Microsoft Defender for Office 365 is email security for Microsoft 365 tenants, protecting against phishing, malware, spoofing and impersonation attacks. It comes in two plans priced from £1.54 per user per month, with Plan 1 including foundational protection and Plan 2 adding advanced hunting and automation.
Listing updated . Checked by MSP Software .
Microsoft Defender for Office 365 is a cloud-native email security solution from Microsoft designed to protect Microsoft 365 organizations from advanced email-based threats. It defends against phishing, malware, spoofing, impersonation and zero-day attacks using machine learning and human expertise. The service integrates natively into Outlook, Microsoft Teams, SharePoint and OneDrive without requiring a separate security gateway or email routing change.
Defender for Office 365 comes in two plans. Plan 1, starting at £1.54 per user per month when billed annually (checked September 2026), provides foundational protection with Safe Attachments that detonate files in a virtual environment, Safe Links that rewrite and test URLs in real-time, anti-phishing with spoofing and impersonation detection, and real-time reporting. Plan 2, at £3.80 per user per month, adds advanced threat hunting with Threat Explorer, automated investigation and response (AIR) for handling incidents, attack simulation training for security awareness, and cross-domain XDR capabilities. Both plans include quarantine management, DMARC policy support and Microsoft 365 user synchronization for policy targeting.
Defender for Office 365 suits MSPs managing Microsoft 365 tenants who want integrated email security without a third-party service. It is particularly suited to smaller or mid-market tenants where per-user licensing fits the budget better than flat-rate security products. As of July 2026, Plan 1 is included with Office 365 E3 and Microsoft 365 E3, making it more accessible to budget-conscious organizations. MSPs should verify that Plan 1 covers their specific needs before assuming Plan 2's advanced features are unnecessary. They should also confirm their SIEM or SOC tool can ingest Defender alerts through Microsoft Graph API or webhook connectors for centralized visibility. The product pairs well with Microsoft Defender for Endpoint for comprehensive endpoint and email security coverage.
Defender for Office 365 is the only native option if you are running Microsoft 365 and want email security without a separate product. Its main strength is tight Microsoft 365 integration and per-user pricing that aligns with employee headcount rather than flat-rate billing. Compare against third-party email security products like Mimecast or Proofpoint Essentials if you want advanced features like archive-in-place or threat detonation that go beyond Defender's scope. For MSPs, the key trade-off is that Plan 1 is now included with E3 but Plan 2's automation and hunting tools require understanding of Microsoft security operations centre console and incident response workflows.
| Feature | Supported | Note |
|---|---|---|
| Phishing and malware filtering | yes | AI and machine learning based detection with customizable phishing thresholds |
| Spoofing and impersonation protection | yes | User, domain and sender impersonation detection with mailbox intelligence |
| Email continuity | yes | Protection for Teams, SharePoint and OneDrive collaboration |
| Archiving | yes | Archiving support via Microsoft 365 Purview compliance |
| Security awareness training bundle | yes | Attack simulation training with de-weaponized payloads in Plan 2 |
| API-based post-delivery scanning | yes | Safe Attachments and Safe Links use machine learning and dynamic analysis |
| DMARC monitoring | yes | DMARC policy support with configurable actions for p=quarantine and p=reject |
| Attachment sandboxing | yes | Safe Attachments detonates files in isolated environment |
| Data loss prevention | yes | Data Loss Prevention integrated with Microsoft 365 Purview |
| Email encryption | yes | Message encryption via Microsoft 365 Information Protection |
| Microsoft 365 integration | yes | Native to Microsoft 365 with no separate gateway required |
| Self-service quarantine | yes | End users can review and release quarantined messages |
| Feature | Supported |
|---|---|
| Phishing simulation campaigns | unknown |
| Training content library | unknown |
| Automated remediation training | unknown |
| Phish-reporting button | unknown |
| Multi-language content | unknown |
| Compliance training modules | unknown |
| Client-facing reporting | unknown |
| Microsoft 365 and Google user sync | unknown |
| Smishing and vishing simulation | unknown |
| Gamification | unknown |
| Campaign scheduling automation | unknown |
| PSA integration for billing | unknown |
Microsoft Defender for Office 365 Plan 1 provides foundational email protection with Safe Attachments, Safe Links, anti-phishing and real-time reporting, starting at £1.54 per user per month (checked September 2026). Plan 2 at £3.80 per user per month includes all Plan 1 features plus threat hunting with Explorer, automated investigation and response (AIR) that can automatically isolate compromised accounts, attack simulation training for end user security awareness, and advanced hunting and analytics. Plan 1 is sufficient for organizations that want basic email security without advanced incident response automation.
Microsoft Defender for Office 365 is designed for Microsoft 365 cloud mailboxes and does not protect on-premises Exchange servers directly. If you have a hybrid deployment with both cloud and on-premises mailboxes, Microsoft Defender for Office 365 protects only the Microsoft 365 portion. For on-premises Exchange, you would need Exchange Online Protection or a third-party email security gateway. MSPs managing hybrid environments should plan email security separately for the on-premises infrastructure.
Microsoft Defender for Office 365 offers a 90-day free trial of Plan 2 through the Microsoft Defender portal trials hub. This allows MSPs and organizations to evaluate advanced features including threat hunting, automated investigation and response, and attack simulation training before committing to a paid subscription. Trial registration requires a Microsoft 365 tenant and appropriate administrator permissions. After the trial expires, the subscription reverts to the paid tier or is terminated depending on your account settings.
Microsoft Defender for Office 365 Plan 1 is now included with Office 365 E3 and Microsoft 365 E3 licensing as of July 1, 2026. This means organizations with E3 subscriptions receive foundational email protection at no additional cost. If you want Plan 2 features (automated incident response, threat hunting, attack simulations), you must purchase Plan 2 as an add-on. This makes Defender for Office 365 more cost-effective for E3 customers than it was previously, since the basic protection is no longer a separate line item.
Microsoft Defender for Office 365 can send alerts and incident data to RMM and PSA systems via Microsoft Graph API, webhook connectors or email forwarding. MSPs using ConnectWise RMM, Datto RMM and NinjaOne can configure integrations to create tickets when security incidents are detected. However, Defender for Office 365 itself does not have a built-in alert routing engine like some third-party email security products. Integration typically requires manual configuration of Microsoft Sentinel, Power Automate or API calls to your PSA to automate ticket creation from Defender alerts.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review