset the password, revoke sessions and require MFA re-registration.
- Check for persistence: inbox rules (including rules that hide replies), forwarding, delegated access, OAuth app consents and new MFA devices.
- Review mailbox audit logs and Microsoft Entra sign-in logs.
- Block the sender, domain and URL in the Tenant Allow/Block List.
- Harden: move high-value targets to Strict and close the gap that let the attacker in, such as legacy authentication or weak MFA.
Plan 2 adds automated investigation and response (AIR), which can investigate these incidents and recommend remediation actions for you.
Two Real Microsoft 365 Account Compromises
Two CyberQuell investigations show why step 4 matters: one account was contained in hours, while the other stayed compromised for four months.
Read the full phishing account compromise investigation and the four-month multi-phase BEC investigation.
Do You Need a Managed Phishing Service for Microsoft 365?
If you already license Defender for Office 365, a managed service mostly adds people, not filters. You're paying for round-the-clock triage, ongoing tuning and fast response when an account is compromised.
What a Managed Phishing Service Should Actually Do
For example, CyberQuell's managed Defender for Office 365 service commits to triage within 30 minutes and containment within 4 hours. Microsoft also offers its own managed option, Defender Experts MDR.
Adding Another Email Filter: What Microsoft's Own Benchmark Shows
Microsoft's data shows that add-on email filters mostly help with bulk mail and add little against malicious email.
Microsoft-published telemetry, not independent testing.
Microsoft also reports that missed threats rose across vendors, Defender included, as AI makes impersonation easier to tailor. Another filter rarely changes your malicious-email results; staffing and response do. A separate gateway can still make sense for other reasons, such as complex mail routing or mixed email platforms.
To compare providers, see our list of Microsoft Defender specialists for managed email security, or read whether Defender is enough on its own.
Final Thoughts
Phishing protection in Microsoft 365 comes down to one decision: leave Defender on its defaults, or move it to Standard and Strict. If you're on Business Premium or E3, you already own the core controls in this guide. Default is weaker than Standard on 10 of 12 anti-phishing settings, so start with the presets and your protected-users list. Then decide who watches what gets through after hours.
Book a call with CyberQuell to review your Defender for Office 365 settings and licence coverage, and see where your tenant stands.

%20for%20Microsoft%20365%20(1).png)
.png)
.png)