Microsoft Defender
10 checks · 2 sub-categories
Defender for Office 365 and Exchange Online Protection are the filters standing between your staff and the phishing email that starts the incident. The licences are usually already paid for; the policies are frequently left on defaults that don't cover Teams, don't protect your executives from impersonation, and don't rewrite malicious links.
Email threat policies
Anti-phishing policy with impersonation protection
Checks that your directors, finance staff and domain are explicitly protected against display-name and lookalike-domain impersonation — the mechanics of nearly every invoice-fraud attempt.
- ACSC — Business Email Compromise guidance
Safe Links enabled for email, Office apps and Teams
URLs are rewritten and checked at click time, catching links that were clean at delivery and weaponised an hour later.
Safe Attachments enabled
Attachments are detonated in a sandbox before delivery. We also check the SharePoint, OneDrive and Teams extension, which is off by default in many tenants.
- CIS 2.5
Disallow download of infected files
The companion setting to Safe Attachments — without it, a file flagged as malicious in SharePoint can still be downloaded.
- CIS 2.6
Anti-malware policy and common attachment filter
Confirms executable and script attachment types are blocked at the gateway rather than left to the endpoint.
- Essential Eight — Application control
Zero-hour Auto Purge (ZAP) enabled
Retroactively removes phishing and malware from mailboxes after delivery, once the threat is identified.
Anti-spam policy and quarantine release permissions
Checks whether users can release their own quarantined mail — a common way filtered phishing ends up in the inbox anyway.
Endpoint and detection signal
Defender for Endpoint deployment coverage
Where licensed, we report which devices are onboarded and which are running unmanaged or with real-time protection disabled.
- Essential Eight — Application control
- Essential Eight — Patch applications
Threat and vulnerability findings surfacing in Secure Score
Correlates outstanding endpoint vulnerabilities with the recommendations already sitting in your tenant's Secure Score.
- Essential Eight — Patch operating systems
Alert policies for detected malware and phishing
Confirms someone is actually notified when Defender catches something significant, rather than it sitting in a portal nobody opens.
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.