Key Takeaways
- Microsoft Defender for Office 365 is Microsoft's paid email and collaboration security layer, sold as Plan 1 and Plan 2, on top of the Exchange Online Protection (EOP) built into every Microsoft 365 mailbox.
- Plan 1 is included in Microsoft 365 Business Premium and, effective 1 July 2026, in Microsoft 365 E3 and Office 365 E3, while Plan 2 comes with Microsoft 365 E5.
- As add-ons, Plan 1 lists at $2 and Plan 2 at $5 per user per month.
- Defender for Office 365 provides no email continuity during a Microsoft 365 outage and no protection for mailboxes outside Microsoft 365, which are the two strongest reasons to add a gateway.
- You can evaluate Defender in audit mode without changing your mail exchanger (MX) record, even with a gateway in front.
- The licence gives you the tool, but policy tuning and out-of-hours alert triage decide the outcome.
Anyone renewing Microsoft 365 email security faces one decision: rely on Microsoft Defender for Office 365, or add a gateway or managed service. Below is what each plan covers, what it costs, and what Microsoft's own documentation and benchmark data say about layering. If your email lives entirely in Microsoft 365, you need Defender's Plan 1 configured properly and someone watching it, not a second filter.
Do You Need Microsoft Defender for Office 365?
If you run email on Microsoft 365, yes: Plan 1 is the sensible minimum, and many organisations already own it through Business Premium or E3. What changes by situation is whether you add a gateway or a managed service on top.
If the last row describes you, our comparison of managed email security providers for Microsoft Defender for Office 365 covers nine US specialists who run Defender for their customers.
What Exactly Does Microsoft Defender Protect You From?
Exchange Online Protection (EOP), included with every cloud mailbox, blocks broad and known attacks. Plan 1 adds protection from zero-day malware, phishing and business email compromise (BEC) across email, Teams, SharePoint and OneDrive. Plan 2 adds investigation, hunting and automated response.
Microsoft's Why do I need Defender for Office 365 page describes these as cumulative layers, with each tier including everything below it. Two Plan 2-only features are often presented as standard: AIR and Threat Explorer. Plan 1 gets Real-time detections instead, which is a subset of Explorer without its remediation actions. Attack simulation training is also Plan 2 only, so Plan 1 tenants need another way to run phishing tests. When a phishing email does reach an inbox, our guide on what to do when a phishing email gets through in Microsoft 365 covers the response steps.
What Defender for Office 365 Doesn't Cover
Defender for Office 365 protects email and collaboration inside Microsoft 365, and its gaps sit at the edges of that scope.
- Email continuity: keeping mail flowing during a Microsoft 365 outage is not a Defender for Office 365 feature.
- Other mail platforms: mailboxes outside Microsoft 365, such as Google Workspace, are not covered.
- Archiving and retention: these are handled by Microsoft Purview, not Defender for Office 365.
- Devices: laptops and phones need their own protection, such as endpoint security with Microsoft Defender for Endpoint.
- Compromised internal accounts: mail from a hijacked internal mailbox passes Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC), so authentication checks alone can't flag it. Catching it depends on someone monitoring sign-in and mailbox behaviour.
Which Microsoft 365 Plans Include Defender for Office 365?
Plan 1 is included in Microsoft 365 Business Premium and, effective 1 July 2026, in Microsoft 365 E3 and Office 365 E3. Plan 2 comes with E5. Other plans have EOP, plus basic link checks on some, and can add Plan 1 for $2 or Plan 2 for $5 per user per month.
Inclusions come from Microsoft's Defender for Office 365 service description and its July 2026 Microsoft 365 packaging update. Prices come from the Defender for Office 365 product page and were checked on 19 September 2026. They are US commercial list prices and vary by country. The URL time-of-click protection that Business Basic and Standard gained is not Plan 1: those plans still have no Safe Attachments or impersonation protection.
