Recommended email and collaboration threat policy settings for cloud organizations
In brief
The page now recommends Off for automatic forwarding in Standard and Strict profiles. It also adds guidance for blocking unscanned encrypted attachments, excluded attachment types, and quarantine policy when the Safe Attachments response is Block.
What Defender admins need to know
Review these recommendations when using the page to configure or audit EOP and Office 365 settings.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Recommended email and collaboration threat policy settings for cloud organizations
|Set an internal message limit (RecipientLimitInternalPerHour)|
| |Set a daily message limit (RecipientLimitPerDay)|Show details
Default: 0
Recommended Standard: 1000
Recommended Strict: 800
Comment: The default value 0 means use the service defaults.| |Restriction placed on users who reach the message limit (ActionWhenThresholdReached)|Show details
Default: 0
Recommended Standard: 1000
Recommended Strict: 800
Comment: The default value 0 means use the service defaults.| |Automatic forwarding rules (AutoForwardingMode)|Show details
Default: Restrict the user from sending mail until the following day (BlockUserForToday)
Recommended Standard: Restrict the user from sending mail (BlockUser)
Recommended Strict: Restrict the user from sending mail (BlockUser)| |Send a copy of outbound messages that exceed these limits to these users and groups (BccSuspiciousOutboundMail and BccSuspiciousOutboundAdditionalRecipients)|Show details
Default: Automatic - System-controlled (Automatic)
Recommended Standard:AutomaticOff -System-controlledForwarding is disabled ()AutomaticOff
Recommended Strict:Automatic - System-controlled(Automatic)Comment: The valueAutomatic - System-controlled(Automatic) is equivalent toOff - Forwarding is disabled (Off).
Comment: The behavior of Automatic - System-controlled (Automatic) can differ by organization. Configure Off - Forwarding is disabled (Off) to explicitly disable automatic external forwarding. For more information, see Control automatic external email forwarding.| |Notify these users and groups if a sender is blocked due to sending outbound spam (NotifyOutboundSpam and NotifyOutboundSpamRecipients)|Show details
Default: Not selected ($falseand Blank)
Recommended Standard: Not selected ($falseand Blank)
Recommended Strict: Not selected ($falseand Blank)
Comment: This setting works only in the default outbound spam policy. It doesn't work in custom outbound spam policies that you create.
The Microsoft SecureScore recommendation Ensure Exchange Online Spam Policies are set to notify administrators suggests that you configure this value.|Show details
Default: Not selected ($falseand Blank)
Recommended Standard: Not selected ($falseand Blank)
Recommended Strict: Not selected ($falseand Blank)
Comment: The default alert policy named User restricted from sending email already sends email notifications to members of the TenantAdmins group (Global Administrator members) when users are blocked due to exceeding the limits in the policy. For instructions, see Verify the alert settings for restricted users.
Although we recommend that you use the alert policy rather than this setting in the outbound spam policy to notify admins and other users, the Microsoft SecureScore recommendation Ensure Exchange Online Spam Policies are set to notify administrators suggests that you configure this value.
|Safe Attachments unknown malware response (Enable and Action)|
| |Quarantine policy (QuarantineTag)|Show details
Default in custom: Off (-Enable $falseand-Action Block)
Built-in protection: Block (-Enable $trueand-Action Block)
Standard: Block (-Enable $trueand-Action Block)
Strict: Block (-Enable $trueand-Action Block)
Comment: When the Enable parameter is $false, the value of the Action parameter doesn't matter.| |Redirect attachment with detected attachments : Enable redirect (Redirect and RedirectAddress)|Show details
Default in custom: AdminOnlyAccessPolicy
Built-in protection: AdminOnlyAccessPolicy
Standard: AdminOnlyAccessPolicy
Strict: AdminOnlyAccessPolicy| |Block messages containing encrypted attachments that could not be scanned|This section and the following settings are available only when the Safe Attachments unknown malware response value is Block (Show details
Default in custom: Not selected and no email address specified. (-Redirect $falseand RedirectAddress is blank)
Built-in protection: Not selected and no email address specified. (-Redirect $falseand RedirectAddress is blank)
Standard: Not selected and no email address specified. (-Redirect $falseand RedirectAddress is blank)
Strict: Not selected and no email address specified. (-Redirect $falseand RedirectAddress is blank)
Comment: Redirection of messages is available only when the Safe Attachments unknown malware response value is Monitor (-Enable $trueand-Action Allow).-Enable $trueand-Action Block).| |Block unscanned attachments (EnableBlockingEncryptedAttachments)|| |Exclude these attachment types (ExcludedTypesFromBlockingEncryptedAttachments)|Show details
Default in custom: Not selected ($false)
Built-in protection: Not selected ($false)
Standard: Not selected ($false)
Strict: Not selected ($false)| |Quarantine policy (QuarantineTagForBlockingEncryptedAttachments)|Show details
Default in custom: None selected ({})
Built-in protection: None selected ({})
Standard: None selected ({})
Strict: None selected ({})|Show details
Default in custom: DefaultFullAccessWithNotificationPolicy
Built-in protection: DefaultFullAccessWithNotificationPolicy
Standard: DefaultFullAccessWithNotificationPolicy
Strict: DefaultFullAccessWithNotificationPolicy
Comment: This quarantine policy applies only to messages quarantined by Safe Attachments because they contain encrypted (password-protected) attachments that can't be scanned.
