What Is Exchange Online Protection and Is It Enough on Its Own?
By Jamie Hamilton · Published
If your business uses Microsoft 365, you already have Exchange Online Protection. You may not know it by name, but it has been filtering your mail since the day you moved to Exchange Online. What is less widely understood is that it is the floor of Microsoft's email security rather than the whole of it.
What Exchange Online Protection does
It is the baseline filtering service included with every plan that has Exchange Online. It handles anti-spam, anti-malware scanning, connection filtering against known bad senders, basic phishing detection, and filtering of outbound spam so your own tenant does not become the problem.
It is genuinely good at what it does. The overwhelming majority of what is sent at your domain never reaches anybody, and that is EOP doing its job invisibly. The question is not whether it works. It is what falls outside the category of thing it is built to catch.
The four things it structurally cannot catch
Not shortcomings so much as consequences of how it works.
Novel malware. EOP matches against known signatures, so something genuinely new passes until it is known. The window is usually short and it only has to be open once.
Links that were not malicious at delivery. A URL is checked when the message arrives. An attacker who sends a clean link and repoints it two hours later has defeated a check that happened in the past, and the message is sitting in the inbox looking exactly as safe as it did when it was scanned.
Well-written impersonation. A business email compromise message contains no attachment, no link and no malware. There is nothing for content filtering to find because the harmful part is the request. This is the category that costs Australian businesses the most and the one baseline filtering is least able to help with.
Anything sent from inside. EOP filters mail arriving from outside your organisation. Once an attacker is operating from a compromised internal mailbox, their messages to your other staff are internal mail, and inbound filtering does not apply to them. That is also the most convincing phishing your people will ever receive, because it genuinely comes from a colleague.
What Defender for Office 365 adds
Defender sits on top of EOP rather than replacing it, and it is included in Microsoft 365 Business Premium. It addresses three of the four gaps above directly:
- •Safe Attachments opens a suspicious file in an isolated environment and watches what it does before letting it through, which catches malware that has no signature yet because it is judged on behaviour rather than recognition.
- •Safe Links rewrites URLs so the check happens when somebody clicks rather than when the message arrived, which closes the repointed-link gap.
- •Anti-phishing with impersonation protection is the one aimed at the expensive category. It learns who normally emails whom and flags a message where the display name matches your director but nothing else does, or where the sending domain is one character different from a supplier you deal with.
- •Attack simulation training lets you run a controlled phishing campaign against your own staff, which is the only honest way to find out how the human layer is doing.
The fourth gap, internal mail from a compromised account, is not really an email filtering problem and is not solved here. That one is answered by multi-factor authentication, Conditional Access, and an alert when somebody creates a mailbox forwarding rule.
Do you need it?
If the business handles money, customer records or anything confidential, which is nearly all of them, then yes. The gap between Business Standard and Business Premium is a modest monthly difference per user. A single successful invoice fraud is not modest.
There is a more important version of that question though, and it is the one worth asking first.
Having it and using it are different things
A large share of the businesses I look at are already paying for Business Premium and have never configured the Defender features inside it. The licence is assigned, the capability is available, and the policies are on their defaults or were never created.
This is the most common finding in this area and the cheapest to fix, because there is nothing to buy. Before pricing an upgrade, check what you already own. In the Defender portal, look at whether Safe Attachments and Safe Links policies exist and who they apply to, and whether anti-phishing has your executives listed as protected users, because impersonation protection needs to be told who to protect.
Paying for a control and not switching it on is the worst position available: the cost of the protection with none of the protection, and a reasonable belief that you are covered.
Frequently asked questions
What is Exchange Online Protection?
The baseline email filtering included with every Microsoft 365 plan that has Exchange Online. It covers anti-spam, anti-malware scanning, connection filtering against known bad senders, basic phishing detection, and outbound spam filtering so your own tenant does not become a problem for others. It has been running since the day you moved to Exchange Online, whether or not anybody configured it.
Is Exchange Online Protection enough on its own?
It is good at what it is built for and there are four things it structurally cannot catch: malware too new to have a signature, links that were harmless when the message arrived and were repointed later, well-written impersonation that contains no attachment or link at all, and anything sent from a compromised mailbox inside your own organisation, because inbound filtering does not apply to internal mail.
What is the difference between EOP and Defender for Office 365?
Defender sits on top of EOP rather than replacing it. It adds Safe Attachments, which judges a file by behaviour in an isolated environment rather than by recognising it; Safe Links, which checks a URL when somebody clicks rather than when the mail arrived; impersonation protection aimed at display name and look-alike domain fraud; and attack simulation training. It is included with Microsoft 365 Business Premium.
Do I already have Defender for Office 365?
If you are on Microsoft 365 Business Premium, yes. Whether it is doing anything is a separate question, and a large share of businesses paying for Business Premium have never configured it. Check in the Defender portal whether Safe Attachments and Safe Links policies exist and who they apply to, and whether anti-phishing has your executives listed as protected users, because impersonation protection has to be told who to protect.
Is it worth upgrading from Business Standard to Business Premium?
For a business handling money, customer records or anything confidential, generally yes: the difference is a modest amount per user per month and a single successful invoice fraud is not modest. Check what you already have first though. If you are already on Business Premium the answer is not to buy anything, it is to configure what you are paying for, and that costs nothing.
Does email filtering stop business email compromise?
Only partly, and this is the gap worth understanding. A well-written impersonation email has no malware, no attachment and often no link, so content filtering has nothing to examine. Impersonation protection in Defender helps because it looks at sender patterns rather than content. The rest is answered by process, specifically a rule that any change of bank details is verified by voice on a number you already had.
Related Articles
Want to know whether the protection you already pay for is switched on?
Email Security, $299or call 0403 401 250