We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender for Office 365
Microsoft Defender for Office 365

Go and open the Defender portal. Explorer means Plan 2. Real-time detections means Plan 1.

That is the published shortcut for telling the two apart, and it takes about ten seconds. Which one you hold determines whether you can genuinely investigate a business email compromise or only observe that one occurred. Most American companies have never once checked.

Book an email security reviewSee what each tier stops
Microsoft Defender for Office 365 plan comparison for US organizations
  • Three tiersBuilt-in, Plan 1, Plan 2
  • E3 and Business PremiumBoth land on Plan 1
  • Explorer or notThe ten-second check
  • BEC is the riskNot volume spam
What each tier actually stops

Eight things to understand about the email protection ladder.

It is described as a ladder with three rungs rather than a product with two tiers, and that distinction is worth holding onto. Anybody with cloud mailboxes already stands on the bottom rung. What the higher ones add is not better spam filtering but protection against attacks aimed specifically at you, and the ability to work out afterward what actually happened.

The ten second check that settles which plan you hold

The documentation states this twice, in two different places. Look at the email and collaboration section of the Defender portal. Real-time detections means Plan 1. Explorer means Plan 2. That is the fastest way to tell, it needs no conversation with a supplier, no digging through the admin center and no licensing expertise. Do it before reading a single further word about which plan to buy.

What everybody already has, and what it is for

Any subscription with cloud mailboxes already includes anti-malware, anti-spam with bulk handling, anti-phishing spoofing protection alongside the spoof intelligence view, outbound spam protection, connection filtering, quarantine with policies attached, the tenant allow and block list, message trace and automatic purging of anything found bad after delivery. This tier is described as preventing broad, high-volume, already-known attacks, and it is genuinely excellent at exactly that. Volume spam is not what costs American businesses money.

What Plan 1 adds: the targeted attack layer

Plan 1 is described as covering previously unseen malware, phishing and business email compromise. In concrete terms it adds impersonation protection for both people and domains, mailbox intelligence drawing on who actually corresponds with whom, adjustable phishing thresholds, attachment detonation in email and across SharePoint, OneDrive and Teams, and link protection in email, the Office applications and Teams. Impersonation protection is the piece that matters most, because impersonation is precisely how wire fraud arrives.

What Plan 2 adds: investigation, hunting and automation

Plan 2 is summarized as adding phishing simulations, investigation after the fact, hunting, response and automation. Specifically that means simulation training, protection aimed at your most important accounts, Explorer replacing real-time detections, threat trackers, campaign views, advanced hunting reaching Teams messages, and automated investigation and response including the version covering compromised accounts. The automation is the practical difference for any team without a dedicated security operations function.

Which subscriptions carry which plan

E3, the government equivalent and Business Premium are given as examples carrying Plan 1, with the academic and enterprise top tiers carrying Plan 2. Worth noting the contrast with endpoint protection, where Business Premium is genuinely ahead of E3. On email the two land on identical rungs, so an American business on either holds exactly the same protection and faces exactly the same decision.

Priority accounts, which most organizations never configure

Tagging people, including marking them as priority accounts, works at Plan 1. The protection that acts on that tag is a Plan 2 capability. The people worth treating differently are the finance team, the executives, and anybody with the authority to change payment details, and in most tenants we open, nobody has ever marked a single one of them. Tagging costs nothing and improves both the alerting and any investigation that follows.

Safe Documents is not in either plan

A genuine trap, this one. Safe Documents comes with the academic top tier or with the Defender Suite licensing, and is explicitly not part of either email plan. So a company on Plan 2 does not automatically have it, which surprises people who quite reasonably assumed the top email plan would include every feature adjacent to email.

None of it replaces email authentication

The three authentication records in your DNS are what let the platform judge spoofing accurately. Those records exist to stop your own domain being impersonated to other people, which no amount of inbound filtering at any tier addresses. The two are complementary and both are necessary, and companies buy the higher plan while leaving their own domain wide open to being spoofed with striking regularity.

What actually costs US businesses money

The attack that empties a bank account bears no resemblance to spam.

Every rung of this ladder deals with bulk spam competently, and bulk spam is not the risk. The risk is a single convincing message about a payment, and where you sit on the ladder decides whether you can see it approaching and reconstruct it afterward. Business email compromise has ranked among the costliest categories in the FBI annual internet crime reporting for years running, and the pattern below explains why.

