Browser limitation detected

Facebook browser may limit features like the Menu. For the best experience, please tap (...) and choose 'Open in Browser'.

Photo by Noah Näf / Unsplash
Microsoft Defender for Office 365 Plan 1 comes to Microsoft 365 E3 and Office 365 : What Changes

Microsoft Defender for Office 365 Plan 1 comes to Microsoft 365 E3 and Office 365 : What Changes

— 5 min read

Microsoft is adding Defender for Office 365 Plan 1 to Microsoft 365 E3 and Office 365 E3 subscriptions.

The rollout started on June 17, 2026, and should be completed by autumn 2026.

This is a significant security improvement for E3 tenants. However, two details require attention:

  • Protection is enabled automatically for licensed users.
  • The default configuration is not the configuration Microsoft recommends.

Rollout and licensing dates

The rollout and licensing dates are not identical.

According to the Microsoft announcement, deployment started on June 17, 2026, and will be completed by autumn 2026.

The Microsoft service description specifies that Defender for Office 365 Plan 1 is included with Office 365 E3 and Microsoft 365 E3 from July 1, 2026.

Licensing entitlement and feature activation therefore follow two different timelines.

Your tenant may be entitled to Plan 1 several weeks before the associated features appear in the Microsoft Defender portal.

Do not assume that your tenant is excluded simply because nothing has changed yet.

What Defender for Office 365 Plan 1 includes

Defender for Office 365 Plan 1 extends the Exchange Online Protection features already included with E3 subscriptions.

The main features are:

  • Safe Links
  • Safe Attachments
  • Advanced anti-phishing protection
  • Real-time detections
  • Email entity pages
  • User tags

Safe Links checks URLs when users click them rather than relying only on the reputation of the URL when the message is delivered.

This protection also applies to URLs contained in QR codes.

Safe Attachments

Safe Attachments analyzes unknown files in an isolated environment before they are delivered to users.

The protection can also cover files stored in:

  • Microsoft SharePoint
  • Microsoft OneDrive
  • Microsoft Teams

Advanced anti-phishing protection

Advanced anti-phishing policies provide additional protection against impersonation attacks.

You can configure protection for:

  • Specific users
  • Executives
  • Trusted domains
  • Frequently targeted addresses

The policies also provide configurable phishing thresholds.

Real-time detections

Plan 1 includes the Real-time detections view in the Microsoft Defender portal.

It also provides access to email entity pages and user tags, including the priority account tag.

Microsoft Teams protection

Defender for Office 365 Plan 1 also adds several protections for Microsoft Teams:

  • Time-of-click protection for URLs and files
  • Tenant Allow/Block List support
  • Zero-hour auto purge
  • Teams messages in quarantine
  • Teams message entity pages
  • User reporting for Teams messages

Microsoft Teams already included some security features before this licensing change:

  • Built-in malware protection
  • External domain anomaly reporting
  • Near real-time URL warnings for messages up to 48 hours after delivery

Plan 1 adds time-of-click analysis, which checks the destination when the user opens the link.

What is not included

Defender for Office 365 Plan 1 should not be confused with Plan 2.

The following features are not included with Microsoft 365 E3 or Office 365 E3:

  • Threat Explorer
  • Automated Investigation and Response
  • Attack simulation training
  • Threat Trackers
  • Campaign views
  • Advanced hunting for Teams messages
  • Removal of users from Teams chats
  • Priority account protection

Priority account protection is different from the priority account user tag.

Plan 1 includes the tag, but not the additional protection features associated with priority accounts.

⚠️
Attack simulation training remains a Plan 2 feature. Adding Plan 1 to E3 does not replace a third-party phishing simulation platform.

How to identify Plan 1

Microsoft provides a simple way to determine which Defender for Office 365 plan is active.

In the Microsoft Defender portal, open:

Email & collaboration > Real-time detections

If Real-time detections is available but Threat Explorer is not, the tenant is using Plan 1.

Threat Explorer requires Plan 2.

Built-in protection is enabled automatically

When Plan 1 becomes available in your tenant, Microsoft automatically applies the built-in protection preset policy to licensed users.

This provides a minimum security baseline without requiring administrator action.

However, the built-in protection policy is not Microsoft’s recommended configuration.

Microsoft provides three preset security policy levels:

  • Built-in protection
  • Standard protection
  • Strict protection

The Standard and Strict preset policies must be enabled manually.

A tenant that takes no action will therefore receive additional protection, but it will remain on the weakest of the three available policy levels.

⚠️
Automatic activation does not mean that Defender for Office 365 is fully configured.

Administrators should review the preset security policies and determine whether Standard or Strict protection is appropriate for their environment.

Configure exclusions before the rollout

Some users, domains or applications may require exclusions from the built-in protection policy.

Common examples include:

  • Automated mail-processing systems
  • Security testing platforms
  • Internal phishing simulation tools
  • Business applications sending unusual attachments
  • Trusted domains using non-standard mail flows

Identify these requirements before activation rather than after users begin reporting blocked messages or URLs.

Microsoft allows exclusions to be configured for the built-in preset security policy.

Third-party email gateway considerations

Organizations using a third-party secure email gateway such as Proofpoint, Mimecast, Barracuda, Cisco Secure Email or Fortinet FortiMail should review their configuration before Defender for Office 365 Plan 1 is activated.

Without preparation, the gateway and Microsoft Defender may both scan attachments and rewrite URLs, which can create detection gaps, user confusion and troubleshooting issues.

Review the following areas:

  • Enable Enhanced Filtering for Connectors so Exchange Online can evaluate the original sender, source IP, authentication results and spoofing signals.
  • Ensure that the gateway preserves the original sender and connection details.
  • Avoid double URL rewriting. Choose either the third-party gateway or Safe Links as the primary URL-rewriting service.
  • Review whether the existing gateway still provides enough additional value now that E3 includes URL protection, attachment sandboxing, impersonation protection and investigation capabilities.

Before activation, document the current mail flow, review inbound connectors, identify required exclusions and inform the service desk about possible Safe Links warnings.

After activation, monitor Real-time detections, quarantined messages, user reports and Microsoft Secure Score for unexpected changes.

Preparation checklist

Before Defender for Office 365 Plan 1 is activated:

  • Document the current mail flow.
  • Identify the protections already enabled.
  • Review the built-in protection preset policy.
  • Decide whether to enable Standard or Strict protection.
  • Document the reason for the selected protection level.
  • Identify users, domains and applications requiring exclusions.
  • Inform the service desk and the users about Safe Links warning and blocking pages.
  • Review inbound connectors.
  • Enable Enhanced Filtering for Connectors when required.
  • Confirm that the original sender information is preserved.
  • Decide which platform will rewrite URLs.
  • Review your third-party email gateway configuration.

After activation:

  • Monitor the Microsoft Defender portal.
  • Review Real-time detections.
  • Check quarantined email and Teams messages.
  • Monitor user-reported messages.
  • Review Microsoft Secure Score recommendations.
  • Investigate unexpected increases in blocked links or attachments.

Conclusion

Adding Safe Links, Safe Attachments and advanced anti-phishing protection to Microsoft 365 E3 and Office 365 E3 is a significant security improvement.

E3 tenants will receive protections that previously required an additional Defender for Office 365 licence.

However, the main risk is the difference between having the features enabled and having them correctly configured.

The built-in protection preset policy is a baseline, not the target configuration.

Organizations using a third-party email gateway must also review their connectors, sender information and URL-rewriting configuration before Plan 1 reaches their tenant.

banner-Bastien Perez
Bastien Perez avatar

Freelance Microsoft 365 - Active Directory - Modern Workplace

France