Defend Exchange Online Against Phishing, Business Email Compromise, Malware, and Spoofing
Protect Exchange Online with anti-phishing, Safe Links, Safe Attachments, impersonation defense, domain authentication, mail-flow control, quarantine, and response evidence.
Technical decision guide
What needs to be true in the tenant
Exchange Online protection is not a single switch. It depends on policy precedence, recipient scope, mail-flow exceptions, domain authentication, quarantine choices, and an operating process for delivered phishing and business email compromise.
- Identify the decision owner, technical administrator, and business process affected before a production change.
- Capture enough point-in-time evidence to show current state, expected result, tested result, and any approved exception.
- Use a representative pilot and rollback path whenever the control can interrupt sign-in, mail, sharing, data handling, or recovery.
Operating sequence
Move from intent to verified outcome
Configuration, evidence, and validation
Controls administrators should verify
The exact portal path is a starting point. Check role permissions, feature availability, policy scope, precedence, and documented exceptions before relying on any result.
Choose an intentional policy baseline
Review built-in, Standard, Strict, and custom Defender policy use; understand preset policy precedence before adding exceptions.
Microsoft Defender portal > Email & collaboration > Policies & rules > Threat policies
Evidence: Preset-policy status, included recipients, custom policy priority.
Configure anti-phishing protection
Protect high-value users and domains, review impersonation settings, and verify spoof intelligence and user-reporting workflow.
Microsoft Defender portal > Threat policies > Anti-phishing
Evidence: Protected users/domains, policy settings, test mail outcome.
Validate Safe Links scope
Confirm real-time URL scanning applies to the intended email, supported Office, and Teams recipients; check custom policy order.
Microsoft Defender portal > Threat policies > Safe Links
Evidence: Policy targets, priority, representative test results.
Validate Safe Attachments scope
Confirm attachment protection, dynamic delivery options, exclusions, and response to known-safe and suspicious test messages.
Microsoft Defender portal > Threat policies > Safe Attachments
Evidence: Policy export, test outcome, exception approval.
Restrict external forwarding
Review outbound spam filter policy, inbox rules, transport rules, and exception process for external forwarding.
Microsoft Defender portal > Email & collaboration > Policies & rules
Evidence: Forwarding policy, rule inventory, approved exceptions.
Control mail-flow bypass
Inspect connectors and transport rules for conditions that bypass scanning, alter headers, or create broad allow paths.
Exchange admin center > Mail flow > Rules and Connectors
Evidence: Rule export, owner, change record, mail-flow test.
Complete domain authentication
Publish and validate SPF and DKIM before gradually advancing DMARC toward enforcement; check legitimate forwarding and intermediaries.
DNS and Microsoft Defender portal domain authentication reports
Evidence: DNS record capture, aggregate-report review, DMARC rollout evidence.
Govern quarantine and allow entries
Assign quarantine permissions carefully and review Tenant Allow/Block List entries for expiry, scope, and unintended bypass.
Microsoft Defender portal > Email & collaboration > Review > Quarantine
Evidence: Quarantine policy, allow/block entries, reviewer cadence.
Evidence that supports a decision
Keep the record useful for operations and audit
- Configuration export or portal capture with collection time, policy target, status, and source tenant context.
- Representative test result that shows the expected security behavior without storing unnecessary sensitive user or customer content.
- Named owner, review frequency, change record, and documented exception or compensating control where the secure configuration cannot be applied.
- Post-change validation showing the original risk scenario was addressed and normal business use remains understood.
Continue the review: Email defenses reduce a major entry point; collaboration controls then limit how far sensitive files and guests can spread after a legitimate sign-in. Keep SharePoint, OneDrive, and Teams Collaboration Secure Without Blocking Work.
Authoritative technical references
Verify implementation decisions against Microsoft documentation
Features, roles, licensing, data locations, and supported behavior can vary. Confirm the tenant’s current configuration before changing production controls.
Frequently asked questions
Practical decisions to resolve before implementation
Why does policy precedence matter?
Preset security policies are applied before custom Safe Links policies for affected recipients, so scope and priority must be checked before troubleshooting.
Can SPF alone prevent spoofing?
No. Microsoft documents that SPF validates the envelope sender, while DKIM and DMARC add integrity and domain alignment controls.
Should DMARC move immediately to reject?
Microsoft recommends a gradual, tested deployment so legitimate mail is not disrupted by unrecognized alignment or routing behavior.
This guidance is for initial planning and does not replace a professional cybersecurity audit, compliance assessment, penetration test, legal advice, or a review of your organization’s specific licensing and regulatory obligations.
Need implementation support?
Move from a control decision to a verified outcome
OC Security Audit can assess the risk, review evidence, and clarify remediation priorities. When an approved finding requires operational configuration, administration, endpoint work, backup testing, or ongoing support, IT Perfection can help scope the technical implementation.