Cybersecurity

9 mins

How to Stop Phishing Attacks in Microsoft 365 Using Defender, Without Losing Your Mind

Last Updated
October 7, 2026
How to Stop Phishing Attacks in Microsoft 365 Using Defender, Without Losing Your Mind

Key Takeaways 

  • Microsoft 365 phishing protection is the set of Exchange Online Protection and Defender for Office 365 controls, including anti-phishing policies, Safe Links, Safe Attachments and zero-hour auto purge (ZAP), that block or remove phishing email.
  • Defender's default anti-phishing policy takes no action on user or domain impersonation, while the Standard and Strict presets quarantine it.
  • Strict raises the phishing email threshold from 3 to 4 and quarantines spoof and mailbox-intelligence detections that Standard sends to Junk.
  • Preset policies take precedence over custom policies: Strict applies first, then Standard, then custom and default policies.
  • ZAP moves phishing out of inboxes up to 48 hours after delivery, but allowlists and mail flow rules can override it.
  • Defender for Office 365 Plan 1 comes with Microsoft 365 Business Premium and, since 1 July 2026, Office 365 E3 and Microsoft 365 E3; Plan 2 comes with E5.

Phishing protection in Microsoft 365 means blocking impersonation, spoofing and malicious links or attachments before users act, then cleaning up fast when one gets through. Many tenants already own the tools in Microsoft Defender for Office 365 but run them on default settings, which take no action on impersonation. The verdict: apply Microsoft's Standard preset to most users, Strict to high-value accounts, and tune from there.

‍

How Do You Stop Phishing Attacks in Microsoft 365?

Apply Defender for Office 365's preset security policies and protect your key people and domains from impersonation. Then enforce email authentication and confirm that zero-hour auto purge and user reporting work.

  1. Confirm your plan. In the Microsoft Defender portal, Real-time detections means Plan 1 and Explorer means Plan 2. E3 tenants have been receiving Plan 1 since June 2026, so check what it switched on.
  2. Apply the presets. Assign Strict to priority users and Standard to everyone else. Both switch on Safe Links and Safe Attachments.
  3. Protect the people attackers copy. Add executives, finance staff and anyone who sends invoices to user impersonation protection, plus key partner domains. Your own domains are covered automatically.
  4. Enforce email authentication. Publish Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) records, then move DMARC (Domain-based Message Authentication, Reporting and Conformance) toward p=reject.
  5. Check zero-hour auto purge. In your anti-spam policies, confirm ZAP for phishing is on and the Phishing action is Quarantine or Move to Junk.
  6. Turn on user reporting. Keep the built-in Report button on in Outlook and review what users report every week.
  7. Require phishing-resistant multifactor authentication (MFA) for high-value accounts. In one CyberQuell investigation, session token theft bypassed app-based MFA, and the fix included FIDO2 security keys.

For the click-by-click setup behind each step, work through our Microsoft 365 email security deployment checklist.

‍

What Phishing Attacks Get Past Default Microsoft 365 Protection?

Built-in protection handles spoofing, known malware and bulk mail, but it can't check for impersonation and has no Safe Links or Safe Attachments. Defender for Office 365 adds all three, yet its default policy still takes no action on impersonation.

Attack Built-in protection only Defender for Office 365 on default settings What to switch on
Spoofing your own domain Spoof intelligence sends it to Junk; enforced DMARC is honoured Same Publish DMARC at p=reject
Executive or user impersonation (spear phishing) No impersonation checks Not configured, so no action User impersonation protection through the Standard or Strict preset
Lookalike domain No impersonation checks Not configured, so no action Domain impersonation protection, with partner domains added
Link weaponised after delivery Delivered; ZAP can remove it within 48 hours if later detected Safe Links through Built-in protection, without URL rewriting Safe Links through Standard or Strict
Zero-day attachment Delivered unless anti-malware recognises it Sandboxed by Safe Attachments through Built-in protection Already covered; the presets keep it on

Microsoft's recommended settings documentation confirms that the default policy leaves impersonation protection and phishing thresholds unconfigured. That gap matters. In August 2026, Microsoft tracked more than a million emails that impersonated CEOs in the display name and signature, used a lookalike vendor domain, and asked finance teams for payments of nearly $50,000.

