SecureMyEmail logoSecureMyEmail

Microsoft 365 security guide

Enable phishing protections in Microsoft 365

A practical guide for Australian businesses. Use Microsoft 365 Standard and Strict preset security policies to protect users from phishing, malicious links and unsafe attachments.

Microsoft 365 phishing protection with Safe Links and Safe Attachments

Recommended method: assign users to Microsoft 365 Standard or Strict preset security policies

Microsoft recommends assigning users to its Standard or Strict preset security policies instead of manually maintaining separate threat policies. These presets enable coordinated anti-phishing, Safe Links and Safe Attachments protection.

Before you begin

Confirm that:

  • Users have Microsoft Defender for Office 365 Plan 1 or Plan 2 licensing. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1.
  • You are signed in using a Security Administrator or another suitably authorised administrative account.
  • Important business applications, automated email systems and third-party mail-filtering services have been documented.
  • You have a small pilot group available for testing.

Microsoft recommends least-privilege administration rather than routinely using a Global Administrator account.

Recommended configuration

  • Standard protectionFor most users.
  • Strict protectionFor high-risk users, such as owners, executives, finance staff and administrators.

A user should not be assigned to both groups. Strict protection takes precedence if assignments overlap.

1

Open Microsoft Defender

  • Sign in to the Microsoft Defender portal.
  • Select Email & collaboration.
  • Select Policies & rules.
  • Select Threat policies.
  • Under Templated policies, select Preset Security Policies.

You can also open the Preset Security Policies page directly.

2

Configure Standard protection

  • Locate Standard protection.
  • Move the toggle to On.
  • Select Manage protection settings.
  • On the Apply Exchange Online Protection page, select All recipients for an organisation-wide rollout, or Specific recipients for an initial pilot group.
  • Avoid adding exclusions unless there is a documented technical requirement.
  • Select Next.
  • On Apply Defender for Office 365 protection, choose Previously selected recipients.
  • Select Next.

Microsoft’s Standard preset includes recommended anti-phishing, Safe Links, Safe Attachments, anti-spam and anti-malware settings.

3

Configure impersonation protection

During the Standard protection wizard:

Add email addresses to flag when impersonated:

  • Business owners and executives
  • Finance and payroll staff
  • Microsoft 365 administrators
  • Employees authorised to request or approve payments

Add domains to flag when impersonated:

  • Trusted suppliers
  • Accountants
  • Banks and financial institutions
  • Frequently impersonated business partners
  • At Add email addresses to flag when impersonated, add important people such as business owners, executives, finance staff, administrators and payment approvers.
  • At Add domains to flag when impersonated, consider adding trusted suppliers, accountants, banks and frequently impersonated partners.
  • Confirm that your organisation’s accepted domains are listed correctly. Microsoft automatically protects accepted domains through preset policies.
  • Add trusted sender or domain exclusions only after verifying that they are genuinely required.
  • Review the configuration.
  • Select Confirm, followed by Done.

Do not automatically trust an entire supplier domain simply because one message was incorrectly detected. A broad exception can allow malicious messages using that domain to bypass impersonation checks.

4

Configure Strict protection for high-risk users

  • Return to Preset Security Policies.
  • Locate Strict protection.
  • Move the toggle to On.
  • Select Manage protection settings.
  • Select Specific recipients.
  • Add a group containing your high-risk accounts.
  • Configure important people and partner domains for impersonation protection.
  • Review the settings and select Confirm.
  • Select Done.

Strict protection is more aggressive and may quarantine more legitimate email, so it should normally be tested before broader deployment.

5

Confirm Safe Links protection

  • Go to Email & collaboration → Policies & rules → Threat policies.
  • Select Safe Links.
  • Confirm that assigned users are covered by either the Standard Preset Security Policy, the Strict Preset Security Policy, or an approved custom Safe Links policy.

Recommended Safe Links behaviour includes:

  • Protect links in email.
  • Scan links when users click them.
  • Scan links pointing to downloadable files.
  • Wait for URL scanning to finish before delivering external messages.
  • Protect links in Microsoft Teams.
  • Protect links opened from supported Microsoft 365 applications.
  • Track user clicks for investigation.
  • Prevent users from bypassing malicious-link warnings.
  • Protect internal email as well as externally received email.

Microsoft advises that a Safe Links policy change can take up to six hours to apply.

6

Confirm Safe Attachments protection

  • Return to Threat policies.
  • Select Safe Attachments.
  • Confirm that users are covered by the Standard or Strict preset policy.
  • If you must use a custom policy, verify that Safe Attachments unknown malware response is set to Block, an appropriate quarantine policy is selected, detected attachments are not automatically released to users, and any redirection or exception address is properly monitored.

Safe Attachments detonates suspicious files in a virtual environment before delivery. Microsoft advises allowing up to 30 minutes for policy changes to apply; individual attachment analysis can sometimes delay delivery.

7

Test and monitor

  • Apply the policy to a small pilot group first.
  • Test ordinary emails containing common website links, Microsoft 365 sharing links, and PDF and Office attachments.
  • Test messages from scanners, accounting platforms and line-of-business systems.
  • Review Email & collaboration → Review → Quarantine.
  • Review Email & collaboration → Reports.
  • Review user reports of delayed or blocked messages.
  • After successful testing, expand Standard protection to all licensed users.
  • Review exceptions regularly and remove any that are no longer required.

Important warnings

  • Safe Links can rewrite URLs and may affect links protected by another secure-email gateway.
  • Safe Attachments can delay messages while files are analysed.
  • Strict protection may quarantine legitimate bulk mail, newsletters or automated notifications.
  • Incorrect recipient conditions can leave users unprotected.
  • Broad trusted-sender, trusted-domain or URL exclusions materially weaken protection.
  • Do not create transport rules that broadly bypass spam, phishing or malware scanning.
  • If a third-party email security service such as INKY is already deployed, review the mail flow and compatibility before enabling overlapping features.
  • Security controls reduce risk but cannot guarantee that every phishing message will be detected.

Microsoft 365 disclaimer

These instructions provide general Microsoft 365 security guidance and may not account for your organisation’s licensing, mail-flow configuration, third-party filtering, compliance requirements or business applications. Incorrect changes can block legitimate email, delay attachments or create unintended security gaps.

Back up or document existing settings, use a controlled pilot group and prepare a rollback plan before changing production policies. If you are uncertain, have the configuration reviewed and implemented by a qualified Microsoft 365 security engineer.