Edit

Get the best security value from Microsoft Defender for Office 365 when you have non-Microsoft email filtering

This guide is for you if:

  • You're licensed for Microsoft Defender for Office 365 and host your mailboxes in Office 365
  • You're also using a non-Microsoft solution for your email security

The following information explains how to get the most out of Microsoft Defender for Office 365 in a dual-use deployment, broken down into easy to follow steps.

Prerequisites

Before you begin, make sure you have the following requirements in place:

  • Mailboxes hosted in Office 365
  • One or more of:
    • Microsoft Defender for Office 365 Plan 1 for protection features.
    • Microsoft Defender for Office 365 Plan 2 for most other features (included in E5 plans).
    • Microsoft Defender for Office 365 Trial (available to all customers at https://aka.ms/tryMDO).
  • Sufficient permissions to configure the features discussed in this article.

Step 1: Understand the value you already have

Start by reviewing the protection and investigation capabilities already included with Microsoft Defender for Office 365.

Review built-in protection features

Built-in protection features provide a baseline layer of security that's included with Microsoft Defender for Office 365.

  • Built-in protection offers a base level of unobtrusive protection, and includes malware, zero day (Safe Attachments), and URL protection (Safe Links) in email (including internal email), SharePoint, OneDrive, and Microsoft Teams. URL protection provided by built-in protection is via API call only. It doesn't wrap or rewrite URLs but does require a supported Outlook client. You can create your own custom Safe Links policies and Safe Attachments policies to expand your protection.

    To learn more and watch an overview video on Safe Links, see Complete Safe Links overview

    To learn more about Safe Attachments, see Safe Attachments

Review detection, investigation, response, and hunting features

The following capabilities help security teams investigate, respond to, and proactively hunt threats.

  • When alerts fire in Microsoft Defender for Office 365, they're automatically correlated, and combined into Incidents to help reduce the alert fatigue on security staff. Automated Investigation and Response (AIR) triggers investigations to help remediate and contain threats.

    To learn more, watch an overview video, and get started, see Incident response with Microsoft Defender XDR

  • Threat Analytics is our in-product, detailed threat intelligence solution from expert Microsoft security researchers. Threat Analytics contains detailed reports that are designed to get you up to speed on the latest threat groups, attack techniques, how to protect your organization with Indicators of Compromise (IOC) and much more.

    To learn more, watch an overview video, and get started, see Threat analytics in Microsoft Defender XDR

  • Explorer can be used to hunt threats, visualize mail flow patterns, spot trends, and identify the affect of changes you make during tuning Defender for Office 365. You can also quickly delete messages from your organization with a few simple clicks.

    To learn more and get started, see Threat Explorer and Real-time detections

  • Advanced hunting can be used to proactively hunt for threats in your organization, using shared queries from the community to help you get started. You can also use custom detections to set up alerts when personalized criteria are met.

To learn more, watch an overview video, and get started, see Overview - Advanced hunting

Step 2: Enhance the value further with these simple steps

After reviewing your existing protections, enable additional features and user education tools to close gaps and strengthen coverage.

Enable additional protection features

You can increase protection further by enabling additional Defender for Office 365 features.

To learn more, see Anti-phishing policies

  • If your current security provider is configured to modify messages in any way, it's important to note that authentication signals can affect the ability for Defender for Office 365 to protect you against attacks such as spoofing. If your non-Microsoft service supports Authenticated Received Chain (ARC), we highly recommend enabling ARC in your journey to advanced dual filtering. Moving any message modification configuration to Defender for Office 365 is also an alternative.

    To learn more, see Configure trusted ARC sealers

  • Enhanced Filtering for connectors allows IP address and sender information to be preserved through the non-Microsoft service. Enhanced Filtering for connectors improves the accuracy of Microsoft Defender for Office 365 filtering, post-breach capabilities, and authentication analysis.

    To learn more, see Enhanced filtering for connectors in Exchange Online

  • Priority account protection offers enhanced visibility for accounts in tooling, along with additional protection when in an advanced defense in-depth configuration state.

    To learn more, see Manage and monitor priority accounts

  • Advanced Delivery should be configured to deliver any non-Microsoft phish simulations correctly, and if you have a Security Operations mailbox, consider defining it as a SecOps mailbox to ensure emails don't get removed from the mailbox due to threats.

    To learn more, see Advanced delivery

  • You can configure user reported settings to allow users to report good or bad messages to Microsoft, to a designated reporting mailbox (to integrate with current security workflows) or both using the built-in Report button in supported versions of Outlook or using supported non-Microsoft solutions. Admins can use the User reported tab on the Submissions page to triage false positives and false negative user reported messages. In organizations with Defender for Office 365 Plan 2 and Security Copilot, the Phishing Triage Agent can autonomously triage and classify user-reported phishing emails.

    Tip

    In attack simulation training in Defender for Office 365 Plan 2, simulation messages reported by non-Microsoft tools aren't captured in attack simulation reports.

    To learn more, see User reported settings and Report phishing and suspicious emails in Outlook for admins

Use education features to improve user awareness

Education features help users recognize and respond to threats before real attacks occur.

  • Attack simulation training allows you to run realistic but benign cyber-attack scenarios in your organization. If you don't already have phishing simulation capabilities from your primary email security provider, Microsoft's simulated attacks can help you identify and find vulnerable users, policies, and practices. Attack simulation training provides important knowledge to have and correct before a real attack impacts your organization. Post simulation we assign in product or custom training to educate users about the threats they missed, ultimately reducing your organization's risk profile. With Attack simulation training, we deliver messages directly into the inbox, so the user experience is rich. Because Attack simulation training delivers messages directly into the inbox, no security changes such as overrides are needed to get simulations delivered correctly.

To learn more, see Get started using Attack simulation.

To get started delivering a simulation, see How to setup automated attacks and training within Attack simulation training

Step 3 and beyond: Become a dual-use hero

For dual-use Defender for Office 365 deployments alongside non-Microsoft email filtering, continue with these ongoing operational practices.

Migrate from a non-Microsoft protection service to Microsoft Defender for Office 365

Security Operations Guide for Defender for Office 365

Get more out of Microsoft Defender for Office 365 with Microsoft Defender XDR.