Microsoft Defender for Office 365
Email and collaboration

Get the best security value from Microsoft Defender for Office 365 when you have non-Microsoft email filtering

In brief

The guide now explicitly covers Microsoft Defender for Office 365 deployments used alongside non-Microsoft email filtering. It adds prerequisites, clarifies built-in protection and Enhanced Filtering guidance, and updates links and operational recommendations.

What Defender admins need to know

Administrators can use the revised guidance to review protection coverage and ongoing practices in dual-use environments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Get the best security value from Microsoft Defender for Office 365 when you have non-Microsoft email filtering

  • You're licensed for Microsoft Defender for Office 365 and host your mailboxes in Office 365
  • You're also using a non-Microsoft solution for your email security

The following information detailsexplains how to get the most out of your investment,Microsoft Defender for Office 365 in a dual-use deployment, broken down into easy to follow steps.

Prerequisites

Before you begin, make sure you have the following requirements in place:

  • Mailboxes hosted in Office 365
  • One or more of:
    • Microsoft Defender for Office 365 Plan 1 for protection features.

Step 1: Understand the value you already have

Start by reviewing the protection and investigation capabilities already included with Microsoft Defender for Office 365.

Review built-in protection features

Built-in protection features provide a baseline layer of security that's included with Microsoft Defender for Office 365.

  • Built-in protection offers a base level of unobtrusive protection, and includes malware, zero day (Safe Attachments), and URL protection (Safe Links) in email (including internal email), SharePoint, OneDrive, and Microsoft Teams. URL protection provided by built-in this stateprotection is via API call only. It doesn't wrap or rewrite URLs but does require a supported Outlook client. You can create your own custom Safe Links policies and Safe Attachments policies to expand your protection.

    To learn more and watch an overview video on Safe Links, see Complete Safe Links overview

Step 2: Enhance the value further with these simple steps

After reviewing your existing protections, enable additional features and user education tools to close gaps and strengthen coverage.

Enable additional protection features

You can increase protection further by enabling additional Defender for Office 365 features.

To learn more, see Anti-phishing policies

To learn more, see Configure trusted ARC sealers

  • Enhanced Filtering for connectors allows IP address and sender information to be preserved through the non-Microsoft service. Enhanced Filtering for connectors improves the accuracy of Microsoft Defender for the filtering (protection) stack, post Office 365 filtering, post-breach capabilities &capabilities, and authentication improvements.analysis.

    To learn more, see Enhanced filtering for connectors in Exchange Online

Step 3 and beyond: Become a dual-use hero

After the initial setup,For dual-use Defender for Office 365 deployments alongside non-Microsoft email filtering, continue maturing your dual-use approach with these ongoing operational practices.