Defend Exchange Online Against Phishing, Business Email Compromise, Malware, and Spoofing

Protect Exchange Online with anti-phishing, Safe Links, Safe Attachments, impersonation defense, domain authentication, mail-flow control, quarantine, and response evidence.

Technical decision guide

What needs to be true in the tenant

Exchange Online protection is not a single switch. It depends on policy precedence, recipient scope, mail-flow exceptions, domain authentication, quarantine choices, and an operating process for delivered phishing and business email compromise.

  • Identify the decision owner, technical administrator, and business process affected before a production change.
  • Capture enough point-in-time evidence to show current state, expected result, tested result, and any approved exception.
  • Use a representative pilot and rollback path whenever the control can interrupt sign-in, mail, sharing, data handling, or recovery.

Operating sequence

Move from intent to verified outcome

AuthenticateValidate SPF, DKIM, DMARC, and alignment for each sending domain.
FilterApply anti-malware, anti-spam, anti-phishing, Safe Links, and Safe Attachments policies.
RouteCheck connectors, transport rules, forwarding, and exceptions that may change the effective protection.
InvestigateUse message, alert, submission, and quarantine workflows to understand suspicious delivery.
ImproveTune only from verified outcomes, then retain the policy and decision evidence.

Configuration, evidence, and validation

Controls administrators should verify

The exact portal path is a starting point. Check role permissions, feature availability, policy scope, precedence, and documented exceptions before relying on any result.

Choose an intentional policy baseline

Review built-in, Standard, Strict, and custom Defender policy use; understand preset policy precedence before adding exceptions.

Microsoft Defender portal > Email & collaboration > Policies & rules > Threat policies

Evidence: Preset-policy status, included recipients, custom policy priority.

Configure anti-phishing protection

Protect high-value users and domains, review impersonation settings, and verify spoof intelligence and user-reporting workflow.

Microsoft Defender portal > Threat policies > Anti-phishing

Evidence: Protected users/domains, policy settings, test mail outcome.

Validate Safe Links scope

Confirm real-time URL scanning applies to the intended email, supported Office, and Teams recipients; check custom policy order.

Microsoft Defender portal > Threat policies > Safe Links

Evidence: Policy targets, priority, representative test results.

Validate Safe Attachments scope

Confirm attachment protection, dynamic delivery options, exclusions, and response to known-safe and suspicious test messages.

Microsoft Defender portal > Threat policies > Safe Attachments

Evidence: Policy export, test outcome, exception approval.

Restrict external forwarding

Review outbound spam filter policy, inbox rules, transport rules, and exception process for external forwarding.

Microsoft Defender portal > Email & collaboration > Policies & rules

Evidence: Forwarding policy, rule inventory, approved exceptions.

Control mail-flow bypass

Inspect connectors and transport rules for conditions that bypass scanning, alter headers, or create broad allow paths.

Exchange admin center > Mail flow > Rules and Connectors

Evidence: Rule export, owner, change record, mail-flow test.

Complete domain authentication

Publish and validate SPF and DKIM before gradually advancing DMARC toward enforcement; check legitimate forwarding and intermediaries.

DNS and Microsoft Defender portal domain authentication reports

Evidence: DNS record capture, aggregate-report review, DMARC rollout evidence.

Govern quarantine and allow entries

Assign quarantine permissions carefully and review Tenant Allow/Block List entries for expiry, scope, and unintended bypass.

Microsoft Defender portal > Email & collaboration > Review > Quarantine

Evidence: Quarantine policy, allow/block entries, reviewer cadence.

Evidence that supports a decision

Keep the record useful for operations and audit

  • Configuration export or portal capture with collection time, policy target, status, and source tenant context.
  • Representative test result that shows the expected security behavior without storing unnecessary sensitive user or customer content.
  • Named owner, review frequency, change record, and documented exception or compensating control where the secure configuration cannot be applied.
  • Post-change validation showing the original risk scenario was addressed and normal business use remains understood.

Continue the review: Email defenses reduce a major entry point; collaboration controls then limit how far sensitive files and guests can spread after a legitimate sign-in. Keep SharePoint, OneDrive, and Teams Collaboration Secure Without Blocking Work.

Ali Hassani, CISO

Practical Microsoft 365 security guidance

Ali Hassani is a CISO and cybersecurity and IT consultant with 25+ years of experience across Microsoft infrastructure, security, compliance, and IT operations.

Meet Ali Hassani, CISO

Authoritative technical references

Verify implementation decisions against Microsoft documentation

Features, roles, licensing, data locations, and supported behavior can vary. Confirm the tenant’s current configuration before changing production controls.

Frequently asked questions

Practical decisions to resolve before implementation

Why does policy precedence matter?

Preset security policies are applied before custom Safe Links policies for affected recipients, so scope and priority must be checked before troubleshooting.

Can SPF alone prevent spoofing?

No. Microsoft documents that SPF validates the envelope sender, while DKIM and DMARC add integrity and domain alignment controls.

Should DMARC move immediately to reject?

Microsoft recommends a gradual, tested deployment so legitimate mail is not disrupted by unrecognized alignment or routing behavior.

This guidance is for initial planning and does not replace a professional cybersecurity audit, compliance assessment, penetration test, legal advice, or a review of your organization’s specific licensing and regulatory obligations.

Need implementation support?

Move from a control decision to a verified outcome

OC Security Audit can assess the risk, review evidence, and clarify remediation priorities. When an approved finding requires operational configuration, administration, endpoint work, backup testing, or ongoing support, IT Perfection can help scope the technical implementation.