Most attacks on a small business still start with an email. Rarely a sophisticated one — usually a message that looks like it came from a supplier, a colleague or Microsoft itself, asking somebody to sign in or approve a payment. It works because it is plausible, not because anyone was careless.
Microsoft 365 Defender is the set of protections Microsoft builds into the platform to catch those messages before they reach anybody. If you are on Microsoft 365 Business Premium you are already paying for it. The question is usually not whether you have it, but whether anyone has set it up.
What it actually does
Spots impersonation
Defender builds a picture of who your people normally correspond with. When a message arrives claiming to be from your finance director but does not behave like the real one — different domain, unusual routing, no prior contact — it gets flagged. This is the protection that catches invoice redirection, which is the fraud that costs small businesses the most money in practice.
Scans attachments with more than one engine
Several scanning engines run rather than one, so a file missed by the first may still be caught. Definitions refresh hourly. You can also block file types that have no business arriving by email at all — executables, screensavers and similar — so they never need scanning in the first place.
Filters spam in both directions
Inbound mail is judged on where it came from and what is in it. Defender also watches outbound mail, which matters more than people expect: if one of your accounts is compromised and starts sending, you find out from your own system rather than from an embarrassed customer.
Checks links when they are clicked, not when they arrive
This is the one worth understanding. Attackers routinely send a clean link and switch the destination to something malicious after delivery, so a scan on arrival sees nothing wrong. Safe Links re-checks the destination at the moment somebody clicks it, and covers links in Teams and SharePoint as well as email.
Opens attachments somewhere safe first
Attachments are opened in an isolated environment before they reach a real device. If the file tries to do something it should not, it never arrives. If it behaves, it comes through and nobody notices anything happened.
Handles mail that routes through something else first
If your mail passes through another filtering service before it reaches Microsoft, the authentication signals that prove who really sent it can be stripped along the way, and Microsoft loses the ability to judge the true sender. Enhanced Filtering restores that. It only applies if you have that kind of routing, and plenty of businesses do not.
Gives people a way to report something odd
Staff get a button to report anything that looks wrong. It goes somewhere you can actually see, rather than into a colleague’s inbox with the subject line “is this real?”. Reports also go back to Microsoft, which improves detection for everyone.
Where it needs configuring
Defender does comparatively little in its default state. Several of the protections above are either off, or applied so permissively that they rarely fire, until somebody goes through the policies deliberately.
- Anti-phishing policies need your actual directors and finance staff listed by name before impersonation protection has anything to compare against.
- Safe Links and Safe Attachments need policies created and scoped to the right people. A tenant with no policy applied gets no protection from either.
- The common attachment filter ships with a short default list that is worth extending.
- Quarantine needs somebody responsible for reviewing it. Without that, legitimate mail sits there for days and people start asking for the filtering to be turned down.
- Alerts need to arrive somewhere a person reads. An alert into an unmonitored mailbox is not a control.
This is the gap we find most often when we take over a Microsoft 365 tenant. The licence is being paid for, the product is sitting there, and nobody has ever been through the settings. It is not anyone’s fault — it is not obvious from the admin centre that anything is missing.
What it will not do
Defender covers email, files and links. It does not manage your laptops, enforce multi-factor authentication, or tell you who has access to which files — those are different parts of the same platform, and they need setting up separately.
No filter catches everything either. The businesses that come off worst are usually the ones where nobody had ever been shown what a convincing message looks like, so the one that got through went unquestioned. Filtering and awareness training do different jobs, and neither replaces the other.
Worth checking yours
If you are on Business Premium and nobody has been through the Defender policies, there is almost always something to tighten. You can check the main ones yourself in the Microsoft 365 security centre — look at whether anti-phishing policies name your executives, and whether Safe Links and Safe Attachments policies exist at all.
If you would rather someone else looked, we are happy to go through it and tell you what we find, whether or not you decide to do anything about it with us.
