Go and open the Defender portal. Explorer means Plan 2. Real-time detections means Plan 1.
That is the published shortcut for telling the two apart, and it takes about ten seconds. Which one you hold determines whether you can genuinely investigate a business email compromise or only observe that one occurred. Most American companies have never once checked.

- Three tiersBuilt-in, Plan 1, Plan 2
- E3 and Business PremiumBoth land on Plan 1
- Explorer or notThe ten-second check
- BEC is the riskNot volume spam
Eight things to understand about the email protection ladder.
The ten second check that settles which plan you hold
The documentation states this twice, in two different places. Look at the email and collaboration section of the Defender portal. Real-time detections means Plan 1. Explorer means Plan 2. That is the fastest way to tell, it needs no conversation with a supplier, no digging through the admin center and no licensing expertise. Do it before reading a single further word about which plan to buy.
What everybody already has, and what it is for
Any subscription with cloud mailboxes already includes anti-malware, anti-spam with bulk handling, anti-phishing spoofing protection alongside the spoof intelligence view, outbound spam protection, connection filtering, quarantine with policies attached, the tenant allow and block list, message trace and automatic purging of anything found bad after delivery. This tier is described as preventing broad, high-volume, already-known attacks, and it is genuinely excellent at exactly that. Volume spam is not what costs American businesses money.
What Plan 1 adds: the targeted attack layer
Plan 1 is described as covering previously unseen malware, phishing and business email compromise. In concrete terms it adds impersonation protection for both people and domains, mailbox intelligence drawing on who actually corresponds with whom, adjustable phishing thresholds, attachment detonation in email and across SharePoint, OneDrive and Teams, and link protection in email, the Office applications and Teams. Impersonation protection is the piece that matters most, because impersonation is precisely how wire fraud arrives.
What Plan 2 adds: investigation, hunting and automation
Plan 2 is summarized as adding phishing simulations, investigation after the fact, hunting, response and automation. Specifically that means simulation training, protection aimed at your most important accounts, Explorer replacing real-time detections, threat trackers, campaign views, advanced hunting reaching Teams messages, and automated investigation and response including the version covering compromised accounts. The automation is the practical difference for any team without a dedicated security operations function.
Which subscriptions carry which plan
E3, the government equivalent and Business Premium are given as examples carrying Plan 1, with the academic and enterprise top tiers carrying Plan 2. Worth noting the contrast with endpoint protection, where Business Premium is genuinely ahead of E3. On email the two land on identical rungs, so an American business on either holds exactly the same protection and faces exactly the same decision.
Priority accounts, which most organizations never configure
Tagging people, including marking them as priority accounts, works at Plan 1. The protection that acts on that tag is a Plan 2 capability. The people worth treating differently are the finance team, the executives, and anybody with the authority to change payment details, and in most tenants we open, nobody has ever marked a single one of them. Tagging costs nothing and improves both the alerting and any investigation that follows.
Safe Documents is not in either plan
A genuine trap, this one. Safe Documents comes with the academic top tier or with the Defender Suite licensing, and is explicitly not part of either email plan. So a company on Plan 2 does not automatically have it, which surprises people who quite reasonably assumed the top email plan would include every feature adjacent to email.
None of it replaces email authentication
The three authentication records in your DNS are what let the platform judge spoofing accurately. Those records exist to stop your own domain being impersonated to other people, which no amount of inbound filtering at any tier addresses. The two are complementary and both are necessary, and companies buy the higher plan while leaving their own domain wide open to being spoofed with striking regularity.
The attack that empties a bank account bears no resemblance to spam.
Every rung of this ladder deals with bulk spam competently, and bulk spam is not the risk. The risk is a single convincing message about a payment, and where you sit on the ladder decides whether you can see it approaching and reconstruct it afterward. Business email compromise has ranked among the costliest categories in the FBI annual internet crime reporting for years running, and the pattern below explains why.
- It usually arrives as one well-written message impersonating somebody the recipient already trusts, asking for a payment or for bank details to be updated. Very often there is no attachment, no link and no malware anywhere in it, which leaves the volume-based filtering in the built-in tier with almost nothing to work from. Impersonation protection, starting at Plan 1, is the layer built specifically for this.
- The more dangerous version involves no impersonation whatsoever. It is a real message from a genuinely compromised mailbox, and very often that mailbox belongs to a supplier rather than to anybody at your company. No filtering tier can flag it as spoofed, because nothing about it is spoofed. What actually helps is a payment process where any change of bank details gets verified by phone to a number you already had on file. That costs nothing and is worth more than any upgrade on this page.