Safe Links policy settings
@@ -14,12 +14,12 @@ ms.collection: description: What are best practices for email and collaboration security settings in Microsoft 365? What are the current recommendations for standard protection? What should you use to be more strict? And what extras do you get if you also use Microsoft Defender for Office 365? ai-usage: ai-assisted ms.service: defender-office-365-ms.date: 03/30/2026+ms.date: 08/10/2026 appliesto: - ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Built-in security features for all cloud mailboxes</a> - ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a> - ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>-ms.custom: sfi-ga-nochange+ms.custom: sfi-ga-nochange, msecd-doc-authoring-1015 --- # Recommended email and collaboration threat policy settings for cloud organizations@@ -186,7 +186,7 @@ For more information about the default sending limits in the service, see [Sendi > |**Set an internal message limit** (_RecipientLimitInternalPerHour_)|<details><summary>Show details</summary><br>**Default**: 0<br>**Recommended Standard**: 1000<br>**Recommended Strict**: 800<br>**Comment**: The default value 0 means use the service defaults.</details>| > |**Set a daily message limit** (_RecipientLimitPerDay_)|<details><summary>Show details</summary><br>**Default**: 0<br>**Recommended Standard**: 1000<br>**Recommended Strict**: 800<br>**Comment**: The default value 0 means use the service defaults.</details>| > |**Restriction placed on users who reach the message limit** (_ActionWhenThresholdReached_)|<details><summary>Show details</summary><br>**Default**: **Restrict the user from sending mail until the following day** (`BlockUserForToday`)<br>**Recommended Standard**: **Restrict the user from sending mail** (`BlockUser`)<br>**Recommended Strict**: **Restrict the user from sending mail** (`BlockUser`)</details>|-> |**Automatic forwarding rules** (_AutoForwardingMode_)|<details><summary>Show details</summary><br>**Default**: **Automatic - System-controlled** (`Automatic`)<br>**Recommended Standard**: **Automatic - System-controlled** (`Automatic`)<br>**Recommended Strict**: **Automatic - System-controlled** (`Automatic`)<br>**Comment**: The value **Automatic - System-controlled** (`Automatic`) is equivalent to **Off - Forwarding is disabled** (`Off`). For more information, see [Control automatic external email forwarding](outbound-spam-policies-external-email-forwarding.md).</details>|+> |**Automatic forwarding rules** (_AutoForwardingMode_)|<details><summary>Show details</summary><br>**Default**: **Automatic - System-controlled** (`Automatic`)<br>**Recommended Standard**: **Off - Forwarding is disabled** (`Off`)<br>**Recommended Strict**: **Off - Forwarding is disabled** (`Off`)<br>**Comment**: The behavior of **Automatic - System-controlled** (`Automatic`) can differ by organization. Configure **Off - Forwarding is disabled** (`Off`) to explicitly disable automatic external forwarding. For more information, see [Control automatic external email forwarding](outbound-spam-policies-external-email-forwarding.md).</details>| > |**Send a copy of outbound messages that exceed these limits to these users and groups** (_BccSuspiciousOutboundMail_ and _BccSuspiciousOutboundAdditionalRecipients_)|<details><summary>Show details</summary><br>**Default**: Not selected (`$false` and Blank)<br>**Recommended Standard**: Not selected (`$false` and Blank)<br>**Recommended Strict**: Not selected (`$false` and Blank)<br>**Comment**: This setting works only in the default outbound spam policy. It doesn't work in custom outbound spam policies that you create.<br><br>The Microsoft SecureScore recommendation **Ensure Exchange Online Spam Policies are set to notify administrators** suggests that you configure this value.