Technically, Microsoft 365 mail can operate without Microsoft Defender for Office 365. Microsoft 365 already includes basic protection against spam, malware, and known threats by default. However, for professional business use, we strongly recommend providing a full advanced email security layer on top of that basic protection.
Email remains one of the main attack vectors for cybercriminals.
An organisation that relies solely on the standard built-in mail protection misses out on important additional detection and protection capabilities.
What is Microsoft Defender for Office 365?
Microsoft Defender for Office 365 is Microsoft's advanced security layer for email and Microsoft 365 collaboration.
Microsoft offers several levels.
- built-in Microsoft 365 security for cloud mailboxes;
- Defender for Office 365 Plan 1 for more advanced protection;
- Defender for Office 365 Plan 2 for additional detection, investigation, automation, and SOC functionality.
The standard protection and Defender for Office 365 are not the same level of security.
What do you get by default without Defender for Office 365?
Microsoft 365 includes standard security mechanisms to filter broad and known mail threats.
Think of, for example:
- spam filtering;
- anti-malware;
- anti-spoofing functionality;
- basic anti-phishing;
- mail flow and reputation checks.
But modern phishing and business email compromise require more than just classic spam and malware filtering.
Why is email still so important for attackers?
Because email reaches the user directly.
An attacker does not need to bypass a firewall if they can convince an employee to:
- click on a malicious link;
- open a fake Microsoft login window;
- execute a file;
- make a payment;
- enter a password;
- approve an MFA request;
- send back confidential information.
A convincing email can be enough.
What does Defender for Office 365 Plan 1 add?
Defender for Office 365 Plan 1 adds important advanced security features.
Microsoft mentions among others:
- Safe Links;
- Safe Attachments;
- extended anti-phishing protection;
- protection against zero-day malware;
- real-time detections;
- protection for SharePoint, OneDrive, and Teams;
- more advanced protection of internal mail.
What does Safe Links do?
Links are one of the most used techniques in phishing emails.
A malicious link can lead to:
- a fake Microsoft 365 login page;
- a malware download;
- a forged supplier website;
- a page trying to steal credentials;
- a website that only becomes malicious after sending.
Safe Links adds extra security around URLs in supported Microsoft 365 workloads.
Why is that important?
Attackers can use so-called delayed attacks.
In these, a website is initially harmless or inconspicuous but is later changed to steal credentials or offer malware.
What does Safe Attachments do?
Safe Attachments is designed to add protection against unknown and zero-day malware in files.
For suspicious or unknown attachments, additional checks can be performed before the user trusts the file blindly.
This is important because attackers regularly use:
- Office documents;
- PDF files;
- archives;
- other attachments;
- files not yet recognised by classic signatures.
And phishing without a link or attachment?
That is at least as important.
A modern phishing email can, for example, simply say:
I am currently in a meeting. Let me know once it is done."
No malware. No malicious attachment. No suspicious link.
Yet it can still be an attack.
What is impersonation?
In impersonation, an attacker tries to pose as a trusted person or organisation.
For example:
- the CEO;
- the CFO;
- HR;
- a supplier;
- a customer;
- another executive member.
The attacker can, for example:
- use a similar domain name;
- only mimic the display name;
- use an external account with a trusted name;
- imitate existing communication.
SPF, DKIM and DMARC do not make Defender redundant
SPF, DKIM and DMARC are essential for good email authentication.
They help, among other things, against direct spoofing of your domain.
But they do not automatically stop:
- lookalike domains;
- a hacked account of a real supplier;
- a convincing social engineering email;
- a malicious link from a correctly authenticated domain;
- a malicious attachment sent via a legitimate account.
One does not replace the other.
What is Defender for Office 365 Plan 2?
Plan 2 includes the security features of Plan 1 and adds more extensive investigation, detection, automation, and security operations capabilities.
Depending on current Microsoft functionality, this includes, among others, features related to:
- Threat Explorer;
- campaign views;
- advanced threat hunting and investigation;
- automated investigation and response;
- attack simulation training;
- more extensive SOC workflows.
Plan 2 adds much more research, response, automation, and security operations.
Do I already have Defender for Office 365?
That depends on your Microsoft 365 licence.
At the time of writing, for example:
- Microsoft 365 Business Premium includes Defender for Office 365 Plan 1;
- Office 365 E3 and Microsoft 365 E3 include Defender for Office 365 Plan 1 from 1 July 2026;
- Microsoft 365 E5 includes more extensive Defender for Office 365 Plan 2 functionality.
Policies, exceptions, anti-phishing settings, Safe Links, Safe Attachments, and other security components must be correctly configured.
Having Business Premium is therefore not automatically sufficient
Microsoft 365 Business Premium contains a very interesting security stack.
But there is a difference between:
The functionality may be used.
Professionally configured
The right policies, exceptions, detections, and processes are actually configured and monitored.
Does it have to be Microsoft Defender for Office 365?
No.
There are also other professional secure email gateways and cloud email security solutions.
The right choice depends on:
- the organisation's risk profile;
- the Microsoft 365 licences used;
- the desired anti-phishing capabilities;
- the desired filtering;
- integration with other security products;
- monitoring and incident response;
- compliance requirements;
- the existing security architecture.
The fundamental requirement is that corporate email is professionally protected against modern threats.
So can I work without Defender for Office 365?
Technically: yes.
Microsoft 365 mail continues to work and still has built-in basic protection.
The more important question is:
Email remains one of the most used attack vectors. Extra protection against phishing, malicious links, attachments, impersonation, and new threats is, in our opinion, not a luxury.