- Where Plan 2 earns its keep is in the aftermath. When somebody asks what happened, who else received the message and whether anybody clicked anything, it is Explorer, the campaign view and automated investigation that answer. On Plan 1 you have real-time detections and the email entity page, which is genuine capability and a considerably narrower window when you are reconstructing an incident under pressure.
- And quite separately from any of this, publish and enforce all three authentication records. Those are what let the platform judge spoofing accurately in the first place. They also stop your own domain being turned against your customers, which no inbound plan at any tier does anything about.
Four things that matter considerably more than which plan you end up buying.
Which tier you hold gets established before anybody mentions an upgrade
That ten second check in the portal settles the question outright. In a meaningful number of cases the company already holds Plan 1 and has configured none of it, which makes the work configuration rather than purchasing. Recommending Plan 2 to somebody running Plan 1 on default settings would be selling more capacity to a business not using what it already owns.
We configure impersonation protection around real people
Impersonation protection acts on specific named people and specific named domains, so somebody has to sit down and decide who and what gets protected. That means the finance team, the executives, anybody able to change payment details, along with your own domains and the vendors who matter. A short exercise, included from Plan 1 onward, and left undone in the large majority of tenants we assess.
Some attacks are not a filtering problem at all, and we say so
A real message from a genuinely compromised supplier mailbox is not spoofed in any way, so no tier will flag it. What actually prevents the loss is a payment process where any change to bank details gets verified by phone to a number you already held. We say that plainly, even when it means recommending a change of process instead of a product, because the alternative is selling somebody a license against a risk it does not touch.
We do the outbound half as well
All three authentication records are what let the platform judge spoofing accurately, and they also stop your domain being used as a weapon against your own customers. No inbound plan does anything whatsoever about that second problem. We treat both as a single piece of work, because a company that bought Plan 2 and left its domain spoofable has protected one direction thoroughly and the other not at all.
Six US situations that justify looking at this properly.
Any business that pays or receives invoices
Which describes every company, and it is why this page exists at all. The impersonation protection arriving at Plan 1 is aimed precisely at the message claiming to come from your chief executive or from a supplier. Configuring it around the specific individuals who authorize payments is short work with an unusually direct relationship to the loss it prevents.
A business on Business Premium or E3
Both carry Plan 1, so impersonation protection, link protection and attachment detonation are all present whether anybody configured them or not. Worth noting this differs from endpoint protection, where Business Premium genuinely is ahead of E3. On email the two are level, and for either the useful question is simply whether any of it has been switched on.
An organization that has just had a near miss
A payment came within an hour of going to the wrong account, or somebody received a thoroughly convincing message from a supplier that turned out to be fraudulent. This is exactly the right moment to look at all of this, because the company has just lived through the specific risk and nobody needs persuading about the budget. The work is nearly always configuration plus a change to the payment process rather than anything requiring a purchase.
A firm with significant vendor payment flows
Construction, distribution, logistics, title and escrow, and anybody else moving money on the strength of an emailed instruction. The exposure sits with your suppliers rather than your own mailboxes, because a compromise at their end produces a genuine message from a genuine address. Domain impersonation protection extended to supplier domains handles the lookalikes. Verifying by phone handles everything it cannot.
A business that needs to investigate an incident properly
When somebody asks who else got the message, whether anybody clicked, and what the sender did next, the answer you can give depends entirely on your tier. Explorer, the campaign view and automated investigation all sit at Plan 2. If a state breach notification analysis, an insurance claim or a large customer requires you to reconstruct an email incident in detail, that is the clearest argument there is for the higher plan.
An organization running user awareness training
Simulation training sits at Plan 2, and running phishing simulations from inside the same platform that filters the mail carries real practical advantages over a separate product. If you already pay for a standalone simulation tool and either hold Plan 2 or are considering it, it is worth checking whether you are about to buy the same capability for the second time.
What we find when we review email security in US tenants.
| Feature | Tier known and configured | Licensed, default settings | Built-in only |
|---|---|---|---|
Knows which plan it holds | Yes | Assumes | Correct by default |
Safe Links and Safe Attachments enabled | Yes | Partly | Not available |
Impersonation protection configured for named people | Yes | No | Not available |
Priority accounts tagged | Yes | No | Not available |
Safe Attachments covers SharePoint and Teams | Yes | Rarely | Not available |
External sender warning in place | Yes | Sometimes | Sometimes |
SPF, DKIM and DMARC enforced | Yes | p=none or absent | Usually absent |
Could reconstruct who else got the message | Yes | Partly | Barely |
Payment changes verified out of band | Yes | Sometimes | Rarely |
Answers a cyber insurance email question honestly | Yes | Unclear | No |
The built-in tier, Plan 1 and Plan 2, set alongside one another.
