Microsoft is adding Defender for Office 365 Plan 1 to Microsoft 365 E3 and Office 365 E3 subscriptions.
The rollout started on June 17, 2026, and should be completed by autumn 2026.
This is a significant security improvement for E3 tenants. However, two details require attention:
- Protection is enabled automatically for licensed users.
- The default configuration is not the configuration Microsoft recommends.
Rollout and licensing dates
The rollout and licensing dates are not identical.
According to the Microsoft announcement, deployment started on June 17, 2026, and will be completed by autumn 2026.
The Microsoft service description specifies that Defender for Office 365 Plan 1 is included with Office 365 E3 and Microsoft 365 E3 from July 1, 2026.
Licensing entitlement and feature activation therefore follow two different timelines.
Your tenant may be entitled to Plan 1 several weeks before the associated features appear in the Microsoft Defender portal.
Do not assume that your tenant is excluded simply because nothing has changed yet.
What Defender for Office 365 Plan 1 includes
Defender for Office 365 Plan 1 extends the Exchange Online Protection features already included with E3 subscriptions.
The main features are:
- Safe Links
- Safe Attachments
- Advanced anti-phishing protection
- Real-time detections
- Email entity pages
- User tags
Safe Links
Safe Links checks URLs when users click them rather than relying only on the reputation of the URL when the message is delivered.
This protection also applies to URLs contained in QR codes.
Safe Attachments
Safe Attachments analyzes unknown files in an isolated environment before they are delivered to users.
The protection can also cover files stored in:
- Microsoft SharePoint
- Microsoft OneDrive
- Microsoft Teams
Advanced anti-phishing protection
Advanced anti-phishing policies provide additional protection against impersonation attacks.
You can configure protection for:
- Specific users
- Executives
- Trusted domains
- Frequently targeted addresses
The policies also provide configurable phishing thresholds.
Real-time detections
Plan 1 includes the Real-time detections view in the Microsoft Defender portal.
It also provides access to email entity pages and user tags, including the priority account tag.
Microsoft Teams protection
Defender for Office 365 Plan 1 also adds several protections for Microsoft Teams:
- Time-of-click protection for URLs and files
- Tenant Allow/Block List support
- Zero-hour auto purge
- Teams messages in quarantine
- Teams message entity pages
- User reporting for Teams messages
Microsoft Teams already included some security features before this licensing change:
- Built-in malware protection
- External domain anomaly reporting
- Near real-time URL warnings for messages up to 48 hours after delivery
Plan 1 adds time-of-click analysis, which checks the destination when the user opens the link.
What is not included
Defender for Office 365 Plan 1 should not be confused with Plan 2.
The following features are not included with Microsoft 365 E3 or Office 365 E3:
- Threat Explorer
- Automated Investigation and Response
- Attack simulation training
- Threat Trackers
- Campaign views
- Advanced hunting for Teams messages
- Removal of users from Teams chats
- Priority account protection
Priority account protection is different from the priority account user tag.
Plan 1 includes the tag, but not the additional protection features associated with priority accounts.
How to identify Plan 1
Microsoft provides a simple way to determine which Defender for Office 365 plan is active.
In the Microsoft Defender portal, open:
Email & collaboration > Real-time detections
If Real-time detections is available but Threat Explorer is not, the tenant is using Plan 1.
Threat Explorer requires Plan 2.
Built-in protection is enabled automatically
When Plan 1 becomes available in your tenant, Microsoft automatically applies the built-in protection preset policy to licensed users.
This provides a minimum security baseline without requiring administrator action.
However, the built-in protection policy is not Microsoft’s recommended configuration.
Microsoft provides three preset security policy levels:
- Built-in protection
- Standard protection
- Strict protection
The Standard and Strict preset policies must be enabled manually.
A tenant that takes no action will therefore receive additional protection, but it will remain on the weakest of the three available policy levels.
Administrators should review the preset security policies and determine whether Standard or Strict protection is appropriate for their environment.
Configure exclusions before the rollout
Some users, domains or applications may require exclusions from the built-in protection policy.
Common examples include:
- Automated mail-processing systems
- Security testing platforms
- Internal phishing simulation tools
- Business applications sending unusual attachments
- Trusted domains using non-standard mail flows
Identify these requirements before activation rather than after users begin reporting blocked messages or URLs.
Microsoft allows exclusions to be configured for the built-in preset security policy.
Third-party email gateway considerations
Organizations using a third-party secure email gateway such as Proofpoint, Mimecast, Barracuda, Cisco Secure Email or Fortinet FortiMail should review their configuration before Defender for Office 365 Plan 1 is activated.
Without preparation, the gateway and Microsoft Defender may both scan attachments and rewrite URLs, which can create detection gaps, user confusion and troubleshooting issues.
Review the following areas:
- Enable Enhanced Filtering for Connectors so Exchange Online can evaluate the original sender, source IP, authentication results and spoofing signals.
- Ensure that the gateway preserves the original sender and connection details.
- Avoid double URL rewriting. Choose either the third-party gateway or Safe Links as the primary URL-rewriting service.
- Review whether the existing gateway still provides enough additional value now that E3 includes URL protection, attachment sandboxing, impersonation protection and investigation capabilities.
Before activation, document the current mail flow, review inbound connectors, identify required exclusions and inform the service desk about possible Safe Links warnings.
After activation, monitor Real-time detections, quarantined messages, user reports and Microsoft Secure Score for unexpected changes.
Preparation checklist
Before Defender for Office 365 Plan 1 is activated:
- Document the current mail flow.
- Identify the protections already enabled.
- Review the built-in protection preset policy.
- Decide whether to enable Standard or Strict protection.
- Document the reason for the selected protection level.
- Identify users, domains and applications requiring exclusions.
- Inform the service desk and the users about Safe Links warning and blocking pages.
- Review inbound connectors.
- Enable Enhanced Filtering for Connectors when required.
- Confirm that the original sender information is preserved.
- Decide which platform will rewrite URLs.
- Review your third-party email gateway configuration.
After activation:
- Monitor the Microsoft Defender portal.
- Review Real-time detections.
- Check quarantined email and Teams messages.
- Monitor user-reported messages.
- Review Microsoft Secure Score recommendations.
- Investigate unexpected increases in blocked links or attachments.
Conclusion
Adding Safe Links, Safe Attachments and advanced anti-phishing protection to Microsoft 365 E3 and Office 365 E3 is a significant security improvement.
E3 tenants will receive protections that previously required an additional Defender for Office 365 licence.
However, the main risk is the difference between having the features enabled and having them correctly configured.
The built-in protection preset policy is a baseline, not the target configuration.
Organizations using a third-party email gateway must also review their connectors, sender information and URL-rewriting configuration before Plan 1 reaches their tenant.