What's changed: Created MS-102 Chapter 3 (domain: Defender XDR, part 1). Defender XDR investigate/respond (Security Exposure Management/Secure Score proactive posture, incidents = correlated alerts and triage, advanced hunting KQL, Defender Threat Intelligence) and Defender for Office 365 (threat policies anti-phishing/spam/malware, Safe Attachments detonation/Safe Links click-time re-evaluation, alert policies, Threat Explorer investigation, attack simulation training, restricted entities release).
3.2Defender for Office 365
Understand threat policies (anti-phishing/anti-spam/anti-malware), Safe Attachments and Safe Links, alert policies, investigating email/collab threats with Threat Explorer, attack simulation training, and restricted entities.
Microsoft Defender for Office 365 provides threat protection for email/collaboration—combining defense at the gateway, investigation, user education, and post-incident response.
3.2.1Threat policies and Safe Attachments/Links
Threat policies include anti-phishing (spoof/impersonation detection), anti-spam, and anti-malware. Safe Attachments detonates attachments in a sandbox to catch unknown malware; Safe Links re-evaluates URLs at click time to block malicious links (effective even for links weaponized later). Remember: "attachment" = Safe Attachments; "link/URL" = Safe Links.
3.2.2Investigate, educate, respond
Use alert policies to notify on suspicious activity, and Threat Explorer (Explorer) to investigate actual email/collab threats (detected threats, delivery status, remediation). Attack simulation training sends simulated phishing to train users (education, distinct from real-threat investigation). Restricted entities shows users restricted from sending (e.g., due to spam); remediate the cause, then remove the restriction.
Cues: "detonate attachments in a sandbox" = Safe Attachments. "re-evaluate URL at click time" = Safe Links. "detect impersonation" = anti-phishing. "investigate delivered threat mail" = Threat Explorer. "train users with simulated phishing" = attack simulation. "release a send-restricted user" = restricted entities.
Watch the mix-ups: (1) Safe Attachments (attachment) vs Safe Links (URL). (2) Attack simulation (educational fake phishing) vs real-threat investigation (Threat Explorer). (3) Restricted entities (release send restriction) vs Conditional Access (sign-in control). (4) Anti-phishing/spam/malware are threat policy types.
3.2.3Section summary
- Threat policies = anti-phishing/spam/malware; Safe Attachments = detonate attachments; Safe Links = re-evaluate URLs at click
- Investigate delivered threats with Threat Explorer; notify with alert policies
- Attack simulation trains users; restricted entities releases send-restricted users
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to run inbound email attachments in a safe environment to detect unknown malware before delivery. Best?
Q2. You want to re-evaluate URLs in email at the moment a user clicks, to block malicious sites. Best?
Q3. To improve phishing resilience, you want to send simulated phishing and assign training based on results. Best?
Q4. A compromised account sent bulk spam and is now blocked from sending. After remediation, you want to remove the restriction. Best?
Q5. You want to investigate delivery and scope of phishing emails actually delivered to the tenant and remediate (purge) in bulk if needed. Best?

