Defender for Office 365 safeguards your organization against malicious threats posed by email messages, links (URLs) and collaboration tools^[[What is Microsoft Defender XDR? | Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide)]. In Microsoft 365 security, there are three main security services (or products) tied to your subscription type:^[[Office 365 Security including Microsoft Defender for Office 365 and Exchange Online Protection | Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/mdo-security-comparison?view=o365-worldwide)]
1. Exchange Online Protection (EOP).
2. Microsoft Defender for Office 365 365 Plan 1 (Defender for Office 365 P1).
3. Microsoft Defender for Office 365 365 Plan 2 (Defender for Office 365 P2).
Microsoft 365 security builds on the core protections offered by EOP. EOP is present in any subscription where Exchange Online mailboxes can be found (remember, all the security products discussed here are cloud-based).
![[Defender for Office 365 Layers.png]]
# Threat Policies
## Anti-Phishing
As of [[2024-03-11]] the **Automatic - System-controller impersonation protection** does not seem to activate. This may be because I recently adjusted the licensing to consolidate 365 Business Standard + Defender for 365 P1 into Business Premium.
## Actions
### Safety tips & indicators
Safety tips are warning messages that are shown to recipients when they open suspicious email messages.