Simple definition
Microsoft Defender for Office 365 protects Microsoft 365 email and collaboration workloads against phishing, malicious links, and dangerous attachments.
Technical definition
It adds specialized protections on top of Exchange Online antispam and antimalware controls. Safe Links scans URLs and can verify them at click time; Safe Attachments detonates suspicious attachments in an isolated environment before delivery; anti-phishing policies strengthen protection against spoofing and impersonation. Available capabilities depend on the Defender for Office 365 plan and licensing.
What is it used for?
Reduce risk from malicious email and collaboration content, apply stronger protection to sensitive users, and provide security teams with useful signals for investigation.
Practical example
A phishing message reaches a user’s mailbox. Safe Links checks the destination when the user clicks and can block access if the URL is considered malicious. A suspicious attachment can also be analyzed by Safe Attachments before delivery.
Common issues
- Safe Links or Safe Attachments policy does not target the intended users
- User or group is outside the protection scope
- Legitimate mail is quarantined as a false positive
- Expected capability is not included in the current license or plan
Key takeaway: Defender for Office 365 is not a tenant administration tool; its primary role is to protect email and collaboration content from threats.