  • It usually arrives as one well-written message impersonating somebody the recipient already trusts, asking for a payment or for bank details to be updated. Very often there is no attachment, no link and no malware anywhere in it, which leaves the volume-based filtering in the built-in tier with almost nothing to work from. Impersonation protection, starting at Plan 1, is the layer built specifically for this.
  • The more dangerous version involves no impersonation whatsoever. It is a real message from a genuinely compromised mailbox, and very often that mailbox belongs to a supplier rather than to anybody at your company. No filtering tier can flag it as spoofed, because nothing about it is spoofed. What actually helps is a payment process where any change of bank details gets verified by phone to a number you already had on file. That costs nothing and is worth more than any upgrade on this page.
  • Where Plan 2 earns its keep is in the aftermath. When somebody asks what happened, who else received the message and whether anybody clicked anything, it is Explorer, the campaign view and automated investigation that answer. On Plan 1 you have real-time detections and the email entity page, which is genuine capability and a considerably narrower window when you are reconstructing an incident under pressure.
  • And quite separately from any of this, publish and enforce all three authentication records. Those are what let the platform judge spoofing accurately in the first place. They also stop your own domain being turned against your customers, which no inbound plan at any tier does anything about.
Ask us to check which tier you hold and how your impersonation policies are set
How we approach it

Four things that matter considerably more than which plan you end up buying.

Email is where the distance between capability you are licensed for and capability anybody configured is at its very widest, and where the most expensive attacks are precisely the ones no filter was ever going to catch.

Which tier you hold gets established before anybody mentions an upgrade

That ten second check in the portal settles the question outright. In a meaningful number of cases the company already holds Plan 1 and has configured none of it, which makes the work configuration rather than purchasing. Recommending Plan 2 to somebody running Plan 1 on default settings would be selling more capacity to a business not using what it already owns.

We configure impersonation protection around real people

Impersonation protection acts on specific named people and specific named domains, so somebody has to sit down and decide who and what gets protected. That means the finance team, the executives, anybody able to change payment details, along with your own domains and the vendors who matter. A short exercise, included from Plan 1 onward, and left undone in the large majority of tenants we assess.

Some attacks are not a filtering problem at all, and we say so

A real message from a genuinely compromised supplier mailbox is not spoofed in any way, so no tier will flag it. What actually prevents the loss is a payment process where any change to bank details gets verified by phone to a number you already held. We say that plainly, even when it means recommending a change of process instead of a product, because the alternative is selling somebody a license against a risk it does not touch.

We do the outbound half as well

All three authentication records are what let the platform judge spoofing accurately, and they also stop your domain being used as a weapon against your own customers. No inbound plan does anything whatsoever about that second problem. We treat both as a single piece of work, because a company that bought Plan 2 and left its domain spoofable has protected one direction thoroughly and the other not at all.

Where this matters

Six US situations that justify looking at this properly.

Wire fraud runs through all of these. It is the attack that most dependably costs American businesses actual money, and email is where it arrives.

Any business that pays or receives invoices

Which describes every company, and it is why this page exists at all. The impersonation protection arriving at Plan 1 is aimed precisely at the message claiming to come from your chief executive or from a supplier. Configuring it around the specific individuals who authorize payments is short work with an unusually direct relationship to the loss it prevents.

A business on Business Premium or E3

Both carry Plan 1, so impersonation protection, link protection and attachment detonation are all present whether anybody configured them or not. Worth noting this differs from endpoint protection, where Business Premium genuinely is ahead of E3. On email the two are level, and for either the useful question is simply whether any of it has been switched on.

An organization that has just had a near miss

A payment came within an hour of going to the wrong account, or somebody received a thoroughly convincing message from a supplier that turned out to be fraudulent. This is exactly the right moment to look at all of this, because the company has just lived through the specific risk and nobody needs persuading about the budget. The work is nearly always configuration plus a change to the payment process rather than anything requiring a purchase.

A firm with significant vendor payment flows

Construction, distribution, logistics, title and escrow, and anybody else moving money on the strength of an emailed instruction. The exposure sits with your suppliers rather than your own mailboxes, because a compromise at their end produces a genuine message from a genuine address. Domain impersonation protection extended to supplier domains handles the lookalikes. Verifying by phone handles everything it cannot.

A business that needs to investigate an incident properly

When somebody asks who else got the message, whether anybody clicked, and what the sender did next, the answer you can give depends entirely on your tier. Explorer, the campaign view and automated investigation all sit at Plan 2. If a state breach notification analysis, an insurance claim or a large customer requires you to reconstruct an email incident in detail, that is the clearest argument there is for the higher plan.

An organization running user awareness training

Simulation training sits at Plan 2, and running phishing simulations from inside the same platform that filters the mail carries real practical advantages over a separate product. If you already pay for a standalone simulation tool and either hold Plan 2 or are considering it, it is worth checking whether you are about to buy the same capability for the second time.

