Microsoft Defender for Office 365
Email and collaboration

Recommended email and collaboration threat policy settings for cloud organizations

In brief

The page now recommends Off for automatic forwarding in Standard and Strict profiles. It also adds guidance for blocking unscanned encrypted attachments, excluded attachment types, and quarantine policy when the Safe Attachments response is Block.

What Defender admins need to know

Review these recommendations when using the page to configure or audit EOP and Office 365 settings.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Recommended email and collaboration threat policy settings for cloud organizations

|Set an internal message limit (RecipientLimitInternalPerHour)|

Show details
Default: 0
Recommended Standard: 1000
Recommended Strict: 800
Comment: The default value 0 means use the service defaults.
| |Set a daily message limit (RecipientLimitPerDay)|
Show details
Default: 0
Recommended Standard: 1000
Recommended Strict: 800
Comment: The default value 0 means use the service defaults.
| |Restriction placed on users who reach the message limit (ActionWhenThresholdReached)|
Show details
Default: Restrict the user from sending mail until the following day (BlockUserForToday)
Recommended Standard: Restrict the user from sending mail (BlockUser)
Recommended Strict: Restrict the user from sending mail (BlockUser)
| |Automatic forwarding rules (AutoForwardingMode)|
Show details
Default: Automatic - System-controlled (Automatic)
Recommended Standard: AutomaticOff - System-controlledForwarding is disabled (AutomaticOff)
Recommended Strict:Automatic - System-controlled (Automatic)
Comment: The value Automatic - System-controlled (Automatic) is equivalent to Off - Forwarding is disabled (Off).
Comment: The behavior of Automatic - System-controlled (Automatic) can differ by organization. Configure Off - Forwarding is disabled (Off) to explicitly disable automatic external forwarding. For more information, see Control automatic external email forwarding.
| |Send a copy of outbound messages that exceed these limits to these users and groups (BccSuspiciousOutboundMail and BccSuspiciousOutboundAdditionalRecipients)|
Show details
Default: Not selected ($false and Blank)
Recommended Standard: Not selected ($false and Blank)
Recommended Strict: Not selected ($false and Blank)
Comment: This setting works only in the default outbound spam policy. It doesn't work in custom outbound spam policies that you create.

The Microsoft SecureScore recommendation Ensure Exchange Online Spam Policies are set to notify administrators suggests that you configure this value.
| |Notify these users and groups if a sender is blocked due to sending outbound spam (NotifyOutboundSpam and NotifyOutboundSpamRecipients)|
Show details
Default: Not selected ($false and Blank)
Recommended Standard: Not selected ($false and Blank)
Recommended Strict: Not selected ($false and Blank)
Comment: The default alert policy named User restricted from sending email already sends email notifications to members of the TenantAdmins group (Global Administrator members) when users are blocked due to exceeding the limits in the policy. For instructions, see Verify the alert settings for restricted users.

Although we recommend that you use the alert policy rather than this setting in the outbound spam policy to notify admins and other users, the Microsoft SecureScore recommendation Ensure Exchange Online Spam Policies are set to notify administrators suggests that you configure this value.
|

|Safe Attachments unknown malware response (Enable and Action)|

Show details
Default in custom: Off (-Enable $false and -Action Block)
Built-in protection: Block (-Enable $true and -Action Block)
Standard: Block (-Enable $true and -Action Block)
Strict: Block (-Enable $true and -Action Block)
Comment: When the Enable parameter is $false, the value of the Action parameter doesn't matter.
| |Quarantine policy (QuarantineTag)|
Show details
Default in custom: AdminOnlyAccessPolicy
Built-in protection: AdminOnlyAccessPolicy
Standard: AdminOnlyAccessPolicy
Strict: AdminOnlyAccessPolicy
| |Redirect attachment with detected attachments : Enable redirect (Redirect and RedirectAddress)|
Show details
Default in custom: Not selected and no email address specified. (-Redirect $false and RedirectAddress is blank)
Built-in protection: Not selected and no email address specified. (-Redirect $false and RedirectAddress is blank)
Standard: Not selected and no email address specified. (-Redirect $false and RedirectAddress is blank)
Strict: Not selected and no email address specified. (-Redirect $false and RedirectAddress is blank)
Comment: Redirection of messages is available only when the Safe Attachments unknown malware response value is Monitor (-Enable $true and -Action Allow).
| |Block messages containing encrypted attachments that could not be scanned|This section and the following settings are available only when the Safe Attachments unknown malware response value is Block (-Enable $true and -Action Block).| |Block unscanned attachments (EnableBlockingEncryptedAttachments)|
Show details
Default in custom: Not selected ($false)
Built-in protection: Not selected ($false)
Standard: Not selected ($false)
Strict: Not selected ($false)
| |Exclude these attachment types (ExcludedTypesFromBlockingEncryptedAttachments)|
Show details
Default in custom: None selected ({})
Built-in protection: None selected ({})
Standard: None selected ({})
Strict: None selected ({})
| |Quarantine policy (QuarantineTagForBlockingEncryptedAttachments)|
Show details
Default in custom: DefaultFullAccessWithNotificationPolicy
Built-in protection: DefaultFullAccessWithNotificationPolicy
Standard: DefaultFullAccessWithNotificationPolicy
Strict: DefaultFullAccessWithNotificationPolicy
Comment: This quarantine policy applies only to messages quarantined by Safe Attachments because they contain encrypted (password-protected) attachments that can't be scanned.
|

Safe Links policy settings