We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Anti-phishing policies
Microsoft 365 anti-phishing policies

Impersonation protection only defends the people you name in it. Almost nobody names anybody, and then the wire transfer goes out.

Spoof intelligence, DMARC policy honoring, and implicit authentication come with every cloud mailbox regardless of what you pay. Defender for Office 365 adds three more: impersonation protection for senders and domains you name, mailbox intelligence, and phishing thresholds you can move. Every one of those three needs somebody to configure it, and across the tenants we review, none of them ever has been.

Book an anti-phishing policy reviewSee what each tier gives you
Microsoft 365 anti-phishing policy configuration for US organizations
  • Two tiersAll cloud mailboxes, then Defender for Office 365
  • Named sendersImpersonation protection must be configured
  • AdjustablePhishing email thresholds are a policy setting
  • Campaign ViewsCoordinated attacks analyzed across the service
What is available

Seven controls, and the ones that stop invoice fraud do nothing until somebody fills them in.

Microsoft is blunt about why this matters: attacks have grown complex enough that even a trained employee struggles to identify a sophisticated phishing message. The built-in features on every cloud mailbox, plus what Defender for Office 365 adds on top, are how you stop depending on somebody noticing.

Impersonation protection, for senders and domains you name

The policies configure impersonation protection for specific senders and specific sender domains. Specific is the word carrying all the weight. Nothing whatsoever protects your finance director from being impersonated until a human types their name and address into that policy, and in most tenants we open that list is either empty or describes the leadership team from three years ago.

Mailbox intelligence, which learns the sender relationships

Mailbox intelligence is configured in the same policy. Instead of matching against a fixed list, it learns who each person normally exchanges mail with. That is how a message from a vendor address that has never once written to this employee becomes suspicious, without anybody having to predict that particular vendor in advance.

Adjustable phishing email thresholds

The policy exposes adjustable phishing thresholds controlling how aggressive detection is. That is a genuine dial with a genuine trade-off attached, and it deserves a decision rather than whatever the tenant shipped with. A company currently under business email compromise pressure almost always wants it set higher than the level it inherited.

Spoof intelligence, available to every cloud mailbox

The spoof intelligence insight shows you which spoofed senders were detected across both external and internal domains, and lets you allow or block each one by hand. The policies available on every cloud mailbox control whether spoof intelligence runs at all, whether Outlook displays the unauthenticated sender indicator, and what actually happens to a message from a blocked spoofed sender.

Honoring the sender DMARC policy

One setting decides what happens when a sender fails explicit DMARC checks and their own published policy says quarantine or reject. That is the difference between respecting what a legitimate domain owner has asked the world to do with forgeries of their name and quietly ignoring it. Almost nobody has ever consciously made that choice.

Campaign Views, which show you the pattern instead of one message

Machine learning and other heuristics identify messages belonging to coordinated campaigns, both across the whole service and against your organization specifically. That turns an investigation from one reported email into a view of the entire campaign it belongs to, including everyone else who received it and how the sending pattern behaved.

Implicit email authentication, on top of the records

The standard authentication checks on inbound mail, SPF, DKIM and DMARC, are supplemented with sender reputation, sender history, recipient history, behavioral analysis, and further techniques aimed at identifying forgery. Your own records still matter enormously, but the platform is not depending on them alone.

The gap that produces the loss

Business email compromise runs on forged trusted senders, and the control that stops it is inert until somebody fills in a list.

The attack is defined precisely in the documentation, and the control that answers it happens to be the one demanding the most manual input.

  • The definition: business email compromise forges trusted senders, specifically naming financial officers, customers, and trusted partners, in order to get somebody to approve a payment, move funds, or hand over customer data. The FBI has ranked it among the costliest categories of cybercrime reported by American businesses for several years running.
  • The matching control is impersonation protection, configured inside a Defender for Office 365 anti-phishing policy against specific senders and specific sender domains. It defends the people and domains on your list, and nobody else.
  • The list needs your executives on it, your finance and accounts payable staff, your board members, and the domains of the customers and vendors who actually appear in payment conversations. It also needs somebody maintaining it, because people join, leave, and change jobs, and a list assembled during a deployment project two years ago now protects a leadership team that has moved on.
  • The impersonation insight then shows what was actually detected, which serves as both an operational tool and proof the configuration is doing something. An empty insight at a company that approves payments over email almost never means nobody is trying. It means the policy is empty.
Ask us to review your impersonation list
How we approach it

Four findings that turn up in almost every tenant we review.

The engagement is short and the return is disproportionate, because the controls are already paid for and the same gaps appear at companies of wildly different sizes.

The protected list is empty, or it defends people who left last year

Protection extends to exactly the senders and sender domains you configure and no further. In most tenants that list is empty, or was filled in once during a deployment project and never touched since. Rebuilding it around the leadership team you have now, the finance function, and the customer and vendor domains that genuinely appear in payment conversations takes a single afternoon.

The phishing thresholds were never a decision

They can be adjusted, which means somebody was supposed to choose. In practice companies run whatever value the tenant was created with years ago. Setting them deliberately, against the pressure the business is actually under and with the false positive trade understood, is a change with a measurable effect and no licensing cost attached.

The DMARC honoring setting has never been looked at

This setting decides what happens when a sender fails explicit DMARC checks and their own published policy says quarantine or reject. Choosing to honor it means respecting what legitimate domain owners have publicly asked the world to do with forgeries of their name. It sits beside your own DMARC record work rather than replacing it, and the two are worth doing in the same project.

Campaign Views is available and nobody has opened it

Machine learning and heuristics identify messages belonging to coordinated campaigns aimed at the service generally and at you specifically. When somebody reports a suspicious email, this view answers in seconds who else received it and what the campaign actually looks like. It is among the highest value features in the product and among the least opened.

Where this matters most

Six US situations where anti-phishing configuration is the difference.

Four attack categories are named in the documentation: spear phishing, whaling, business email compromise, and the phishing that opens a ransomware incident. Each maps onto a different part of the configuration.

A firm that authorizes payments by email

Business email compromise forges a trusted sender, with financial officers, customers, and trusted partners named specifically, in order to get somebody to approve a payment, move funds, or release customer data. Impersonation protection covering those senders and their domains is the direct control, and it does absolutely nothing until the list has names in it.

A business whose executives are publicly identifiable

Whaling aims at executives and other high value targets for maximum effect, and American leadership teams are listed on the company website, quoted in trade publications, and fully visible on LinkedIn. Reconnaissance costs an attacker about twenty minutes, which is precisely the precondition the documentation describes for spear phishing.

A company that trades with a defined set of significant partners

Domain impersonation protection covers whichever sender domains you name. Where the bulk of your payment instructions arrive from a known set of customers and vendors, naming those domains explicitly closes the most likely route. It is a short list that rarely changes, which is exactly what makes it maintainable.

An operator whose ransomware exposure starts in the inbox

Ransomware almost always begins with a phishing message. Anti-phishing protection cannot decrypt a single file after the event, but it can catch the message that started the campaign. That reframes this configuration as ransomware prevention rather than as an email quality problem, and it happens to be exactly how your cyber carrier sees it at renewal.

An organization running phishing simulations without configuring the controls

Attack simulation training lets an administrator build fake phishing messages and send them to staff as a teaching exercise. It is genuinely valuable and it is not a substitute for configuration. Measuring whether people click while impersonation protection sits empty tests the human layer thoroughly and leaves the technical one completely untouched.

An organization investigating a reported message

During an investigation, three questions matter: how many people got this, is it part of something coordinated, and what else arrived from the same source. Campaign Views answers all three. Put beside the impersonation insight showing what was detected, it turns one reported message into an actual understanding of what is happening to you.

Three positions

How US organizations configure anti-phishing today.

The middle column covers the overwhelming majority. The licensing is paid for, the defaults are quietly running, and every setting that addresses a targeted attack sits empty.
Spoof intelligence active
Configured and maintainedYes
Licensed, left at defaultsYes
Basic mailbox protection onlyYes
Sender DMARC policy honored
Configured and maintainedYes
Licensed, left at defaultsUnverified
Basic mailbox protection onlyUnverified
Executives protected from impersonation
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Vendor domains protected
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Mailbox intelligence configured
Configured and maintainedYes
Licensed, left at defaultsPartly
Basic mailbox protection onlyNot available
Thresholds set deliberately
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Impersonation insight reviewed
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Campaign Views used in investigations
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Protected lists maintained as people change
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot applicable
Position against targeted invoice fraud
Configured and maintainedDefended
Licensed, left at defaultsExposed
Basic mailbox protection onlyExposed
Feature
Configured and maintained
Licensed, left at defaults
Basic mailbox protection only
Spoof intelligence active
YesYesYes
Sender DMARC policy honored
YesUnverifiedUnverified
Executives protected from impersonation
YesNoNot available
Vendor domains protected
YesNoNot available
Mailbox intelligence configured
YesPartlyNot available
Thresholds set deliberately
YesNoNot available
Impersonation insight reviewed
YesNoNot available
Campaign Views used in investigations
YesNoNot available
Protected lists maintained as people change
YesNoNot applicable
Position against targeted invoice fraud
DefendedExposedExposed
The two tiers

What comes with any mailbox, against what the paid tier adds.

The capabilities are as documented. The right hand column, saying whether a control works on its own or waits for you to supply information, is our assessment rather than theirs.

Capability

Spoof intelligence and the spoof intelligence insight

Tier
All cloud mailboxes
Does it work without configuration
Detection happens on its own, though overriding a verdict is manual review work

Capability

Anti-phishing policies for all cloud mailboxes

Tier
All cloud mailboxes
Does it work without configuration
Defaults exist, but the spoof action and the Outlook indicator are both decisions

Capability

Honor the sender DMARC policy on spoof detection

Tier
All cloud mailboxes
Does it work without configuration
A configuration decision about quarantine and reject policies

Capability

Spoofed senders in the Tenant Allow/Block List

Tier
All cloud mailboxes
Does it work without configuration
Entries arrive when you override a verdict, and can also be created by hand in advance

Capability

Implicit email authentication

Tier
All cloud mailboxes
Does it work without configuration
Yes, it augments SPF, DKIM and DMARC automatically

Capability

Impersonation protection for named senders

Tier
Defender for Office 365
Does it work without configuration
No. It protects only the senders you enter

Capability

Impersonation protection for named sender domains

Tier
Defender for Office 365
Does it work without configuration
No. It protects only the domains you enter

Capability

Mailbox intelligence

Tier
Defender for Office 365
Does it work without configuration
Learns relationships, but the policy settings still need configuring

Capability

Adjustable phishing email thresholds

Tier
Defender for Office 365
Does it work without configuration
A dial with a default value, and that default is a choice somebody else made for you

Capability

Impersonation insight

Tier
Defender for Office 365
Does it work without configuration
Reports what impersonation protection caught, which means it mirrors your own configuration

Capability

Campaign Views

Tier
Defender for Office 365
Does it work without configuration
Yes, but only useful if somebody looks at it

Capability

Attack simulation training

Tier
Defender for Office 365
Does it work without configuration
No. It is a program you run, not a setting
CapabilityTierDoes it work without configuration
Spoof intelligence and the spoof intelligence insightAll cloud mailboxesDetection happens on its own, though overriding a verdict is manual review work
Anti-phishing policies for all cloud mailboxesAll cloud mailboxesDefaults exist, but the spoof action and the Outlook indicator are both decisions
Honor the sender DMARC policy on spoof detectionAll cloud mailboxesA configuration decision about quarantine and reject policies
Spoofed senders in the Tenant Allow/Block ListAll cloud mailboxesEntries arrive when you override a verdict, and can also be created by hand in advance
Implicit email authenticationAll cloud mailboxesYes, it augments SPF, DKIM and DMARC automatically
Impersonation protection for named sendersDefender for Office 365No. It protects only the senders you enter
Impersonation protection for named sender domainsDefender for Office 365No. It protects only the domains you enter
Mailbox intelligenceDefender for Office 365Learns relationships, but the policy settings still need configuring
Adjustable phishing email thresholdsDefender for Office 365A dial with a default value, and that default is a choice somebody else made for you
Impersonation insightDefender for Office 365Reports what impersonation protection caught, which means it mirrors your own configuration
Campaign ViewsDefender for Office 365Yes, but only useful if somebody looks at it
Attack simulation trainingDefender for Office 365No. It is a program you run, not a setting
How a review runs

Five steps, with most of the value arriving in the first two.

Two to four weeks in most cases, run remotely. The controls are already licensed in the majority of tenants, so what you end up buying is configuration and a named maintenance owner rather than a product.
  1. 1

    Inventory the current policies and what they actually contain

    Which policies actually exist, who each one applies to, how spoof intelligence and the Outlook unauthenticated sender indicator are set, what happens to a blocked spoofed sender, and whether anybody has ever given a moment thought to the DMARC honoring setting.

  2. 2

    Rebuild the impersonation lists around the current business

    Protected senders covering the leadership team as it stands today, everyone in finance and accounts payable, and anybody whose name appears on a payment instruction. Protected domains covering the customers and vendors who genuinely matter. Then an owner by name, because this list decays quietly every time somebody joins, leaves, or changes role.

  3. 3

    Set thresholds and mailbox intelligence deliberately

    Phishing thresholds chosen deliberately against the pressure your business is genuinely under, rather than inherited from whenever the tenant was created, with the false positive trade understood in advance and a working route for somebody to report a message that got caught wrongly.

  4. 4

    Review the spoofed senders list and the insight

    Every override in the spoof intelligence insight becomes a manual allow or block entry on the spoofed senders tab of the Tenant Allow and Block List. Those accumulate across years and are almost never revisited, which means a permitted spoof from a vendor relationship that ended three years ago may well still be sitting there quietly working.

  5. 5

    Establish the operating rhythm

    Somebody has to review the impersonation insight, somebody has to open Campaign Views when a message is reported, the reporting route needs maintaining, and the protected lists need an owner. Attack simulation training can sit on top as the human layer, running alongside the configuration rather than in place of it.

Straight answers

What organizations ask about anti-phishing policies.

Every organization with cloud mailboxes already has the following: spoof intelligence, with an insight page for reviewing detections and allowing or blocking each sender by hand; anti-phishing policies covering all cloud mailboxes; the option to honor a sender published DMARC policy when a message is detected as spoofed; allow and block entries for spoofed senders in the Tenant Allow and Block List; and implicit email authentication.

Policies carrying impersonation protection for named senders and named sender domains, mailbox intelligence settings, and phishing thresholds you can move. On top of that, the impersonation insight showing what was detected, Campaign Views for anything coordinated, and attack simulation training for building fake phishing messages as a teaching exercise.

No, and this is the single most important sentence on this page. It is configured against specific senders and specific sender domains, which means it defends the people and domains you typed in and nothing else whatsoever. A policy with an empty protected senders list delivers no impersonation protection at all, and that is the most common finding across every review we run.

Whoever an attacker would pretend to be in order to move money or extract data. In practice that is the chief executive, the finance chief and their team, anybody who approves a payment or can change vendor banking details, and usually the controller and several board members. Business email compromise is documented as forging trusted senders including financial officers, and that is the population to start from.

Protection extends to sender domains as well as individual senders. Where payment instructions and contract discussions arrive from a defined set of counterparties, adding those domains closes off the attack that uses a lookalike domain rather than a lookalike display name. The list is short, it rarely changes, and it repays maintaining.

A policy setting configured beside impersonation protection and the phishing thresholds. Rather than checking a fixed list, it considers the correspondence patterns each recipient normally has, which is how a message from an address that has never once written to this person gets treated differently from one that writes weekly.

They can be adjusted, which means the current value is a setting rather than a law of nature, and in most tenants nobody ever chose it. Whether to raise it turns on the pressure your business is under and how much false positive pain people will tolerate, which makes it a business conversation at least as much as a technical one. What we would never do is leave it inherited with nobody having looked.

It governs what happens to a message whose sender fails explicit DMARC checks while their own published policy says quarantine or reject. Honoring that means treating a forgery exactly the way the legitimate domain owner publicly asked everyone to treat it. It sits beside publishing your own DMARC record and does not replace that work.

Spoof intelligence handles messages forging a sending domain, your own very much included, and it is available on every cloud mailbox. Impersonation protection, which requires Defender for Office 365, handles messages imitating a specific person or domain you have named, usually through a lookalike address or display name rather than an outright forgery. Both matter, and they catch entirely different attacks.

Overriding a verdict in the spoof intelligence insight turns that spoofed sender into a manual allow or block entry, which appears only on the spoofed senders tab of the Tenant Allow and Block List. Entries can also be created by hand before spoof intelligence has ever seen the sender, which is useful when you already know a legitimate sender is going to be flagged.

Machine learning and heuristics identify messages that belong to coordinated campaigns, both across the service generally and against you specifically. In practice it answers the three questions that follow every user report: who else received this, is it part of something bigger, and what does the sending pattern look like. It is sitting there licensed and it is almost never opened.

No, and treating it as one is a mistake we run into regularly. It lets an administrator build fake phishing messages and send them to staff as a teaching exercise, which genuinely measures and improves the human layer. But running simulations while impersonation protection sits unconfigured tests your people against attacks your technology was never told to stop in the first place.

It can, which is why the review includes a reporting route for messages that were wrongly caught and why threshold changes are made deliberately rather than maximally. The two changes least likely to cause disruption, and among the highest value, are populating the impersonation lists and reviewing the accumulated spoofed sender overrides.

Directly. Cyber insurance applications and SOC 2 or vendor security questionnaires routinely ask how email impersonation and phishing are controlled, and a configured anti-phishing policy with maintained impersonation lists is a concrete answer rather than a narrative one. For HIPAA-covered organizations and firms under the FTC Safeguards Rule, phishing controls are part of the reasonable safeguards story your assessors expect to see in writing.

The protected sender list needs maintaining whenever the leadership or finance team changes, which in most organizations means at least annually and realistically at each significant appointment. The spoofed senders override list is worth an annual review because entries accumulate and outlive the relationships that justified them. Thresholds are worth revisiting after any incident.

It is scoped per engagement, typically two to four weeks, and we usually fold it into a wider email security assessment alongside your Safe Links configuration and your email authentication records. The controls are already licensed in most tenants, so the output is configuration and an owner rather than a purchase.
The policy review

Fifteen checks worth running on an existing tenant.

This is one of the very few security controls where a review turns up the same three gaps in nearly every company we look at. These are the checks that surface them.

Impersonation

  • Who is on the protected senders list?
    Frequently empty, frequently stale.
  • Is the current leadership team on it?
    People change roles.
  • Are finance and accounts payable staff protected?
    They are the actual target.
  • Which sender domains are protected?
    Key customers and vendors.
  • Does the impersonation insight show activity?
    Empty usually means unconfigured.

Spoof and authentication

  • Is spoof intelligence on?
    It is a policy setting.
  • Do you honor sender DMARC policies?
    For quarantine and reject.
  • Are unauthenticated sender indicators shown?
    The Outlook visual cue.
  • What is the action for blocked spoofed senders?
    Specified in the policy.
  • Has anyone reviewed the spoofed senders list?
    Overrides accumulate.

Operating it

  • What are your phishing thresholds set to?
    Adjustable, and usually never adjusted.
  • Does anyone look at Campaign Views?
    It shows the pattern, not the message.
  • How do users report a suspected phish?
    And where does it go.
  • Is attack simulation training run?
    It is a program, not a setting.
  • Who maintains the protected lists?
    They decay without an owner.
Related reading

The pages around this one.

Defender for Office 365

The product these policies belong to, and the rest of what it does.

Learn more

Phishing protection

The layered program these policies sit inside: technical filtering plus the human layer.

Learn more

Email security audit

The wider assessment that reviews these policies alongside authentication records and mail flow.

Learn more
Next step

Open your anti-phishing policy and look at the protected senders list.

If it is empty, or it lists people who no longer work there, you have the most common gap in Microsoft 365 email security and it takes an afternoon to close. If it is current and maintained, you are in a small minority.

Book an anti-phishing policy reviewSee Defender for Office 365

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Office 365 Services

Anti-phishing, Safe Links and Safe Attachments done right

Learn more

Phishing Protection for US Businesses

Layered phishing protection for US businesses combining technical

Learn more

Microsoft Attack Simulation Training Programs

Attack simulation training programs for US organizations using

Learn more

Security Awareness Training Programs

Security awareness training programs for US businesses: role-based

Learn more

Email Security Audit

Email security audits for US organizations: sending domain inventory

Learn more

Threat Explorer Email Investigation

Email threat investigation capability for US organizations using

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA