Yes. Since July 1, 2026, Microsoft includes Defender for Office 365 Plan 1 with Office 365 E3 and Microsoft 365 E3, adding Safe Links, Safe Attachments and impersonation protection. Business Premium already had Plan 1, and Business Basic and Standard didn't change. E3 admins should switch on Microsoft's Standard preset policy, and everyone still needs SPF, DKIM and DMARC.
Key takeaways
- Office 365 E3 and Microsoft 365 E3 include Defender for Office 365 Plan 1 from July 1, 2026. Microsoft says E3 customers get Plan 1 capabilities only.
- Plan 1 adds Safe Links, Safe Attachments and impersonation protection to the built-in protection every cloud mailbox has.
- Business Premium already included Plan 1. Business Basic and Business Standard keep the built-in protection only.
- Safe Links and Safe Attachments work by default, but impersonation protection needs you to name the people to protect.
- Defender filters the mail your staff receive. SPF, DKIM and DMARC are what stop criminals forging your domain in mail sent to everyone else.
What changed on July 1, 2026?
Microsoft's service description for Defender for Office 365 now reads: "Effective July 1, 2026, Defender for Office 365 Plan 1 is included with Office 365 E3 and Microsoft 365 E3. E3 customers receive Plan 1 capabilities only."
Plan 2 features such as Threat Explorer, automated investigation and response, and Attack simulation training are not part of the change.
Which Microsoft 365 plans are affected?
| Subscription | Defender for Office 365 before July 1 | From July 1, 2026 |
|---|---|---|
| Microsoft 365 Business Basic | Not included (built-in protection only) | No change |
| Microsoft 365 Business Standard | Not included (built-in protection only) | No change |
| Microsoft 365 Business Premium | Plan 1 included | No change |
| Office 365 E3 / Microsoft 365 E3 | Not included | Plan 1 included |
| Microsoft 365 E5 | Plan 2 included | No change |
Microsoft also sells Defender for Office 365 as a standalone add-on for business and enterprise plans that don't include it, so a Business Basic or Standard tenant can still buy it separately.
What does Defender for Office 365 Plan 1 add?
Every subscription with cloud mailboxes includes built-in anti-malware, anti-spam and anti-spoofing protection. Microsoft says that layer prevents "broad, volume-based, known email attacks," while Plan 1 "protects email and collaboration features from zero-day malware, phishing, and business email compromise (BEC)."
According to Microsoft's documentation, Plan 1 adds:
- Safe Links: scans and rewrites links in inbound email, and checks links again at the moment someone clicks them in email, Teams and supported Office apps.
- Safe Attachments: opens attachments in a virtual environment to see what they do before the message is delivered, and also covers files in SharePoint, OneDrive and Teams.
- Impersonation protection: extra anti-phishing settings that flag messages impersonating specific people or domains, plus "mailbox intelligence," which learns who each user normally emails.
- Investigation tools: Real-time detections and Defender for Office 365 reports.
Why does this matter for your business?
Business email compromise (BEC) relies on impersonation, which comes in two shapes that need different fixes.
Someone forging your exact domain. If a criminal sends mail claiming to be from [email protected] (a made-up address) from their own server, SPF, DKIM and DMARC on your domain are the fix, with DMARC set to enforcement (p=quarantine or p=reject). Your DMARC record tells receiving mail systems what to do with messages that fail those checks, which protects your customers and vendors too. Defender for Office 365 can't do that job: it protects your own users, not the companies a criminal writes to while pretending to be you.
Someone impersonating you from a different domain. A lookalike domain, or a free email account with your CEO's name as the display name, is a domain you don't own, so your DMARC record doesn't apply to it. That's the gap Plan 1's impersonation protection is designed to narrow for your own staff.
Microsoft treats both as necessary: its Defender for Office 365 setup guide makes SPF, DKIM and DMARC for every custom domain, including parked domains and subdomains, step 1, before threat policies.
One limit: Microsoft says user impersonation protection doesn't work if the sender and recipient have previously exchanged email. It's a filter, not a substitute for checking payment requests.
What should you do now?
If you're on E3, these steps follow Microsoft's setup guidance:
- Confirm your licenses. Check the Your products page in the Microsoft 365 admin center to see which subscriptions your tenant has.
- Know what's already on. A "Built-in protection" preset policy gives Safe Links and Safe Attachments to all recipients by default in tenants with Defender for Office 365 licenses.
- Turn on the Standard preset security policy for everyone. Microsoft recommends starting with Standard for all users unless you have a compelling business reason not to. In the Microsoft Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Preset security policies. Consider Strict for high-value targets such as executives and finance staff.
- Tell impersonation protection who matters. The preset policies automatically protect the domains you own and use mailbox intelligence, but you must add the individual people to protect, up to 350 users. Start with your owner, executives, and anyone who approves payments or payroll.
- Set up message reporting. Let users report suspicious mail with Outlook's built-in Report button, and choose where those reports go.
- Check your own domain. Run your domain through our free SPF, DKIM and DMARC scanner, and if DMARC is still at
p=none, plan the move to enforcement with our DMARC enforcement roadmap.
If you're on Business Basic or Standard, nothing changed on July 1. The domain-side steps still apply, and our small business email security checklist covers the rest.
Frequently asked questions
Is Defender for Office 365 included in Microsoft 365 Business Standard?
No. Microsoft's security overview for its business plans shows Defender for Office 365 Plan 1 only in Business Premium. Business Basic and Business Standard get the built-in anti-malware, anti-spam and anti-spoofing protection that every cloud mailbox has. You can add Safe Links, Safe Attachments and impersonation protection by buying Defender for Office 365 as an add-on or upgrading to Business Premium.
Do E3 customers get Plan 2 features like Threat Explorer?
No. Microsoft's service description says E3 customers receive Plan 1 capabilities only. Threat Explorer, automated investigation and response, and Attack simulation training remain Plan 2 features, which Microsoft includes in subscriptions such as Microsoft 365 E5 or sells as an add-on. Plan 1 organizations use Real-time detections to look into recent threats instead.
Does Defender for Office 365 replace DMARC?
No. Defender filters email coming into your organization. DMARC is a DNS record on your own domain that tells every receiving mail system, including your customers' and vendors', what to do with messages that fail authentication while claiming to be from you. Microsoft's own setup guide lists SPF, DKIM and DMARC as the first step, before any threat policies.
Do I need to do anything for Safe Links and Safe Attachments to work?
Basic protection starts on its own: Microsoft's Built-in protection preset policy applies Safe Links and Safe Attachments to all recipients by default. Microsoft still recommends turning on the Standard preset security policy for all users. Impersonation protection needs setup, because you have to add the specific people you want protected.
Need help sorting out your Microsoft 365 email security or DMARC rollout? Call (818) 574-8240.
Sources
- Microsoft Learn — Microsoft Defender for Office 365 Features service description (service documentation, describes the July 1, 2026 change)
- Microsoft Learn — Microsoft Defender for Office 365 service description (service documentation, describes the July 1, 2026 change)
- Microsoft Learn — Microsoft Defender for Office 365 overview (reference documentation, undated)
- Microsoft Learn — Microsoft 365 for business security overview (reference documentation, undated)
- Microsoft Learn — Microsoft 365 and Office 365 plan options (service documentation, undated)
- Microsoft Learn — Preset security policies in cloud organizations (reference documentation, undated)
- Microsoft Learn — Get started with Microsoft Defender for Office 365 (reference documentation, undated)
- Microsoft Learn — Safe Links in Microsoft Defender for Office 365 (reference documentation, undated)
- Microsoft Learn — Set up Safe Attachments policies in Microsoft Defender for Office 365 (reference documentation, undated)
- Microsoft Learn — Anti-phishing policies in cloud organizations (reference documentation, undated)
- Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.