"We are just a small company"
Even a small company receives:
- invoices;
- payment requests;
- Microsoft 365 login links;
- customer communication;
- supplier emails;
- HR communication;
- confidential documents.
This makes email particularly attractive for fraud.
One convincing payment request can be enough.
"Our employees are well trained"
That is very important.
But security awareness should never be the only security layer.
Even experienced employees can:
- believe a very convincing phishing email;
- see a trusted supplier whose mailbox has indeed been hacked;
- overlook a misspelled domain name;
- act under time pressure;
- open a professionally forged Microsoft login page.
No email security stops everything
That must also be clear.
No product can guarantee that every dangerous email is always blocked.
Attackers constantly change their techniques.
Email security must work together with identity security
Suppose a phishing email still gets through the filtering.
You want other security layers to limit the impact.
For example:
- MFA;
- passkeys;
- Conditional Access;
- risk-based access;
- endpoint security;
- password management;
- monitoring of suspicious logins.
And SPF, DKIM and DMARC?
These also belong to a mature mail security architecture.
FLEXAMIT therefore looks not only at Defender for Office 365 but also at:
- SPF;
- DKIM;
- DMARC;
- anti-phishing policies;
- Safe Links;
- Safe Attachments;
- impersonation protection;
- quarantine policy;
- mail flow;
- external applications sending mail on behalf of your domain;
- security awareness;
- incident response.
This is exactly where FLEXAMIT is particularly strong
FLEXAMIT does not only check if Defender for Office 365 is "on".
We assess how the entire mail security environment works.
We look, among other things, at:
- which Microsoft 365 licences are present;
- which Defender functionality is available;
- which policies are active;
- whether preset security policies are correctly used;
- Safe Links;
- Safe Attachments;
- anti-phishing;
- impersonation protection;
- SPF, DKIM and DMARC;
- quarantine;
- mail flow and connectors;
- external mail platforms;
- alerting and follow-up;
- the impact on end users.
Too little filtering lets dangerous mail through.
Too aggressive or poorly designed filtering causes false positives, unnecessary quarantine, and employees not receiving important mail.
FLEXAMIT therefore tailors the security to your organisation, the applications used, senders, users, and risks.
Maximum security where needed. As little inconvenience as possible where possible.
Why specialist configuration is important
Email security contains many exceptions and dependencies.
A wrong setting can, for example:
- block legitimate mail;
- let phishing through unnecessarily;
- allowlist an entire partner organisation too broadly;
- weaken impersonation protection;
- apply Safe Links or Safe Attachments incorrectly;
- create security alerts that no one follows up on.
FLEXAMIT seeks the right balance
A manufacturing company, law firm, retailer, and financial organisation do not have exactly the same mail traffic.
That is why the configuration should not be identical either.
FLEXAMIT takes into account:
- the sector;
- the suppliers used;
- critical correspondence;
- shared mailboxes;
- marketing platforms;
- CRM and ERP systems;
- scanners and applications that send email;
- risk users such as management, finance, and HR;
- the desired user experience.
It is the policy that blocks as many threats as possible while reliably allowing legitimate business communication to proceed.
Why FLEXAMIT is a particularly strong partner for this
Good email security requires knowledge of multiple domains simultaneously.
- Exchange Online;
- Microsoft Defender for Office 365;
- Microsoft Entra;
- SPF;
- DKIM;
- DMARC;
- phishing and BEC;
- identity security;
- endpoint security;
- security awareness;
- incident response.
FLEXAMIT combines this knowledge into a coherent mail security model.
We ensure not only that technology is present but that it is correctly configured, tested, and tailored to how your organisation actually communicates.
The result must simultaneously:
- be strongly protected against phishing and malware;
- reduce BEC and impersonation risks;
- reliably deliver legitimate mail;
- not overwhelm users with unnecessary alerts;
- remain manageable for IT;
- grow with the organisation.
Our cybersecurity expertise has been recognised three years in a row by our Microsoft distributor with the award Cybersecurity Partner of the Year.
Don't know how your mail environment is secured today?
Then have it assessed.
FLEXAMIT can, among other things, check:
- which Defender for Office 365 licences you have;
- which policies are actually active;
- Safe Links and Safe Attachments;
- anti-phishing and impersonation protection;
- SPF, DKIM and DMARC;
- allowlists and exceptions;
- quarantine policy;
- mail flow and external sending platforms;
- security alerts and follow-up;
- the overall mail security maturity.
Contact us via:
sales@flexamit.com
Received suspicious email?
If you are a FLEXAMIT customer and doubt a message?
Contact us via:
support@flexamit.com
Especially if you have already clicked a link, entered credentials, opened a file, or approved an MFA request, quick reporting is important.
In summary
- Microsoft 365 includes basic email protection by default.
- Defender for Office 365 adds more advanced security.
- Plan 1 includes, among other things, Safe Links, Safe Attachments, anti-phishing, and real-time detections.
- Plan 2 adds more extensive investigation, automation, hunting, and security operations capabilities.
- Microsoft 365 Business Premium includes Defender for Office 365 Plan 1.
- Office 365 E3 and Microsoft 365 E3 also include Plan 1 from 1 July 2026.
- SPF, DKIM and DMARC do not make advanced email security redundant.
- Security awareness alone is insufficient.
- No product can block 100% of all phishing.
- Email security must work together with identity, endpoint, and user security.
- A licence alone is insufficient: policies must be professionally configured.
- The question is therefore not only whether mail works without Defender for Office 365, but whether your company can responsibly operate without advanced email security. Our advice: do not do that.
Comments
0 comments
Please sign in to leave a comment.