Impersonation protection only defends the people you name in it. Almost nobody names anybody, and then the wire transfer goes out.
Spoof intelligence, DMARC policy honoring, and implicit authentication come with every cloud mailbox regardless of what you pay. Defender for Office 365 adds three more: impersonation protection for senders and domains you name, mailbox intelligence, and phishing thresholds you can move. Every one of those three needs somebody to configure it, and across the tenants we review, none of them ever has been.

- Two tiersAll cloud mailboxes, then Defender for Office 365
- Named sendersImpersonation protection must be configured
- AdjustablePhishing email thresholds are a policy setting
- Campaign ViewsCoordinated attacks analyzed across the service
Seven controls, and the ones that stop invoice fraud do nothing until somebody fills them in.
Impersonation protection, for senders and domains you name
The policies configure impersonation protection for specific senders and specific sender domains. Specific is the word carrying all the weight. Nothing whatsoever protects your finance director from being impersonated until a human types their name and address into that policy, and in most tenants we open that list is either empty or describes the leadership team from three years ago.
Mailbox intelligence, which learns the sender relationships
Mailbox intelligence is configured in the same policy. Instead of matching against a fixed list, it learns who each person normally exchanges mail with. That is how a message from a vendor address that has never once written to this employee becomes suspicious, without anybody having to predict that particular vendor in advance.
Adjustable phishing email thresholds
The policy exposes adjustable phishing thresholds controlling how aggressive detection is. That is a genuine dial with a genuine trade-off attached, and it deserves a decision rather than whatever the tenant shipped with. A company currently under business email compromise pressure almost always wants it set higher than the level it inherited.
Spoof intelligence, available to every cloud mailbox
The spoof intelligence insight shows you which spoofed senders were detected across both external and internal domains, and lets you allow or block each one by hand. The policies available on every cloud mailbox control whether spoof intelligence runs at all, whether Outlook displays the unauthenticated sender indicator, and what actually happens to a message from a blocked spoofed sender.
Honoring the sender DMARC policy
One setting decides what happens when a sender fails explicit DMARC checks and their own published policy says quarantine or reject. That is the difference between respecting what a legitimate domain owner has asked the world to do with forgeries of their name and quietly ignoring it. Almost nobody has ever consciously made that choice.
Campaign Views, which show you the pattern instead of one message
Machine learning and other heuristics identify messages belonging to coordinated campaigns, both across the whole service and against your organization specifically. That turns an investigation from one reported email into a view of the entire campaign it belongs to, including everyone else who received it and how the sending pattern behaved.
Implicit email authentication, on top of the records
The standard authentication checks on inbound mail, SPF, DKIM and DMARC, are supplemented with sender reputation, sender history, recipient history, behavioral analysis, and further techniques aimed at identifying forgery. Your own records still matter enormously, but the platform is not depending on them alone.
Business email compromise runs on forged trusted senders, and the control that stops it is inert until somebody fills in a list.
The attack is defined precisely in the documentation, and the control that answers it happens to be the one demanding the most manual input.
- The definition: business email compromise forges trusted senders, specifically naming financial officers, customers, and trusted partners, in order to get somebody to approve a payment, move funds, or hand over customer data. The FBI has ranked it among the costliest categories of cybercrime reported by American businesses for several years running.
- The matching control is impersonation protection, configured inside a Defender for Office 365 anti-phishing policy against specific senders and specific sender domains. It defends the people and domains on your list, and nobody else.
- The list needs your executives on it, your finance and accounts payable staff, your board members, and the domains of the customers and vendors who actually appear in payment conversations. It also needs somebody maintaining it, because people join, leave, and change jobs, and a list assembled during a deployment project two years ago now protects a leadership team that has moved on.
- The impersonation insight then shows what was actually detected, which serves as both an operational tool and proof the configuration is doing something. An empty insight at a company that approves payments over email almost never means nobody is trying. It means the policy is empty.
Four findings that turn up in almost every tenant we review.
The protected list is empty, or it defends people who left last year
Protection extends to exactly the senders and sender domains you configure and no further. In most tenants that list is empty, or was filled in once during a deployment project and never touched since. Rebuilding it around the leadership team you have now, the finance function, and the customer and vendor domains that genuinely appear in payment conversations takes a single afternoon.
The phishing thresholds were never a decision
They can be adjusted, which means somebody was supposed to choose. In practice companies run whatever value the tenant was created with years ago. Setting them deliberately, against the pressure the business is actually under and with the false positive trade understood, is a change with a measurable effect and no licensing cost attached.
The DMARC honoring setting has never been looked at
This setting decides what happens when a sender fails explicit DMARC checks and their own published policy says quarantine or reject. Choosing to honor it means respecting what legitimate domain owners have publicly asked the world to do with forgeries of their name. It sits beside your own DMARC record work rather than replacing it, and the two are worth doing in the same project.
Campaign Views is available and nobody has opened it
Machine learning and heuristics identify messages belonging to coordinated campaigns aimed at the service generally and at you specifically. When somebody reports a suspicious email, this view answers in seconds who else received it and what the campaign actually looks like. It is among the highest value features in the product and among the least opened.
Six US situations where anti-phishing configuration is the difference.
A firm that authorizes payments by email
Business email compromise forges a trusted sender, with financial officers, customers, and trusted partners named specifically, in order to get somebody to approve a payment, move funds, or release customer data. Impersonation protection covering those senders and their domains is the direct control, and it does absolutely nothing until the list has names in it.
A business whose executives are publicly identifiable
Whaling aims at executives and other high value targets for maximum effect, and American leadership teams are listed on the company website, quoted in trade publications, and fully visible on LinkedIn. Reconnaissance costs an attacker about twenty minutes, which is precisely the precondition the documentation describes for spear phishing.
A company that trades with a defined set of significant partners
Domain impersonation protection covers whichever sender domains you name. Where the bulk of your payment instructions arrive from a known set of customers and vendors, naming those domains explicitly closes the most likely route. It is a short list that rarely changes, which is exactly what makes it maintainable.
An operator whose ransomware exposure starts in the inbox
Ransomware almost always begins with a phishing message. Anti-phishing protection cannot decrypt a single file after the event, but it can catch the message that started the campaign. That reframes this configuration as ransomware prevention rather than as an email quality problem, and it happens to be exactly how your cyber carrier sees it at renewal.
An organization running phishing simulations without configuring the controls
Attack simulation training lets an administrator build fake phishing messages and send them to staff as a teaching exercise. It is genuinely valuable and it is not a substitute for configuration. Measuring whether people click while impersonation protection sits empty tests the human layer thoroughly and leaves the technical one completely untouched.
An organization investigating a reported message
During an investigation, three questions matter: how many people got this, is it part of something coordinated, and what else arrived from the same source. Campaign Views answers all three. Put beside the impersonation insight showing what was detected, it turns one reported message into an actual understanding of what is happening to you.
How US organizations configure anti-phishing today.
| Feature | Configured and maintained | Licensed, left at defaults | Basic mailbox protection only |
|---|---|---|---|
Spoof intelligence active | Yes | Yes | Yes |
Sender DMARC policy honored | Yes | Unverified | Unverified |
Executives protected from impersonation | Yes | No | Not available |
Vendor domains protected | Yes | No | Not available |
Mailbox intelligence configured | Yes | Partly | Not available |
Thresholds set deliberately | Yes | No | Not available |
Impersonation insight reviewed | Yes | No | Not available |
Campaign Views used in investigations | Yes | No | Not available |
Protected lists maintained as people change | Yes | No | Not applicable |
Position against targeted invoice fraud | Defended | Exposed | Exposed |
What comes with any mailbox, against what the paid tier adds.
Capability
Spoof intelligence and the spoof intelligence insight
- Tier
- All cloud mailboxes
- Does it work without configuration
- Detection happens on its own, though overriding a verdict is manual review work
Capability
Anti-phishing policies for all cloud mailboxes
- Tier
- All cloud mailboxes
- Does it work without configuration
- Defaults exist, but the spoof action and the Outlook indicator are both decisions
Capability
Honor the sender DMARC policy on spoof detection
- Tier
- All cloud mailboxes
- Does it work without configuration
- A configuration decision about quarantine and reject policies
Capability
Spoofed senders in the Tenant Allow/Block List
- Tier
- All cloud mailboxes
- Does it work without configuration
- Entries arrive when you override a verdict, and can also be created by hand in advance
Capability
Implicit email authentication
- Tier
- All cloud mailboxes
- Does it work without configuration
- Yes, it augments SPF, DKIM and DMARC automatically
Capability
Impersonation protection for named senders
- Tier
- Defender for Office 365
- Does it work without configuration
- No. It protects only the senders you enter
Capability
Impersonation protection for named sender domains
- Tier
- Defender for Office 365
- Does it work without configuration
- No. It protects only the domains you enter
Capability
Mailbox intelligence
- Tier
- Defender for Office 365
- Does it work without configuration
- Learns relationships, but the policy settings still need configuring
Capability
Adjustable phishing email thresholds
- Tier
- Defender for Office 365
- Does it work without configuration
- A dial with a default value, and that default is a choice somebody else made for you
Capability
Impersonation insight
- Tier
- Defender for Office 365
- Does it work without configuration
- Reports what impersonation protection caught, which means it mirrors your own configuration
Capability
Campaign Views
- Tier
- Defender for Office 365
- Does it work without configuration
- Yes, but only useful if somebody looks at it
Capability
Attack simulation training
- Tier
- Defender for Office 365
- Does it work without configuration
- No. It is a program you run, not a setting
Five steps, with most of the value arriving in the first two.
