← Microsoft 365 audit scope

Microsoft Defender

10 checks · 2 sub-categories

Defender for Office 365 and Exchange Online Protection are the filters standing between your staff and the phishing email that starts the incident. The licences are usually already paid for; the policies are frequently left on defaults that don't cover Teams, don't protect your executives from impersonation, and don't rewrite malicious links.

Email threat policies

  • Anti-phishing policy with impersonation protection

    Checks that your directors, finance staff and domain are explicitly protected against display-name and lookalike-domain impersonation — the mechanics of nearly every invoice-fraud attempt.

    • ACSC — Business Email Compromise guidance
  • Safe Links enabled for email, Office apps and Teams

    URLs are rewritten and checked at click time, catching links that were clean at delivery and weaponised an hour later.

  • Safe Attachments enabled

    Attachments are detonated in a sandbox before delivery. We also check the SharePoint, OneDrive and Teams extension, which is off by default in many tenants.

    • CIS 2.5
  • Disallow download of infected files

    The companion setting to Safe Attachments — without it, a file flagged as malicious in SharePoint can still be downloaded.

    • CIS 2.6
  • Anti-malware policy and common attachment filter

    Confirms executable and script attachment types are blocked at the gateway rather than left to the endpoint.

    • Essential Eight — Application control
  • Zero-hour Auto Purge (ZAP) enabled

    Retroactively removes phishing and malware from mailboxes after delivery, once the threat is identified.

  • Anti-spam policy and quarantine release permissions

    Checks whether users can release their own quarantined mail — a common way filtered phishing ends up in the inbox anyway.

Endpoint and detection signal

  • Defender for Endpoint deployment coverage

    Where licensed, we report which devices are onboarded and which are running unmanaged or with real-time protection disabled.

    • Essential Eight — Application control
    • Essential Eight — Patch applications
  • Threat and vulnerability findings surfacing in Secure Score

    Correlates outstanding endpoint vulnerabilities with the recommendations already sitting in your tenant's Secure Score.

    • Essential Eight — Patch operating systems
  • Alert policies for detected malware and phishing

    Confirms someone is actually notified when Defender catches something significant, rather than it sitting in a portal nobody opens.

Want to know where you actually stand?

Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.