</details>| > |**Notify these users and groups if a sender is blocked due to sending outbound spam** (_NotifyOutboundSpam_ and _NotifyOutboundSpamRecipients_)|<details><summary>Show details</summary><br>**Default**: Not selected (`$false` and Blank)<br>**Recommended Standard**: Not selected (`$false` and Blank)<br>**Recommended Strict**: Not selected (`$false` and Blank)<br>**Comment**: The default [alert policy](/defender-xdr/alert-policies#threat-management-alert-policies) named **User restricted from sending email** already sends email notifications to members of the **TenantAdmins** group (**Global Administrator** members) when users are blocked due to exceeding the limits in the policy. For instructions, see [Verify the alert settings for restricted users](outbound-spam-restore-restricted-users.md#verify-the-alert-settings-for-restricted-users).<br><br>Although we recommend that you use the alert policy rather than this setting in the outbound spam policy to notify admins and other users, the Microsoft SecureScore recommendation **Ensure Exchange Online Spam Policies are set to notify administrators** suggests that you configure this value.</details>| @@ -345,6 +345,10 @@ Users can't release their own messages quarantined as malware or phishing by Saf > |**Safe Attachments unknown malware response** (_Enable_ and _Action_)|<details><summary>Show details</summary><br>**Default in custom**: **Off** (`-Enable $false` and `-Action Block`)<br>**Built-in protection**: **Block** (`-Enable $true` and `-Action Block`)<br>**Standard**: **Block** (`-Enable $true` and `-Action Block`)<br>**Strict**: **Block** (`-Enable $true` and `-Action Block`)<br>**Comment**: When the _Enable_ parameter is $false, the value of the _Action_ parameter doesn't matter.</details>| > |**Quarantine policy** (_QuarantineTag_)|<details><summary>Show details</summary><br>**Default in custom**: AdminOnlyAccessPolicy<br>**Built-in protection**: AdminOnlyAccessPolicy<br>**Standard**: AdminOnlyAccessPolicy<br>**Strict**: AdminOnlyAccessPolicy</details>| > |**Redirect attachment with detected attachments** : **Enable redirect** (_Redirect_ and _RedirectAddress_)|<details><summary>Show details</summary><br>**Default in custom**: Not selected and no email address specified. (`-Redirect $false` and _RedirectAddress_ is blank)<br>**Built-in protection**: Not selected and no email address specified. (`-Redirect $false` and _RedirectAddress_ is blank)<br>**Standard**: Not selected and no email address specified. (`-Redirect $false` and _RedirectAddress_ is blank)<br>**Strict**: Not selected and no email address specified. (`-Redirect $false` and _RedirectAddress_ is blank)<br>**Comment**: Redirection of messages is available only when the **Safe Attachments unknown malware response** value is **Monitor** (`-Enable $true` and `-Action Allow`).</details>|+> |**Block messages containing encrypted attachments that could not be scanned**|This section and the following settings are available only when the **Safe Attachments unknown malware response** value is **Block** (`-Enable $true` and `-Action Block`).|+> |**Block unscanned attachments** (_EnableBlockingEncryptedAttachments_)|<details><summary>Show details</summary><br>**Default in custom**: Not selected (`$false`)<br>**Built-in protection**: Not selected (`$false`)<br>**Standard**: Not selected (`$false`)<br>**Strict**: Not selected (`$false`)</details>|+> |**Exclude these attachment types** (_ExcludedTypesFromBlockingEncryptedAttachments_)|<details><summary>Show details</summary><br>**Default in custom**: None selected (`{}`)<br>**Built-in protection**: None selected (`{}`)<br>**Standard**: None selected (`{}`)<br>**Strict**: None selected (`{}`)</details>|+> |**Quarantine policy** (_QuarantineTagForBlockingEncryptedAttachments_)|<details><summary>Show details</summary><br>**Default in custom**: DefaultFullAccessWithNotificationPolicy<br>**Built-in protection**: DefaultFullAccessWithNotificationPolicy<br>**Standard**: DefaultFullAccessWithNotificationPolicy<br>**Strict**: DefaultFullAccessWithNotificationPolicy<br>**Comment**: This quarantine policy applies only to messages quarantined by Safe Attachments because they contain encrypted (password-protected) attachments that can't be scanned.</details>| ### Safe Links policy settings 