For the wider picture of what Microsoft Defender protects you from, see our Defender for Office 365 guide.

‍

Core Defender Features That Actually Stop Phishing, If You Set Them Up Right

Five controls do most of the work: impersonation protection, spoof intelligence with DMARC enforcement, Safe Links, Safe Attachments and zero-hour auto purge. Three of them run on default settings, but impersonation protection needs setting up and Safe Links stays weaker until you apply a preset.

Feature What it stops When it acts Minimum licence Setting to check
Impersonation protection Mail pretending to come from your executives, staff or domains Before delivery Plan 1 Protected users and domains added; action set to Quarantine
Spoof intelligence and DMARC Senders forging a domain they don't own, including yours Before delivery All cloud mailboxes On by default; spoof action is Junk in Standard, Quarantine in Strict
Safe Links Malicious URLs, including links weaponised after delivery At delivery and again at click, in email, Teams and Office apps Plan 1 Users covered by Standard or Strict, not just Built-in protection
Safe Attachments Unknown and zero-day malware in attachments Before delivery, in a sandbox Plan 1 Unknown malware response set to Block (new custom policies start Off)
Zero-hour auto purge Phishing, spam and malware identified after delivery Up to 48 hours after delivery All Exchange Online mailboxes Phishing action in your anti-spam policy is Quarantine or Move to Junk

Built-in protection covers anyone outside a preset, but it skips internal email, doesn't rewrite URLs and lets users click through blocked links. Move everyone onto Standard or Strict.

What Zero-Hour Auto Purge Can and Can't Do

Zero-hour auto purge pulls phishing out of mailboxes after delivery, but only within 48 hours and only when your policies let it act.

  • It only searches email delivered in the last 48 hours.
  • It acts on phishing whether or not the message has been read.
  • The phishing action comes from your anti-spam policy, not your anti-phishing policy.
  • It takes no action if that action is Add X-Header, Prepend subject, Redirect or Delete.
  • Allowlists and mail flow rules can override it.
  • High-confidence phishing is quarantined, and by default only admins can manage it.
  • Users aren't notified when it moves a message.
  • ZAP for Teams needs Plan 1 or Plan 2 and doesn't cover external chats or private channels.

Moving a message doesn't undo a click. If someone opened the link before ZAP acted, treat it as a possible compromise and follow the response steps below. To see what ZAP moved, check the Mailflow status report or filter Threat Explorer for the ZAP action.

‍

Standard vs Strict: The Exact Anti-Phishing Settings Microsoft Recommends

Use Standard for most users and Strict for high-value targets. Strict raises the phishing threshold from 3 to 4 and quarantines spoof and mailbox-intelligence detections. The default policy takes no action on impersonation at all. Apply both under Threat policies > Preset security policies in the Microsoft Defender portal.

Default vs Standard vs Strict, Setting by Setting

Microsoft publishes exact values for all three levels, and the gap between Default and Standard is far bigger than the gap between Standard and Strict.

Setting Default Standard Strict
Phishing email threshold 1 - Standard 3 - More aggressive 4 - Most aggressive
User impersonation protection Off On (your user list) On (your user list)
Include domains I own Off On On
Action on user impersonation Don't apply any action Quarantine Quarantine
Action on domain impersonation Don't apply any action Quarantine Quarantine
Enable intelligence for impersonation protection Off On On
Mailbox-intelligence impersonation action Don't apply any action Move to Junk Quarantine
Spoof detected by spoof intelligence Move to Junk Move to Junk Quarantine
First contact safety tip Off On On
Impersonation safety tips Off On On
Honour DMARC (p=quarantine to quarantine; p=reject to reject) On On On
Quarantine policy for user/domain impersonation DefaultFullAccessPolicy DefaultFullAccessWithNotificationPolicy (users notified) DefaultFullAccessWithNotificationPolicy (users notified)

Default is weaker than Standard on 10 of these 12 settings; only the spoof action and DMARC honouring match. Strict differs from Standard on just 3: the threshold, the mailbox-intelligence action and the spoof action.

