Technical guide · Defender for Office 365

Defender for Office 365 Security Assessment Checklist

Use this checklist to review who is protected, which policy actually wins, where exceptions weaken coverage, and whether detection leads to a workable response. Licensing and mail architecture determine which items apply.

Start with scope

1. Establish the protection model before comparing settings.

Defender for Office 365 policies do not operate in isolation. Start by recording licenses, accepted domains, recipient populations, third-party filtering, hybrid routing, high-value users, shared mailboxes, application mail, and approved exceptions. Then determine whether Built-in protection, Standard or Strict preset security policies, or custom policies apply to each population.

  • Inventory Defender for Office 365 Plan 1, Plan 2, Microsoft 365 E5, and Exchange Online Protection coverage by recipient population.
  • Map MX records, connectors, third-party gateways, hybrid hops, and any mail flow rule that bypasses filtering or changes message scoring.
  • Export preset and custom policy rules with their enabled state, priority, recipient conditions, exclusions, and associated policy settings.
  • Identify executives, finance, payroll, IT administrators, service desks, and other impersonation-sensitive populations using business context rather than job title alone.
  • Record who owns threat-policy changes, false-positive review, submissions, quarantine decisions, alert triage, and emergency exceptions.
Applicability matters: this page is a planning checklist, not a promise that every assessment reviews every item. The agreed evidence plan should identify licensed, applicable, out-of-scope, and unavailable controls.
Pre-delivery controls

2. Test effective coverage, not just whether policies exist.

A policy can look strong while missing a recipient, losing precedence, or carrying an exception that changes the outcome. Trace representative users through the policy chain.

Preset policy coverage

Compare Built-in, Standard, and Strict coverage; exclusions; priority; protected users; and custom policy overlap. Use Microsoft’s preset security policy documentation to interpret the resulting policy chain.

Anti-phishing and impersonation

Review spoof intelligence, mailbox intelligence, protected users and domains, impersonation actions, phishing thresholds, unauthenticated sender indicators, and DMARC handling. Confirm that high-risk populations are actually in scope.

Safe Links

Check recipient coverage, email and internal-message protection, real-time scanning, delivery behavior, Teams and Office app coverage, user click-through choices, and every do-not-rewrite entry. Validate the operational reason and owner for each exception.

Safe Attachments

Review policy recipients, action, redirect or monitoring configuration, Dynamic Delivery behavior where used, and protection for SharePoint, OneDrive, and Teams. Confirm that exclusions do not create an unreviewed path for high-impact content.

Spam, malware, and bulk mail

Review inbound and outbound spam policies, high-confidence verdict actions, quarantine policies, bulk thresholds, notification paths, allowed senders and domains, and custom malware controls. Broad allows require evidence and an owner.

Configuration drift

Compare applicable settings with Microsoft’s current Standard or Strict guidance and inspect the Configuration Analyzer. Treat a difference as a prompt for analysis, not automatic proof of a finding.

Detection and response

3. Verify what happens after Microsoft produces a signal.

Protection quality also depends on submissions, investigation, remediation, quarantine, and accountable follow-through. Features vary by plan, so confirm licensing before scoring a gap.

User and admin submissions

Review the reported-message path, who receives reports, how false positives and false negatives are investigated, and whether outcomes feed the Tenant Allow/Block List without creating permanent, unowned exceptions.

Post-delivery protection

Confirm configured verdict actions and the scope of zero-hour auto purge. Review whether message locations, custom actions, or operational assumptions change the expected result.

Investigation workflow

Where licensed, examine alerts, incidents, Explorer or real-time detections, campaign views, automated investigations, pending remediation actions, role assignments, service-level expectations, and escalation to identity or endpoint response.

Quarantine governance

Review quarantine policies, user notifications, release and request-release permissions, administrative review, retention expectations, and the risk of allowing users to release sensitive verdict categories.

Simulation and learning

Where Plan 2 is licensed and simulations are appropriate, review targeting, authorization, payload safety, training follow-up, repeat testing, exclusions, and outcome ownership. A click rate alone is not a complete control assessment.

Response evidence

Sample recent alerts or submitted messages to determine whether assigned people saw the signal, reached a defensible verdict, completed approved actions, documented exceptions, and closed related identity or endpoint work.

Evidence request

4. Collect evidence that reveals the effective policy.

  • Licensing and recipient population map
  • Preset policy assignments and exclusions
  • Custom anti-phishing, Safe Links, and Safe Attachments policies and rules
  • Inbound and outbound anti-spam and anti-malware settings
  • Quarantine policies and release permissions
  • Tenant Allow/Block List entries, owners, reasons, and expiration
  • Mail flow rules and connectors that affect filtering
  • Configuration Analyzer results with approved deviations
  • Alert, submission, investigation, and remediation samples
Analysis questions

Ask why the condition matters here.

  • Which recipients or collaboration workloads can avoid the intended control?
  • Is a weaker setting deliberate, documented, monitored, and periodically reviewed?
  • Does a third-party gateway preserve the signals Microsoft needs to evaluate the original sender?
  • Who can approve an allow, release a quarantined item, or change a policy?
  • Will the response path contain related identity, mailbox, endpoint, and application exposure?
  • What can be improved safely now, and what requires staged testing?
Useful output

Turn policy exports into prioritized decisions.

A professional assessment should state the observed condition, effective recipient scope, evidence, attack path, operational context, and recommended action. It should distinguish a licensing limitation from a configuration gap, a design decision from deployment drift, and an isolated exception from systematic undercoverage.

  • Executive summary of material email and collaboration exposure
  • Technical findings with effective policy coverage and evidence references
  • Exception register with reason, owner, affected population, and review action
  • Prioritized remediation roadmap with dependencies, testing, and rollback considerations
  • Stakeholder readout that separates immediate containment from planned hardening

Continue with the Defender for Office 365 assessment service, the broader Exchange Online checklist, or the sample assessment.

Frequently asked questions

Scope the review without overpromising.

Is Defender for Office 365 the same as Exchange Online Protection?

No. Exchange Online Protection provides baseline anti-spam, anti-malware, and anti-phishing capabilities for cloud mailboxes. Defender for Office 365 adds capabilities such as impersonation protection, Safe Links, Safe Attachments, and additional investigation or response features depending on the licensed plan.

Should every organization use the Strict preset security policy?

Not automatically. Microsoft publishes Standard and Strict recommended configurations, but recipient coverage, exceptions, third-party mail flow, false-positive tolerance, and operational ownership must be evaluated before changes are made.

Does the checklist prove that email is secure?

No. It helps organize a configuration and operating-control review. It does not prove that every message will be detected, replace monitoring and response, or certify the environment.

Does every assessment include every item on this page?

No. Applicable checks depend on licensing, mail architecture, business workflows, available evidence, and the agreed scope. The assessment should state what was reviewed, what was not applicable, and what could not be validated.

See which Defender for Office 365 controls protect real recipients.

Request a focused assessment to trace policy coverage, exceptions, response ownership, and the improvements that matter most in your mail environment.