Specialist assessment · Microsoft Defender for Office 365

Know whether email threat protection is configured, observable, and operationally owned.

A focused assessment of Microsoft Defender for Office 365 policy design and the people, evidence, and response workflows needed to make those protections useful.

Technical scope

Review prevention together with investigation and response.

Controls are assessed only where the applicable Microsoft Defender for Office 365 plan, Microsoft 365 licensing, data, and portal capabilities are available and included in scope.

Policy architecture

Review preset security policies, standard and strict protection use, custom policy priority, scoped populations, exceptions, conflicts, and documented ownership.

Anti-phishing and impersonation

Assess spoof intelligence, impersonation protection, mailbox intelligence, trusted senders and domains, protected users or domains, actions, and exception governance.

Safe Attachments

Review policy coverage, dynamic delivery or blocking decisions, redirect dependencies, SharePoint, OneDrive, and Microsoft Teams protections where licensed and configured.

Safe Links

Evaluate time-of-click protection, URL rewriting, Teams and Office application coverage, user click-through settings, exclusions, and policy assignment.

Submissions and quarantine

Review user-reported message flow, admin submissions, quarantine policies, release authority, notifications, security-operations ownership, and feedback loops.

Investigation and response

Assess alerts, incidents, automated investigation and response, campaign visibility, Threat Explorer or real-time detections, hunting, and Attack simulation training where licensed.

Questions this assessment can answer

Determine whether licensed protection is becoming operational value.

Who and what is actually protected?

Trace policy scope, priority, preset and custom policy interaction, exclusions, accepted domains, and user populations.

Can users and analysts report safely?

Review reporting, submissions, quarantine, release authority, false-positive handling, escalation, and feedback responsibilities.

Can the team investigate an email attack?

Assess alert and incident flow, evidence access, automation, campaign context, hunting capability, ownership, and retention dependencies where licensed.

Assessment process

A controlled review from scope to decision.

01 · LICENSE

Confirm available capability

Map license entitlements, accepted domains, protected populations, mail-flow dependencies, integrations, portals, and security-operations ownership.

02 · POLICY

Trace protection policy

Review preset and custom policy scope, priority, exceptions, actions, Safe Links, Safe Attachments, anti-phishing, reporting, and quarantine.

03 · OPERATE

Review investigation workflow

Validate alert intake, incidents, submissions, evidence, automated investigation, hunting, escalation, and lessons learned where capabilities apply.

04 · IMPROVE

Prioritize protection and process

Separate urgent coverage or exception issues from rollout, tuning, operational ownership, training, and longer-term maturity work.

Deliverables

A protection and operations action register.

  • Executive summary of material email-threat protection and response gaps
  • Policy-scope, priority, exception, Safe Links, Safe Attachments, and anti-phishing findings
  • Submission, quarantine, release, alert, incident, and investigation observations
  • License and applicability notes so unavailable features are not scored as failures
  • Prioritized rollout, tuning, ownership, and validation plan
Boundaries

Clear scope protects the quality of the answer.

  • Plan-specific features only where licensed, enabled, and in scope
  • No live phishing campaign, payload delivery, or adversary simulation by default
  • No policy, quarantine, allow-list, submission, or investigation changes during assessment
  • Message-content access is not assumed and must be separately justified if ever required
  • A configuration review cannot guarantee that every malicious message will be prevented
Frequently asked questions

Questions to resolve before the work begins.

Which Microsoft Defender for Office 365 plan is required?

The assessment is tailored to the customer’s licenses. Plan 1, Plan 2, Microsoft 365 bundle entitlements, and feature availability differ, so controls such as investigation, campaign views, simulation, or advanced hunting are reviewed only where licensed and applicable.

Does the assessment send live phishing messages?

No live phishing exercise is included by default. Attack simulation training configuration and governance can be reviewed where licensed, but any campaign execution requires separate authorization, communications, safeguards, and scope.

How is this different from the Exchange Online assessment?

The Exchange Online assessment covers broader messaging configuration, mail flow, access, forwarding, auditing, and built-in protection. This service concentrates on Microsoft Defender for Office 365 threat-protection, investigation, response, and security-operations capabilities.

Will TenantShield change protection policies during the review?

No. The assessment records evidence and recommends priorities. Policy rollout or remediation is separately approved and should include impact analysis, pilot populations, monitoring, rollback, and validation.

Related services and evidence

Exchange Online Assessment

Review the broader mail-flow, forwarding, connector, permission, application, audit, and email-authentication context.

Review Exchange Online →

Defender assessment checklist

Prepare a focused review of policy coverage, Safe Links, Safe Attachments, anti-phishing, exceptions, and response workflows.

Use the Defender checklist →

Microsoft Entra ID Assessment

Review the privileged roles, authentication, applications, and consent paths that support messaging administration.

Review Microsoft Entra ID →

Sample assessment

See how technical evidence is turned into a measured business-risk statement and sequenced action.

View sample assessment →

Start with the decision your team needs to make.

Share the business trigger, relevant Microsoft 365 licensing, approximate environment size, and decision deadline. No credentials or tenant exports are needed for the first conversation.