The presets tighten bulk mail too. The bulk complaint level threshold drops from 7 by default to 6 in Standard and 5 in Strict. Threshold level 1 is labelled "Standard" in Microsoft's scale, which is different from the Standard preset. All values come from Microsoft's recommended settings.

Why Custom Policies Don't Override Presets

Preset policies always win: Strict applies first, then Standard, then any custom or default policy.

  • You can't change the individual settings inside a preset.
  • If some users need different values, leave them out of the preset and cover them with a custom policy.
  • Keep recipient groups unambiguous, so the order of precedence doesn't decide the outcome for you.

Who Belongs in Strict?

Put the accounts attackers most want to impersonate or compromise in Strict, and leave everyone else on Standard:

  • Executives
  • Finance and payment approvers
  • Shared accounts-payable mailboxes
  • IT administrators
  • Priority accounts (Plan 2 adds extra priority account protection)

Microsoft also recommends adding senders in key roles to user impersonation protection. Include staff who send invoices or payment instructions, since theirs are the names attackers copy. Strict quarantines more, so expect more release requests. For the five configurations to set first, see our Defender for Office 365 guide.

If you're not sure how far your tenant sits from these values, CyberQuell's free email security assessment reviews your current email security settings and licence coverage.

‍

How to Reduce False Positives Without Weakening Phishing Protection

Fix false positives with narrow, time-limited exceptions. Broad allowlists and mail flow rules also let phishing through, and they can stop zero-hour auto purge from removing it later.

  • Do report false positives as admin submissions. The allow entry this creates in the Tenant Allow/Block List covers only that sender, domain, file or URL and expires 45 days after last use.
  • Do use the Advanced Delivery policy for third-party phishing simulation URLs and security team mailboxes.
  • Do add partners that keep getting flagged as impersonation to the trusted senders and domains in your impersonation settings.
  • Don't create mail flow rules that bypass filtering, or allow whole domains in anti-spam policies. They stay until someone removes them, and both can override ZAP.
  • Don't pull a user out of the presets because Strict is too tight. Move them to Standard.

Even submission allow entries stop ZAP acting on malware and high-confidence phishing for that item, so use them only for messages you've confirmed are clean.

‍

What to Do When a Phishing Email Gets Through

Find everyone who received the message, pull it from every mailbox, and secure any account that clicked or entered credentials. Then check for persistence before closing the incident, because a password reset won't remove an attacker who has built another way back in.

Phishing Response Checklist

  1. Scope every recipient using Real-time detections (Plan 1) or Threat Explorer (Plan 2).
  2. Remove the message from all mailboxes.
  3. If anyone clicked or entered credentials, reset the password, revoke sessions and require MFA re-registration.
  4. Check for persistence: inbox rules (including rules that hide replies), forwarding, delegated access, OAuth app consents and new MFA devices.
  5. Review mailbox audit logs and Microsoft Entra sign-in logs.
  6. Block the sender, domain and URL in the Tenant Allow/Block List.
  7. Harden: move high-value targets to Strict and close the gap that let the attacker in, such as legacy authentication or weak MFA.

Plan 2 adds automated investigation and response (AIR), which can investigate these incidents and recommend remediation actions for you.

Two Real Microsoft 365 Account Compromises

Two CyberQuell investigations show why step 4 matters: one account was contained in hours, while the other stayed compromised for four months.

Case How it started How it was detected What was found Fixes applied afterwards
Phishing account compromise (published March 2026) Phishing-related sign-in from an unfamiliar location Monitoring flagged the unusual sign-ins About 10 emails viewed in a browser session; no mailbox rules, new MFA devices, app tokens or bulk data access Password reset, token revocation, MFA reset
Multi-phase BEC (October 2025 to February 2026) Stolen session token that bypassed app-based MFA; legacy authentication still enabled A client called to verify an unusual payment-change request Outlook rules hid client replies; access survived a password reset and session revocation, likely through a malicious OAuth app; $150,000+ in fraud attempted, no money lost OAuth permissions revoked, rules removed, legacy authentication disabled, FIDO2 security keys, Conditional Access, Defender for Office 365 enabled, out-of-band payment checks

Read the full phishing account compromise investigation and the four-month multi-phase BEC investigation.