- 1
Inventory the current policies and what they actually contain
Which policies actually exist, who each one applies to, how spoof intelligence and the Outlook unauthenticated sender indicator are set, what happens to a blocked spoofed sender, and whether anybody has ever given a moment thought to the DMARC honoring setting.
- 2
Rebuild the impersonation lists around the current business
Protected senders covering the leadership team as it stands today, everyone in finance and accounts payable, and anybody whose name appears on a payment instruction. Protected domains covering the customers and vendors who genuinely matter. Then an owner by name, because this list decays quietly every time somebody joins, leaves, or changes role.
- 3
Set thresholds and mailbox intelligence deliberately
Phishing thresholds chosen deliberately against the pressure your business is genuinely under, rather than inherited from whenever the tenant was created, with the false positive trade understood in advance and a working route for somebody to report a message that got caught wrongly.
- 4
Review the spoofed senders list and the insight
Every override in the spoof intelligence insight becomes a manual allow or block entry on the spoofed senders tab of the Tenant Allow and Block List. Those accumulate across years and are almost never revisited, which means a permitted spoof from a vendor relationship that ended three years ago may well still be sitting there quietly working.
- 5
Establish the operating rhythm
Somebody has to review the impersonation insight, somebody has to open Campaign Views when a message is reported, the reporting route needs maintaining, and the protected lists need an owner. Attack simulation training can sit on top as the human layer, running alongside the configuration rather than in place of it.
What organizations ask about anti-phishing policies.
Fifteen checks worth running on an existing tenant.
Impersonation
- Who is on the protected senders list?Frequently empty, frequently stale.
- Is the current leadership team on it?People change roles.
- Are finance and accounts payable staff protected?They are the actual target.
- Which sender domains are protected?Key customers and vendors.
- Does the impersonation insight show activity?Empty usually means unconfigured.
Spoof and authentication
- Is spoof intelligence on?It is a policy setting.
- Do you honor sender DMARC policies?For quarantine and reject.
- Are unauthenticated sender indicators shown?The Outlook visual cue.
- What is the action for blocked spoofed senders?Specified in the policy.
- Has anyone reviewed the spoofed senders list?Overrides accumulate.
Operating it
- What are your phishing thresholds set to?Adjustable, and usually never adjusted.
- Does anyone look at Campaign Views?It shows the pattern, not the message.
- How do users report a suspected phish?And where does it go.
- Is attack simulation training run?It is a program, not a setting.
- Who maintains the protected lists?They decay without an owner.
The pages around this one.
Defender for Office 365
The product these policies belong to, and the rest of what it does.
Phishing protection
The layered program these policies sit inside: technical filtering plus the human layer.
Email security audit
The wider assessment that reviews these policies alongside authentication records and mail flow.
Open your anti-phishing policy and look at the protected senders list.
If it is empty, or it lists people who no longer work there, you have the most common gap in Microsoft 365 email security and it takes an afternoon to close. If it is current and maintained, you are in a small minority.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Office 365 Services
Anti-phishing, Safe Links and Safe Attachments done right
Learn morePhishing Protection for US Businesses
Layered phishing protection for US businesses combining technical
Learn moreMicrosoft Attack Simulation Training Programs
Attack simulation training programs for US organizations using
Learn moreSecurity Awareness Training Programs
Security awareness training programs for US businesses: role-based
Learn moreEmail Security Audit
Email security audits for US organizations: sending domain inventory
Learn moreThreat Explorer Email Investigation
Email threat investigation capability for US organizations using
Learn more