Preset policy coverage
Compare Built-in, Standard, and Strict coverage; exclusions; priority; protected users; and custom policy overlap. Use Microsoft’s preset security policy documentation to interpret the resulting policy chain.
Use this checklist to review who is protected, which policy actually wins, where exceptions weaken coverage, and whether detection leads to a workable response. Licensing and mail architecture determine which items apply.
Defender for Office 365 policies do not operate in isolation. Start by recording licenses, accepted domains, recipient populations, third-party filtering, hybrid routing, high-value users, shared mailboxes, application mail, and approved exceptions. Then determine whether Built-in protection, Standard or Strict preset security policies, or custom policies apply to each population.
A policy can look strong while missing a recipient, losing precedence, or carrying an exception that changes the outcome. Trace representative users through the policy chain.
Compare Built-in, Standard, and Strict coverage; exclusions; priority; protected users; and custom policy overlap. Use Microsoft’s preset security policy documentation to interpret the resulting policy chain.
Review spoof intelligence, mailbox intelligence, protected users and domains, impersonation actions, phishing thresholds, unauthenticated sender indicators, and DMARC handling. Confirm that high-risk populations are actually in scope.
Check recipient coverage, email and internal-message protection, real-time scanning, delivery behavior, Teams and Office app coverage, user click-through choices, and every do-not-rewrite entry. Validate the operational reason and owner for each exception.
Review policy recipients, action, redirect or monitoring configuration, Dynamic Delivery behavior where used, and protection for SharePoint, OneDrive, and Teams. Confirm that exclusions do not create an unreviewed path for high-impact content.
Review inbound and outbound spam policies, high-confidence verdict actions, quarantine policies, bulk thresholds, notification paths, allowed senders and domains, and custom malware controls. Broad allows require evidence and an owner.
Compare applicable settings with Microsoft’s current Standard or Strict guidance and inspect the Configuration Analyzer. Treat a difference as a prompt for analysis, not automatic proof of a finding.
Protection quality also depends on submissions, investigation, remediation, quarantine, and accountable follow-through. Features vary by plan, so confirm licensing before scoring a gap.
Review the reported-message path, who receives reports, how false positives and false negatives are investigated, and whether outcomes feed the Tenant Allow/Block List without creating permanent, unowned exceptions.
Confirm configured verdict actions and the scope of zero-hour auto purge. Review whether message locations, custom actions, or operational assumptions change the expected result.
Where licensed, examine alerts, incidents, Explorer or real-time detections, campaign views, automated investigations, pending remediation actions, role assignments, service-level expectations, and escalation to identity or endpoint response.
Review quarantine policies, user notifications, release and request-release permissions, administrative review, retention expectations, and the risk of allowing users to release sensitive verdict categories.
Where Plan 2 is licensed and simulations are appropriate, review targeting, authorization, payload safety, training follow-up, repeat testing, exclusions, and outcome ownership. A click rate alone is not a complete control assessment.
Sample recent alerts or submitted messages to determine whether assigned people saw the signal, reached a defensible verdict, completed approved actions, documented exceptions, and closed related identity or endpoint work.
A professional assessment should state the observed condition, effective recipient scope, evidence, attack path, operational context, and recommended action. It should distinguish a licensing limitation from a configuration gap, a design decision from deployment drift, and an isolated exception from systematic undercoverage.
Continue with the Defender for Office 365 assessment service, the broader Exchange Online checklist, or the sample assessment.
No. Exchange Online Protection provides baseline anti-spam, anti-malware, and anti-phishing capabilities for cloud mailboxes. Defender for Office 365 adds capabilities such as impersonation protection, Safe Links, Safe Attachments, and additional investigation or response features depending on the licensed plan.
Not automatically. Microsoft publishes Standard and Strict recommended configurations, but recipient coverage, exceptions, third-party mail flow, false-positive tolerance, and operational ownership must be evaluated before changes are made.
No. It helps organize a configuration and operating-control review. It does not prove that every message will be detected, replace monitoring and response, or certify the environment.
No. Applicable checks depend on licensing, mail architecture, business workflows, available evidence, and the agreed scope. The assessment should state what was reviewed, what was not applicable, and what could not be validated.
Request a focused assessment to trace policy coverage, exceptions, response ownership, and the improvements that matter most in your mail environment.