‍

Do You Need a Managed Phishing Service for Microsoft 365?

If you already license Defender for Office 365, a managed service mostly adds people, not filters. You're paying for round-the-clock triage, ongoing tuning and fast response when an account is compromised.

What a Managed Phishing Service Should Actually Do

Task Doing it yourself Managed service
Preset and impersonation tuning Your admin updates presets and protected users as staff change Provider reviews them on a set schedule
Triaging reported and detected phishing Checked in business hours, when someone has time Triaged around the clock against a written SLA
Account containment Your admin resets credentials and revokes sessions Provider contains within a stated time
Phishing simulation Your team runs Attack simulation training (Plan 2) Provider runs campaigns and reports click rates
Reporting Built manually from Defender reports Delivered every month

For example, CyberQuell's managed Defender for Office 365 service commits to triage within 30 minutes and containment within 4 hours. Microsoft also offers its own managed option, Defender Experts MDR.

Adding Another Email Filter: What Microsoft's Own Benchmark Shows

Microsoft's data shows that add-on email filters mostly help with bulk mail and add little against malicious email.

Microsoft-published telemetry, not independent testing.

Metric Feb to Apr 2026 May to Jul 2026
Malicious-email catch uplift from add-on filters after Defender 0.13% 0.30%
Spam catch uplift from add-on filters 0.28% 0.52%
Promotional and bulk filtering uplift from add-on filters 16.85% Not published
Defender's high-severity misses vs the next-closest email gateway 59% fewer 55.4% fewer

Microsoft also reports that missed threats rose across vendors, Defender included, as AI makes impersonation easier to tailor. Another filter rarely changes your malicious-email results; staffing and response do. A separate gateway can still make sense for other reasons, such as complex mail routing or mixed email platforms.

To compare providers, see our list of Microsoft Defender specialists for managed email security, or read whether Defender is enough on its own.

‍

Final Thoughts 

Phishing protection in Microsoft 365 comes down to one decision: leave Defender on its defaults, or move it to Standard and Strict. If you're on Business Premium or E3, you already own the core controls in this guide. Default is weaker than Standard on 10 of 12 anti-phishing settings, so start with the presets and your protected-users list. Then decide who watches what gets through after hours.

Book a call with CyberQuell to review your Defender for Office 365 settings and licence coverage, and see where your tenant stands.

Last Updated:
October 7, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

What is Microsoft Defender for Office 365?

It’s an advanced email security layer for Microsoft 365 that detects phishing, malicious links, attachments, and impersonation attacks.

What’s the difference between Plan 1 and Plan 2?

Plan 1 provides front-line protection (Safe Links, Safe Attachments, anti-spoofing), while Plan 2 adds automated investigation, threat hunting, and advanced reporting.

‍

Isn’t Microsoft 365’s default protection enough?

No, Exchange Online Protection (EOP) blocks basic spam and malware but struggles with CEO impersonation, QR/OAuth scams, and BEC attacks.

How can I tune Defender without causing email disruptions?

Use allow lists for trusted senders, adjust detection sensitivity per user group, review user-reported emails, and keep quarantine policies user-friendly.

What should I do if a phishing email gets through?

Investigate with Threat Explorer or Incidents & Alerts, purge malicious emails, reset affected credentials, and use automated response if Plan 2 is available.

‍

‍

Does Defender replace other security tools?

No, it layers on top of EOP; enterprises may add Microsoft Sentinel, Defender XDR, or third-party MDR for broader threat management.

‍

‍

What’s the simplest immediate action I can take?

Ensure Defender is enabled, turn on Safe Links and Safe Attachments, review phishing policies, and run a real-world phishing simulation.

‍

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.