Plan 1 vs Plan 2: What the Upgrade Buys and Costs
Plan 2 adds Attack simulation training, priority account protection, Threat Explorer, Threat Trackers, Campaigns, AIR, advanced hunting and incident correlation in Microsoft Defender XDR.
Plan 2 pays off only if someone uses Explorer, AIR and simulations every week. If nobody in-house will, a managed Defender for Office 365 service can run them for you.
How to Check Which Plan You Have
The quickest check is in the Microsoft Defender portal. Under Email & collaboration, "Real-time detections" means Plan 1 and "Explorer" means Plan 2. To confirm licence counts, open the Microsoft 365 admin center and go to Billing, then Your products.
Is Microsoft Defender Enough on Its Own? (vs Proofpoint, Mimecast & Others)
For organisations whose email lives entirely in Microsoft 365, usually yes. Microsoft's latest benchmark shows that tools layered on top of Defender mostly improve bulk and promotional filtering, not malicious-email catch. The strong reasons to add a layer are continuity, non-Microsoft mail and compliance tooling.
Defender vs Gateway vs Add-on Filter: Where Each Sits in Your Mail Flow
The gateway row matters most at renewal time. Microsoft's Try and evaluate Defender for Office 365 guide confirms that blocking mode isn't available while a non-Microsoft service sits in front of Microsoft 365. You can measure Defender alongside a gateway, but it can't become your primary filter until the MX record moves.
Integrated cloud email security (ICES) is a product category: these tools connect to Microsoft 365 through its API instead of sitting in front of it. Microsoft's ICES vendor ecosystem is narrower. Its integration guide lists Darktrace/EMAIL, KnowBe4 Defend Platform and VIPRE Integrated Email Security as approved partners, as of 17 July 2026.
What Microsoft's Own Benchmark Shows About Adding Another Layer
Microsoft publishes a quarterly benchmark built from its own Defender telemetry. It is vendor data, not independent testing, so read it as Microsoft's case.
Latest-quarter figures come from Microsoft's 17 September 2026 benchmark post and its benchmarking page. Prior-quarter figures come from the 15 June 2026 post.
- Inbox cleanliness is the main gain. The malicious-catch uplift more than doubled last quarter, but it is still under half a percent.
- Defender does most of the clean-up after delivery. It removed 92% of the malicious mail found in inboxes after delivery, on average, from May to July 2026.
- Against gateways, Microsoft reports Defender missed 55.4% fewer high-severity threats than the next-closest gateway vendor over the same period.
- Missed threats are rising everywhere. Microsoft reports this across several periods, its own results included, as attackers use AI to tailor messages.
- You can measure the uplift in your own tenant. With an integrated partner, Defender's Efficacy report divides the add-on's unique post-delivery detections by Defender's total detections.
When a Third-Party Layer Is Worth It
Add a third-party layer if one of these applies:
- Some of your mail lives outside Microsoft 365, or you are mid-migration.
- A contract requires email continuity during a Microsoft 365 outage.
- You need archiving or encryption workflows you won't run in Microsoft Purview.
- A regulator or insurer requires two email security vendors.
- Users complain persistently about promotional mail, the one area where Microsoft's data shows a large gain. Before paying for a fix, try the Promotions folder Microsoft added to anti-spam policies in 2026 (the "Bulk moves enabled" setting).
Don't add one if the only reason is "defence in depth" and nobody will manage two quarantines. If one of the reasons above does apply, our overview of third-party email security solutions compares the main options.
If you're comparing Defender against a gateway before a renewal, CyberQuell's managed email security service for Microsoft 365 can run the audit-mode evaluation and read the results with you.
How to Test Defender Before You Replace (or Renew) a Gateway
Run Defender's evaluation in audit mode. It logs what Defender would have caught without acting on messages, needs no MX change, and works with a gateway in front.
- Start the evaluation. In the Microsoft Defender portal, open the Microsoft Defender for Office 365 evaluation page and select Start evaluation. You need the Security Administrator role.
- Choose reporting only. If asked, select "No, I only want reporting". With a gateway in front of Microsoft 365, audit mode is the only option.
- Pick who it covers. Microsoft recommends all users.
- Describe your mail flow. Select your gateway provider and the inbound connector it uses. Enhanced Filtering for Connectors is then configured automatically, so Defender sees the original sender.
- Add impersonation targets. In Manage evaluation settings, add the executives and domains to protect, because impersonation protection starts switched off.
- Read the results. The evaluation page reports what Defender would have caught under Email links, Attachments in email, Impersonation and Spoofed senders. Each report can be exported to CSV.
- Switch when ready. Once the MX record points to Microsoft 365, select "Convert to standard protection" to move into blocking mode. Our Defender for Office 365 deployment checklist covers the configuration that follows.
Limits worth knowing. Microsoft provisions Plan 2 licences for 90 days. If you already have Plan 1, the evaluation policies keep working after that, and only the Plan 2 investigation, automation and training features stop. Organisations with Plan 2 can evaluate with no time limit. Each organisation gets two trials at most, and trial data is deleted 30 days after expiry. Even in audit mode, Microsoft 365 still acts on malware and high-confidence phishing. Evaluations aren't available for US Government or Education tenants. All of this comes from Microsoft's Try and evaluate Defender for Office 365 guide.
How to Set It Up Right: 5 Must-Do Configurations
Apply the Standard preset security policy to everyone and Strict to high-risk users, name your impersonation targets, and switch on Safe Attachments for SharePoint, OneDrive and Teams. Then confirm Safe Links covers Teams and Office apps, and run Attack simulation training if you have Plan 2. Email authentication sits underneath all five as the base layer.
Microsoft's recommended settings guide confirms that the Standard and Strict presets don't set the global Safe Attachments options, which is why that row needs its own check. Custom policies can also silently override presets for the users they cover, and our guide to Standard vs Strict preset policies explains how to avoid that.
Should You Run Defender Yourself or Use a Managed Provider?
Run it yourself if someone can tune policies weekly and respond to alerts out of hours. Otherwise keep Defender and add a managed service rather than a second filter, because the gap is usually people, not detection.
Microsoft also sells its own managed service, Defender Experts MDR. Our comparison of Defender Experts vs third-party MDR explains the seat minimums and which option fits smaller organisations.
The Attack Authentication Checks Can't Stop: A Compromised Internal Mailbox
From CyberQuell's multi-phase business email compromise investigation
- For four months, an attacker used a bookkeeper's real Microsoft 365 mailbox at a professional services firm of about 50 people to send ACH payment-change requests to clients.
- The emails passed SPF, DKIM and DMARC because they came from a legitimate, authorised account.
- The attacker got in by stealing a session token, which bypassed MFA. They hid client replies with Outlook rules and kept access after password resets through a malicious OAuth application.
- A client checking back on a request caught it, not a filter. No money was lost.
- Afterwards, the firm added Defender for Office 365, Conditional Access, phishing-resistant MFA and out-of-band checks for payment changes.
Better filtering would not have flagged these emails. What surfaces this kind of attack is someone watching sign-ins, mailbox rules and app consents.
If nobody on your team can watch Defender out of hours, see what CyberQuell's managed Defender for Office 365 service includes.
Final Thoughts
If your email lives in Microsoft 365, the real decision is not which filter to buy but who runs the one you already have. Start with your licence: Business Premium, Microsoft 365 E3 and Office 365 E3 already include Plan 1, so check what you own before buying anything. Then configure it properly, test it in audit mode before your next gateway renewal, and decide who watches it out of hours.
A second filter earns its cost only when mail lives outside Microsoft 365, a contract requires continuity, or promotional mail stays a problem after you've tried the Promotions folder. For everything else, the gap is monitoring, as the compromised-mailbox case above shows.
Book a call with CyberQuell for a free email security assessment. We review your Microsoft 365 licence, your current policies and any gateway you run, then tell you what to keep, add or drop.

%20for%20Microsoft%20365%20(1).png)
.png)
.png)