Three positions

What we find when we review email security in US tenants.

The middle column is where most companies sit. The license already includes impersonation protection, link protection and attachment detonation, none of which anybody has configured, which means the business is effectively running the built-in tier while paying for considerably more than that.
Knows which plan it holds
Tier known and configuredYes
Licensed, default settingsAssumes
Built-in onlyCorrect by default
Safe Links and Safe Attachments enabled
Tier known and configuredYes
Licensed, default settingsPartly
Built-in onlyNot available
Impersonation protection configured for named people
Tier known and configuredYes
Licensed, default settingsNo
Built-in onlyNot available
Priority accounts tagged
Tier known and configuredYes
Licensed, default settingsNo
Built-in onlyNot available
Safe Attachments covers SharePoint and Teams
Tier known and configuredYes
Licensed, default settingsRarely
Built-in onlyNot available
External sender warning in place
Tier known and configuredYes
Licensed, default settingsSometimes
Built-in onlySometimes
SPF, DKIM and DMARC enforced
Tier known and configuredYes
Licensed, default settingsp=none or absent
Built-in onlyUsually absent
Could reconstruct who else got the message
Tier known and configuredYes
Licensed, default settingsPartly
Built-in onlyBarely
Payment changes verified out of band
Tier known and configuredYes
Licensed, default settingsSometimes
Built-in onlyRarely
Answers a cyber insurance email question honestly
Tier known and configuredYes
Licensed, default settingsUnclear
Built-in onlyNo
Feature
Tier known and configured
Licensed, default settings
Built-in only
Knows which plan it holds
YesAssumesCorrect by default
Safe Links and Safe Attachments enabled
YesPartlyNot available
Impersonation protection configured for named people
YesNoNot available
Priority accounts tagged
YesNoNot available
Safe Attachments covers SharePoint and Teams
YesRarelyNot available
External sender warning in place
YesSometimesSometimes
SPF, DKIM and DMARC enforced
Yesp=none or absentUsually absent
Could reconstruct who else got the message
YesPartlyBarely
Payment changes verified out of band
YesSometimesRarely
Answers a cyber insurance email question honestly
YesUnclearNo
The three rungs

The built-in tier, Plan 1 and Plan 2, set alongside one another.

Taken from the published comparison. That first column applies to every subscription with cloud mailboxes, which means it describes what you already hold even if nobody has ever bought anything.

Capability

Anti-malware, anti-spam, anti-spoofing

Built-in
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Quarantine, Tenant Allow/Block List, message trace

Built-in
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Zero-hour auto purge for email

Built-in
Yes
Plan 1
Yes
Plan 2
Yes

Capability

User and domain impersonation protection

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Mailbox intelligence impersonation, contact graph

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Safe Attachments, email and SharePoint, OneDrive, Teams

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Safe Links in email, Office clients and Teams

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Real-time detections

Built-in
No
Plan 1
Yes
Plan 2
Replaced by Explorer

Capability

Email entity page and user tags

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Zero-hour auto purge for Teams

Built-in
No
Plan 1
Yes
Plan 2
Yes

Capability

Threat Explorer

Built-in
No
Plan 1
No
Plan 2
Yes

Capability

Threat Trackers and Campaigns

Built-in
No
Plan 1
No
Plan 2
Yes

Capability

Attack simulation training

Built-in
No
Plan 1
No
Plan 2
Yes

Capability

Automated Investigation and Response

Built-in
No
Plan 1
No
Plan 2
Yes

Capability

Safe Documents

Built-in
No
Plan 1
No
Plan 2
No, needs A5 or Defender Suite
CapabilityBuilt-inPlan 1Plan 2
Anti-malware, anti-spam, anti-spoofingYesYesYes
Quarantine, Tenant Allow/Block List, message traceYesYesYes
Zero-hour auto purge for emailYesYesYes
User and domain impersonation protectionNoYesYes
Mailbox intelligence impersonation, contact graphNoYesYes
Safe Attachments, email and SharePoint, OneDrive, TeamsNoYesYes
Safe Links in email, Office clients and TeamsNoYesYes
Real-time detectionsNoYesReplaced by Explorer
Email entity page and user tagsNoYesYes
Zero-hour auto purge for TeamsNoYesYes
Threat ExplorerNoNoYes
Threat Trackers and CampaignsNoNoYes
Attack simulation trainingNoNoYes
Automated Investigation and ResponseNoNoYes
Safe DocumentsNoNoNo, needs A5 or Defender Suite
How an engagement runs

Five steps, starting with a ten-second check.

One to two weeks as a rule. Most of the value comes from configuring capability you already own, so the licensing question gets settled first and frequently turns out not to be the problem at all.
  1. 1

    Establish the tier and what is configured

    That ten second check in the portal first, then a proper review of what has genuinely been enabled: link protection, attachment detonation including the coverage reaching SharePoint, OneDrive and Teams, the anti-phishing policies, and whether the preset policies are in use or custom ones nobody has opened since they were written.

  2. 2

    Configure impersonation protection around named people and domains

    The executives and the finance team, anybody with authority to change payment details, your own domains, and whichever supplier domains genuinely matter. This calls for a decision from the business about who gets protected rather than a technical judgment from IT, and it is the most precisely targeted control available against the attack that actually costs money.

  3. 3

    Tag priority accounts and set the surrounding controls

    Priority accounts tagged, warnings on external senders, and a reporting route so that somebody suspicious of a message has somewhere to send it. Then that route gets tested from one end to the other, because a report button leading nowhere teaches people very quickly to stop pressing it.

  4. 4

    Fix the outbound half

    All three authentication records across your domains, which improves the platform own spoofing judgment and separately stops your domain being used against your customers. Where that turns out to be a larger job it gets scoped on its own, because moving to enforcement safely needs discovery work in its own right.

  5. 5

    Make the Plan 2 decision with actual evidence in front of you

    Only once everything above is done, and with one clear question in front of you: do you need investigation after the fact, hunting and automation, and would anybody here genuinely use them. A ninety day Plan 2 trial is available through the portal, so this can be settled by running it rather than by arguing about it in a meeting.

Straight answers

What organizations ask about Defender for Office 365.

Open the Defender portal and look at the email and collaboration section. Explorer means Plan 2. Real-time detections means Plan 1. That is published as the quick way to tell the two apart, and stated in both directions in the documentation. Ten seconds, no licensing expertise required, and well worth doing before any conversation about upgrading, because a genuinely surprising number of companies find out they already hold more than they thought they did.

Considerably more than most people expect. Any subscription with cloud mailboxes already carries anti-malware, anti-spam with bulk handling, spoofing protection alongside the spoof intelligence view, outbound spam protection, connection filtering, quarantine with its policies, the tenant allow and block list, message trace, the security reports and automatic purging of anything found bad after delivery. That tier is meant to prevent broad, high-volume, already-known attacks, and it does exactly that. What it does not do at any point is impersonation protection.

E3, the government equivalent and Business Premium are the examples given for Plan 1, with the academic and enterprise top tiers carrying Plan 2. Both are also purchasable as add-ons to most subscriptions with cloud mailboxes. Worth noticing that this behaves differently from endpoint protection, where Business Premium sits ahead of E3 while on email the two are level. Never assume the pattern from one product carries across to another.

It turns entirely on whether anybody would ever use the investigation capability. Plan 2 brings simulation training, Explorer, threat trackers, campaign views and automated investigation and response. For a company with somebody who would genuinely investigate an email incident, that is substantial. For a twenty person firm with nobody doing security, configuring Plan 1 properly and fixing how payments get verified will prevent considerably more loss than Plan 2 would. There is a ninety day trial, so this can be answered by running it rather than debating it.

Partly, and precision matters here. The impersonation protection at Plan 1 targets a message pretending to come from your chief executive or a supplier, and against that it is genuinely effective. What no tier anywhere stops is a real message from a real supplier mailbox that somebody has compromised, because nothing about it is spoofed. What prevents the loss in that case is a payment process where a change of bank details is verified by phone to a number you already held. That costs nothing and outperforms every license tier on this page against this specific risk.

It defends specific named people and specific domains against being impersonated, using both exact matching and mailbox intelligence built from who each person normally corresponds with. The reason it so often does nothing is that it has to be given names. Somebody has to list the executives, the finance team and the domains worth defending. Straight out of the box that list is empty, so the capability sits there fully licensed and entirely idle, which is the most common finding we produce on this subject by a wide margin.

No, and it catches people out regularly. Safe Documents comes with the academic top tier or with the Defender Suite licensing, and is explicitly outside both email plans. Assuming the top email plan includes every feature adjacent to email is entirely reasonable, and in this instance the assumption is simply wrong. Check the specific capability rather than inferring it from the tier you hold.

It can, and it is a separate setting from the email one that gets left switched off with great regularity. Attachment detonation covering SharePoint, OneDrive and Teams is included from Plan 1 onward. Given how much file sharing has migrated out of email and into Teams and SharePoint, a company that enabled it for email alone has protected the channel people barely use and left the one they use constantly wide open.