Capability
Anti-malware, anti-spam, anti-spoofing
- Built-in
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Quarantine, Tenant Allow/Block List, message trace
- Built-in
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Zero-hour auto purge for email
- Built-in
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
User and domain impersonation protection
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Mailbox intelligence impersonation, contact graph
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Safe Attachments, email and SharePoint, OneDrive, Teams
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Safe Links in email, Office clients and Teams
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Real-time detections
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Replaced by Explorer
Capability
Email entity page and user tags
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Zero-hour auto purge for Teams
- Built-in
- No
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Threat Explorer
- Built-in
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Threat Trackers and Campaigns
- Built-in
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Attack simulation training
- Built-in
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Automated Investigation and Response
- Built-in
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Safe Documents
- Built-in
- No
- Plan 1
- No
- Plan 2
- No, needs A5 or Defender Suite
Five steps, starting with a ten-second check.
- 1
Establish the tier and what is configured
That ten second check in the portal first, then a proper review of what has genuinely been enabled: link protection, attachment detonation including the coverage reaching SharePoint, OneDrive and Teams, the anti-phishing policies, and whether the preset policies are in use or custom ones nobody has opened since they were written.
- 2
Configure impersonation protection around named people and domains
The executives and the finance team, anybody with authority to change payment details, your own domains, and whichever supplier domains genuinely matter. This calls for a decision from the business about who gets protected rather than a technical judgment from IT, and it is the most precisely targeted control available against the attack that actually costs money.
- 3
Tag priority accounts and set the surrounding controls
Priority accounts tagged, warnings on external senders, and a reporting route so that somebody suspicious of a message has somewhere to send it. Then that route gets tested from one end to the other, because a report button leading nowhere teaches people very quickly to stop pressing it.
- 4
Fix the outbound half
All three authentication records across your domains, which improves the platform own spoofing judgment and separately stops your domain being used against your customers. Where that turns out to be a larger job it gets scoped on its own, because moving to enforcement safely needs discovery work in its own right.
- 5
Make the Plan 2 decision with actual evidence in front of you
Only once everything above is done, and with one clear question in front of you: do you need investigation after the fact, hunting and automation, and would anybody here genuinely use them. A ninety day Plan 2 trial is available through the portal, so this can be settled by running it rather than by arguing about it in a meeting.
What organizations ask about Defender for Office 365.
Fifteen checks, and the first one takes ten seconds.
What you have
- In the portal, does it say Explorer or does it say real-time detections?Explorer is Plan 2. Real-time detections is Plan 1. That is the whole test.
- Are Safe Links and Safe Attachments actually turned on?Included at Plan 1 and frequently never configured.
- Does Safe Attachments cover SharePoint, OneDrive and Teams?A separate setting from email, and often missed.
- Are the preset security policies in use, or custom ones nobody has read in years?Standard and Strict presets are a reasonable default.
- Has anybody ever run a Plan 2 trial to find out what it actually adds?Microsoft provides a 90-day trial through the Defender portal.
The payment fraud layer
- Is user impersonation protection configured for your executives?It protects specific named people, which means somebody has to sit down and name them.
- Is domain impersonation protection configured for your own domains?And for key vendor and customer domains.
- Are priority accounts tagged?Finance, executives, anyone who can change payment details.
- Do external emails carry a visible warning?Cheap, and effective against display-name tricks.
- Does a bank detail change require phone verification?The control no license tier can replace.
Could you investigate afterwards
- Could you list everybody else who received a particular message?Explorer at Plan 2, more limited at Plan 1.
- Would you know whether a link was clicked?Tracing a link and the email entity page both begin at Plan 1.
- How far back does your audit retention reach?A separate question from your Defender plan.
- Are SPF, DKIM and DMARC published and enforced?Microsoft states these improve its own spoofing protection.
- Has anybody ever reported a phishing message and followed what happened to it?User submission, triage, and what happens next.
The pages around this one.
Microsoft Outlook and Exchange
The mail platform underneath: mailbox management, mail flow, and the DNS records that decide whether your domain can be spoofed.
Defender for Endpoint
The device half of the same Defender family, where the licensing pattern is genuinely different and Business Premium comes out ahead of E3.
Cybersecurity audit and compliance
A full tenant review including mail flow rules, forwarding, and how far back your audit evidence actually reaches.
Open the Defender portal and look at Email and collaboration.
Explorer is Plan 2, real-time detections is Plan 1. Then go and look at whether impersonation protection contains a single name. Those two answers together tell you whether your next move is a purchase or an afternoon of configuration, and it is very nearly always the second.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Defender XDR Services
One incident queue across endpoint, email and identity
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn more