Microsoft Defender for Office 365
Email and collaboration

Eop About

In brief

The documentation now states that messages pass through anti-spam and anti-phishing filtering, removing the broader “content filtering” wording.

What Defender admins need to know

Administrators have a clearer description of the message-processing flow; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In on-premises organizations with Exchange Enterprise CAL with Services licenses, data loss prevention (DLP) checks also happen at this point.

  1. The message passes through content filtering, which includes anti-spam and anti-phishing filtering:
    • Anti-spam policies identify messages as bulk, spam, high confidence spam, phishing, or high confidence phishing.

      High confidence phishing messages are always delivered to quarantine. By default, only admins can view and interact with high confidence phishing messages.