Yes, and they address different directions. Defender for Office 365 protects mail arriving at your organization. SPF, DKIM and DMARC concern whether somebody can send mail that appears to come from your domain, to your customers and partners. Microsoft states directly that those DNS records let Microsoft 365 protect more accurately against spoofing, so they help inbound too, but the main benefit is outbound and no plan tier substitutes for it.

For most US organizations the Standard or Strict preset security policies are a better starting point than custom policies, because they are maintained by Microsoft and updated as the threat picture changes, whereas a custom policy set is frozen at whoever configured it last. Custom policies make sense where you have a specific requirement the presets do not meet. What we find most often is custom policies created years ago by somebody who has left, which nobody has reviewed and nobody fully understands.

A tagging capability that marks the users most worth protecting differently, typically executives, finance staff and anybody who can authorize or change payments. User tags including the Priority account tag are available from Plan 1, and priority account protection as a capability is Plan 2. Tagging costs nothing, improves alert quality and makes investigation faster, and in most tenants we assess nobody has ever done it.

It might, and the honest answer requires looking at what the gateway is doing that Defender does not. Where organizations run both, we frequently find the gateway was bought before Defender matured and is now duplicating capability at additional cost and additional complexity, since mail passes through two filtering layers with two sets of policies and two quarantines. It is a genuine review worth doing, and the answer is sometimes to keep the gateway, particularly where it covers non-Microsoft mail flows.

For a typical US organization, one to two weeks including the impersonation protection decisions, which need business input rather than technical work. The technical configuration is quick; the part that takes elapsed time is agreeing who counts as a priority account and which vendor domains to protect. Commercially we scope per engagement, driven by tenant size and whether the outbound authentication work is included. What we will tell you free in the first conversation is how to run the ten-second check yourself and what impersonation protection settings to look at, and for a meaningful number of organizations those two things reveal that the capability is already licensed and unconfigured.
Check your own tenant

Fifteen checks, and the first one takes ten seconds.

The first block establishes what you actually hold and whether anybody configured it. The second covers the impersonation and payment fraud layer specifically. The third asks what you would genuinely be able to do the morning after an incident.

What you have

  • In the portal, does it say Explorer or does it say real-time detections?
    Explorer is Plan 2. Real-time detections is Plan 1. That is the whole test.
  • Are Safe Links and Safe Attachments actually turned on?
    Included at Plan 1 and frequently never configured.
  • Does Safe Attachments cover SharePoint, OneDrive and Teams?
    A separate setting from email, and often missed.
  • Are the preset security policies in use, or custom ones nobody has read in years?
    Standard and Strict presets are a reasonable default.
  • Has anybody ever run a Plan 2 trial to find out what it actually adds?
    Microsoft provides a 90-day trial through the Defender portal.

The payment fraud layer

  • Is user impersonation protection configured for your executives?
    It protects specific named people, which means somebody has to sit down and name them.
  • Is domain impersonation protection configured for your own domains?
    And for key vendor and customer domains.
  • Are priority accounts tagged?
    Finance, executives, anyone who can change payment details.
  • Do external emails carry a visible warning?
    Cheap, and effective against display-name tricks.
  • Does a bank detail change require phone verification?
    The control no license tier can replace.

Could you investigate afterwards

  • Could you list everybody else who received a particular message?
    Explorer at Plan 2, more limited at Plan 1.
  • Would you know whether a link was clicked?
    Tracing a link and the email entity page both begin at Plan 1.
  • How far back does your audit retention reach?
    A separate question from your Defender plan.
  • Are SPF, DKIM and DMARC published and enforced?
    Microsoft states these improve its own spoofing protection.
  • Has anybody ever reported a phishing message and followed what happened to it?
    User submission, triage, and what happens next.
Related reading

The pages around this one.

Microsoft Outlook and Exchange

The mail platform underneath: mailbox management, mail flow, and the DNS records that decide whether your domain can be spoofed.

Learn more

Defender for Endpoint

The device half of the same Defender family, where the licensing pattern is genuinely different and Business Premium comes out ahead of E3.

Learn more

Cybersecurity audit and compliance

A full tenant review including mail flow rules, forwarding, and how far back your audit evidence actually reaches.

Learn more
Next step

Open the Defender portal and look at Email and collaboration.

Explorer is Plan 2, real-time detections is Plan 1. Then go and look at whether impersonation protection contains a single name. Those two answers together tell you whether your next move is a purchase or an afternoon of configuration, and it is very nearly always the second.

Book an email security reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Endpoint Services

EDR plan selection, onboarding and zero-gap AV migration

Learn more

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more

SOC-as-a-Service

24/7 security operations delivered as a service

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA