Cybersecurity

9 mins

Microsoft Defender for Office 365: Do You Really Need It for Email Security?

Last Updated
September 24, 2026
Microsoft Defender for Office 365: Do You Really Need It for Email Security?

Key Takeaways

  • Microsoft Defender for Office 365 is Microsoft's paid email and collaboration security layer, sold as Plan 1 and Plan 2, on top of the Exchange Online Protection (EOP) built into every Microsoft 365 mailbox.
  • Plan 1 is included in Microsoft 365 Business Premium and, effective 1 July 2026, in Microsoft 365 E3 and Office 365 E3, while Plan 2 comes with Microsoft 365 E5.
  • As add-ons, Plan 1 lists at $2 and Plan 2 at $5 per user per month.
  • Defender for Office 365 provides no email continuity during a Microsoft 365 outage and no protection for mailboxes outside Microsoft 365, which are the two strongest reasons to add a gateway.
  • You can evaluate Defender in audit mode without changing your mail exchanger (MX) record, even with a gateway in front.
  • The licence gives you the tool, but policy tuning and out-of-hours alert triage decide the outcome.

Anyone renewing Microsoft 365 email security faces one decision: rely on Microsoft Defender for Office 365, or add a gateway or managed service. Below is what each plan covers, what it costs, and what Microsoft's own documentation and benchmark data say about layering. If your email lives entirely in Microsoft 365, you need Defender's Plan 1 configured properly and someone watching it, not a second filter.

‍

Do You Need Microsoft Defender for Office 365?

If you run email on Microsoft 365, yes: Plan 1 is the sensible minimum, and many organisations already own it through Business Premium or E3. What changes by situation is whether you add a gateway or a managed service on top.

Your situation Recommended setup Why
Email only in Microsoft 365, on Business Premium or E3 Plan 1 with the Standard or Strict preset security policies turned on You already pay for Plan 1, and the presets apply Microsoft's recommended settings
Microsoft 365 E5 Plan 2, run by someone who uses its investigation tools and automated investigation and response (AIR) Plan 2's extra value is investigation and response, which needs an analyst to use it
Business Basic, Business Standard or E1 Plan 1 add-on at $2 per user per month EOP has no impersonation protection or Safe Attachments, and only basic time-of-click link checks
Mail outside Microsoft 365 (Google Workspace, on-premises servers, or mid-migration) A secure email gateway, plus Defender for the Microsoft 365 mailboxes Defender for Office 365 protects Microsoft 365 mailboxes only
Email continuity during an outage is a contractual requirement A gateway with a continuity service Continuity is not a Defender for Office 365 feature
No one on staff to manage security Defender plus a managed service Policies need tuning and alerts need triage, including out of hours

If the last row describes you, our comparison of managed email security providers for Microsoft Defender for Office 365 covers nine US specialists who run Defender for their customers.

‍

What Exactly Does Microsoft Defender Protect You From?

Exchange Online Protection (EOP), included with every cloud mailbox, blocks broad and known attacks. Plan 1 adds protection from zero-day malware, phishing and business email compromise (BEC) across email, Teams, SharePoint and OneDrive. Plan 2 adds investigation, hunting and automated response.

Tier Prevent and detect Investigate Respond
EOP (every cloud mailbox) Anti-malware, anti-spam, spoof protection Message trace, audit log Quarantine, Tenant Allow/Block List, zero-hour auto purge (ZAP) for email
Plan 1 (adds) Impersonation protection for users and domains, mailbox intelligence, Safe Attachments, Safe Links Real-time detections ZAP for Teams
Plan 2 (adds) Attack simulation training, priority account protection Threat Explorer (replaces Real-time detections), Threat Trackers, Campaigns, advanced hunting AIR, including AIR for compromised users

Microsoft's Why do I need Defender for Office 365 page describes these as cumulative layers, with each tier including everything below it. Two Plan 2-only features are often presented as standard: AIR and Threat Explorer. Plan 1 gets Real-time detections instead, which is a subset of Explorer without its remediation actions. Attack simulation training is also Plan 2 only, so Plan 1 tenants need another way to run phishing tests. When a phishing email does reach an inbox, our guide on what to do when a phishing email gets through in Microsoft 365 covers the response steps.

What Defender for Office 365 Doesn't Cover

Defender for Office 365 protects email and collaboration inside Microsoft 365, and its gaps sit at the edges of that scope.

  • Email continuity: keeping mail flowing during a Microsoft 365 outage is not a Defender for Office 365 feature.
  • Other mail platforms: mailboxes outside Microsoft 365, such as Google Workspace, are not covered.
  • Archiving and retention: these are handled by Microsoft Purview, not Defender for Office 365.
  • Devices: laptops and phones need their own protection, such as endpoint security with Microsoft Defender for Endpoint.
  • Compromised internal accounts: mail from a hijacked internal mailbox passes Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting and Conformance (DMARC), so authentication checks alone can't flag it. Catching it depends on someone monitoring sign-in and mailbox behaviour.

‍

Which Microsoft 365 Plans Include Defender for Office 365?

Plan 1 is included in Microsoft 365 Business Premium and, effective 1 July 2026, in Microsoft 365 E3 and Office 365 E3. Plan 2 comes with E5. Other plans have EOP, plus basic link checks on some, and can add Plan 1 for $2 or Plan 2 for $5 per user per month.

Subscription Defender for Office 365 tier
Microsoft 365 Business Basic, Business Standard, Office 365 E1 None: EOP, plus URL time-of-click protection added in 2026
Microsoft 365 Business Premium Plan 1
Microsoft 365 E3, Office 365 E3 Plan 1, effective 1 July 2026
Government G3 plans Plan 1, rolling out during 2026
Microsoft 365 E5, Office 365 E5, A5, G5 Plan 2
Add-on for other plans Plan 1 at $2 or Plan 2 at $5 per user per month, billed annually

Inclusions come from Microsoft's Defender for Office 365 service description and its July 2026 Microsoft 365 packaging update. Prices come from the Defender for Office 365 product page and were checked on 19 September 2026. They are US commercial list prices and vary by country. The URL time-of-click protection that Business Basic and Standard gained is not Plan 1: those plans still have no Safe Attachments or impersonation protection.

Plan 1 vs Plan 2: What the Upgrade Buys and Costs

Plan 2 adds Attack simulation training, priority account protection, Threat Explorer, Threat Trackers, Campaigns, AIR, advanced hunting and incident correlation in Microsoft Defender XDR.

Option Annual cost, 100 users, list price
Plan 1 add-on ($2 x 100 x 12) $2,400
Plan 2 add-on ($5 x 100 x 12) $6,000
Switching from the Plan 1 add-on to Plan 2 $3,600 more
Adding Plan 2 on Business Premium or E3, where Plan 1 is already included $6,000

Plan 2 pays off only if someone uses Explorer, AIR and simulations every week. If nobody in-house will, a managed Defender for Office 365 service can run them for you.

How to Check Which Plan You Have

The quickest check is in the Microsoft Defender portal. Under Email & collaboration, "Real-time detections" means Plan 1 and "Explorer" means Plan 2. To confirm licence counts, open the Microsoft 365 admin center and go to Billing, then Your products.

‍

Is Microsoft Defender Enough on Its Own? (vs Proofpoint, Mimecast & Others)

For organisations whose email lives entirely in Microsoft 365, usually yes. Microsoft's latest benchmark shows that tools layered on top of Defender mostly improve bulk and promotional filtering, not malicious-email catch. The strong reasons to add a layer are continuity, non-Microsoft mail and compliance tooling.

Defender vs Gateway vs Add-on Filter: Where Each Sits in Your Mail Flow

Setup MX record points to What Defender still does
Defender only Microsoft 365 Filters all inbound mail, with blocking mode available
Secure email gateway (SEG) in front, such as Proofpoint or Mimecast The gateway Filters mail after the gateway; needs Enhanced Filtering for Connectors to see the original sender; evaluations run in audit mode only
Add-on filter through Microsoft's ICES vendor ecosystem Microsoft 365 Shows the add-on's verdicts in Defender's quarantine, Explorer and advanced hunting, and applies the most serious verdict; requires Plan 2 or E5

The gateway row matters most at renewal time. Microsoft's Try and evaluate Defender for Office 365 guide confirms that blocking mode isn't available while a non-Microsoft service sits in front of Microsoft 365. You can measure Defender alongside a gateway, but it can't become your primary filter until the MX record moves.

Integrated cloud email security (ICES) is a product category: these tools connect to Microsoft 365 through its API instead of sitting in front of it. Microsoft's ICES vendor ecosystem is narrower. Its integration guide lists Darktrace/EMAIL, KnowBe4 Defend Platform and VIPRE Integrated Email Security as approved partners, as of 17 July 2026.

What Microsoft's Own Benchmark Shows About Adding Another Layer

Microsoft publishes a quarterly benchmark built from its own Defender telemetry. It is vendor data, not independent testing, so read it as Microsoft's case.

Uplift when an ICES tool is layered on Defender May to Jul 2026 Feb to Apr 2026
Malicious email caught 0.30% 0.13%
Spam caught 0.52% 0.28%
Promotional and bulk mail filtered 19.6% 16.85%

Latest-quarter figures come from Microsoft's 17 September 2026 benchmark post and its benchmarking page. Prior-quarter figures come from the 15 June 2026 post.

  • Inbox cleanliness is the main gain. The malicious-catch uplift more than doubled last quarter, but it is still under half a percent.
  • Defender does most of the clean-up after delivery. It removed 92% of the malicious mail found in inboxes after delivery, on average, from May to July 2026.
  • Against gateways, Microsoft reports Defender missed 55.4% fewer high-severity threats than the next-closest gateway vendor over the same period.
  • Missed threats are rising everywhere. Microsoft reports this across several periods, its own results included, as attackers use AI to tailor messages.
  • You can measure the uplift in your own tenant. With an integrated partner, Defender's Efficacy report divides the add-on's unique post-delivery detections by Defender's total detections.

When a Third-Party Layer Is Worth It

Add a third-party layer if one of these applies:

  • Some of your mail lives outside Microsoft 365, or you are mid-migration.
  • A contract requires email continuity during a Microsoft 365 outage.
  • You need archiving or encryption workflows you won't run in Microsoft Purview.
  • A regulator or insurer requires two email security vendors.
  • Users complain persistently about promotional mail, the one area where Microsoft's data shows a large gain. Before paying for a fix, try the Promotions folder Microsoft added to anti-spam policies in 2026 (the "Bulk moves enabled" setting).

Don't add one if the only reason is "defence in depth" and nobody will manage two quarantines. If one of the reasons above does apply, our overview of third-party email security solutions compares the main options.

If you're comparing Defender against a gateway before a renewal, CyberQuell's managed email security service for Microsoft 365 can run the audit-mode evaluation and read the results with you.

‍

How to Test Defender Before You Replace (or Renew) a Gateway

Run Defender's evaluation in audit mode. It logs what Defender would have caught without acting on messages, needs no MX change, and works with a gateway in front.

  1. Start the evaluation. In the Microsoft Defender portal, open the Microsoft Defender for Office 365 evaluation page and select Start evaluation. You need the Security Administrator role.
  2. Choose reporting only. If asked, select "No, I only want reporting". With a gateway in front of Microsoft 365, audit mode is the only option.
  3. Pick who it covers. Microsoft recommends all users.
  4. Describe your mail flow. Select your gateway provider and the inbound connector it uses. Enhanced Filtering for Connectors is then configured automatically, so Defender sees the original sender.
  5. Add impersonation targets. In Manage evaluation settings, add the executives and domains to protect, because impersonation protection starts switched off.
  6. Read the results. The evaluation page reports what Defender would have caught under Email links, Attachments in email, Impersonation and Spoofed senders. Each report can be exported to CSV.
  7. Switch when ready. Once the MX record points to Microsoft 365, select "Convert to standard protection" to move into blocking mode. Our Defender for Office 365 deployment checklist covers the configuration that follows.

Limits worth knowing. Microsoft provisions Plan 2 licences for 90 days. If you already have Plan 1, the evaluation policies keep working after that, and only the Plan 2 investigation, automation and training features stop. Organisations with Plan 2 can evaluate with no time limit. Each organisation gets two trials at most, and trial data is deleted 30 days after expiry. Even in audit mode, Microsoft 365 still acts on malware and high-confidence phishing. Evaluations aren't available for US Government or Education tenants. All of this comes from Microsoft's Try and evaluate Defender for Office 365 guide.

‍

How to Set It Up Right: 5 Must-Do Configurations

Apply the Standard preset security policy to everyone and Strict to high-risk users, name your impersonation targets, and switch on Safe Attachments for SharePoint, OneDrive and Teams. Then confirm Safe Links covers Teams and Office apps, and run Attack simulation training if you have Plan 2. Email authentication sits underneath all five as the base layer.

Configuration Covered by the Standard or Strict preset? Minimum licence
Standard and Strict preset security policies Is the preset EOP for the anti-spam and anti-malware settings; Plan 1 for the Defender protections
Impersonation protection Partly: your own domains and mailbox intelligence are automatic; named executives and partner domains must be added Plan 1
Safe Links in email, Teams and Office apps Yes Plan 1
Safe Attachments for SharePoint, OneDrive and Teams No: a separate global setting, worth checking it's on Plan 1
Attack simulation training No Plan 2
Base layer: SPF, DKIM and DMARC No: DNS records, plus DKIM signing enabled in the Defender portal All

Microsoft's recommended settings guide confirms that the Standard and Strict presets don't set the global Safe Attachments options, which is why that row needs its own check. Custom policies can also silently override presets for the users they cover, and our guide to Standard vs Strict preset policies explains how to avoid that.

‍

Should You Run Defender Yourself or Use a Managed Provider?

Run it yourself if someone can tune policies weekly and respond to alerts out of hours. Otherwise keep Defender and add a managed service rather than a second filter, because the gap is usually people, not detection.

Task Doing it in-house means A managed service should
Tuning presets and impersonation targets Admin time every week, plus a review whenever a new executive or supplier arrives Review policies on a fixed schedule and after every change
Triaging user-reported messages Someone checking the submissions queue daily Triage reports and release or purge messages
After-hours alerts An on-call rota Respond around the clock
AIR investigations (Plan 2) An analyst who reviews and approves pending actions Review AIR findings and approve remediation
Configuration drift A quarterly check with Configuration analyzer and Secure Score Run the checks and fix the drift
Reporting A monthly summary for leadership Deliver it for you

Microsoft also sells its own managed service, Defender Experts MDR. Our comparison of Defender Experts vs third-party MDR explains the seat minimums and which option fits smaller organisations.

The Attack Authentication Checks Can't Stop: A Compromised Internal Mailbox

From CyberQuell's multi-phase business email compromise investigation

  • For four months, an attacker used a bookkeeper's real Microsoft 365 mailbox at a professional services firm of about 50 people to send ACH payment-change requests to clients.
  • The emails passed SPF, DKIM and DMARC because they came from a legitimate, authorised account.
  • The attacker got in by stealing a session token, which bypassed MFA. They hid client replies with Outlook rules and kept access after password resets through a malicious OAuth application.
  • A client checking back on a request caught it, not a filter. No money was lost.
  • Afterwards, the firm added Defender for Office 365, Conditional Access, phishing-resistant MFA and out-of-band checks for payment changes.

Better filtering would not have flagged these emails. What surfaces this kind of attack is someone watching sign-ins, mailbox rules and app consents.

If nobody on your team can watch Defender out of hours, see what CyberQuell's managed Defender for Office 365 service includes.

‍

Final Thoughts 

If your email lives in Microsoft 365, the real decision is not which filter to buy but who runs the one you already have. Start with your licence: Business Premium, Microsoft 365 E3 and Office 365 E3 already include Plan 1, so check what you own before buying anything. Then configure it properly, test it in audit mode before your next gateway renewal, and decide who watches it out of hours.

A second filter earns its cost only when mail lives outside Microsoft 365, a contract requires continuity, or promotional mail stays a problem after you've tried the Promotions folder. For everything else, the gap is monitoring, as the compromised-mailbox case above shows.

Book a call with CyberQuell for a free email security assessment. We review your Microsoft 365 licence, your current policies and any gateway you run, then tell you what to keep, add or drop.

Last Updated:
September 24, 2026

FAQs

Find answers to commonly asked questions about our cybersecurity solutions and services.

Is Microsoft Defender the same as ATP?

Not exactly. Microsoft used to call it Advanced Threat Protection (ATP), but it's now branded as Microsoft Defender for Office 365. The features are mostly the same, just under a new name with ongoing updates.

Which Office 365 plans include it?

Business Premium includes Defender Plan 1. E3 does not include Defender by default and must be added separately. E5 includes Defender Plan 2. Remember, Plan 1 gives core protections, while Plan 2 adds advanced investigation, automated response, and training.

Can Defender stop phishing and ransomware?

Yes, it's very effective at catching phishing emails, malicious links, and infected attachments before they reach users. That said, no tool is perfect, so proper configuration and monitoring are key to maximizing protection.

Is it enough, or do I need another layer?

For most organizations, Defender is enough if it's set up correctly and actively monitored. Some very large organizations or highly regulated industries may add third-party layers, but many businesses get full protection using just Defender plus good policies and training.

Do I still need antivirus if I use it?

Yes. Defender for Office 365 focuses on email threats. A good endpoint antivirus or endpoint protection solution is still recommended to protect devices from malware that might come from web downloads, USB drives, or other channels.

Can I use Defender for Office 365 with Mimecast or Proofpoint?

Yes. When a gateway sits in front of Microsoft 365, turn on Enhanced Filtering for Connectors so Defender sees the original sender. You can then evaluate Defender in audit mode without changing your MX (mail exchanger) record.

Does Defender for Office 365 protect Teams, SharePoint and OneDrive?

Yes, with Plan 1. Safe Links covers Teams and Office apps, and zero-hour auto purge (ZAP) removes malicious Teams messages after delivery. Safe Attachments for SharePoint, OneDrive and Teams is a separate global setting, so check that it is switched on.

‍

Protect Your Business from Cyber Threats

Get in touch with our cybersecurity experts to discuss your security needs and solutions.