Blog Post

Microsoft Defender for Office 365 Blog
3 MIN READ

Microsoft Defender for Office 365 Plan 1 is now rolling out to Microsoft 365 E3 and Office 365 E3

VipulPandey's avatar
VipulPandey
Icon for Microsoft rankMicrosoft
Jun 17, 2026

Starting today, Microsoft Defender for Office 365 Plan 1 is rolling out to customers with Microsoft 365 E3/G3 and Office 365 E3/G3 licenses, with rollout expected to complete by Fall 2026. For security teams, this means added protection against phishing, malware, and malicious links across email and collaboration, without needing to purchase or deploy a separate email security solution. It also means some protections will turn on automatically, so now is the right time to review your configuration and prepare for any changes to mail flow, policies, and end-user experience.

What E3 customers are getting

Previously, these subscriptions included built-in security to help filter spam and known malware. Defender for Office 365 Plan 1 builds on that foundation with additional protections designed to catch more sophisticated phishing attempts, malicious links, and zero-day threats, while giving your team better visibility into what is happening in your environment.

  • Safe Links: Helps protect users with time-of-click protection by checking URLs and blocking malicious destinations, including QR code-based attacks.
  • Safe Attachments: Helps stop unknown and zero-day malware before harmful files reach users.
  • Advanced anti-phishing: Helps detect impersonation attacks that target your users, executives, and trusted domains.
  • Expanded visibility and reporting: Gives security teams more actionable detections, alerts, and reporting in the Microsoft Defender portal.

What changes automatically

As the plan rolls out, protection will turn on automatically for licensed users. That is good news from a security perspective, but it is still important to understand what is changing in your environment. New protections can affect how messages are processed, how suspicious links are handled, what users see when they click blocked content, and how your team monitors and tunes policy settings after rollout. 

Read more about it here: https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies#use-the-microsoft-defender-portal-to-add-exclusions-to-the-built-in-protection-preset-security-policy

How to prepare for the rollout

  • Review your current mail flow and security configuration. If you know how mail is routed today and which protections are already in place, it will be easier to spot what changes once Defender for Office 365 Plan 1 is active.
  • Decide how you want to manage policies. When the plan becomes available in your tenant, built-in protection is applied automatically for licensed users. If you want Microsoft recommended settings beyond that baseline, consider enabling the Standard or Strict preset security policies.
  • Prepare your help desk and users. Users may start seeing warning or block experiences when Safe Links identifies a malicious destination. A simple heads-up can reduce confusion and support tickets. For more details and how to customize user notification, see Set up Safe Links policies.
  • Plan for exceptions and tuning. If you have specific users, domains, or workflows that need exclusions, review those requirements early so your team is ready to adjust policies after rollout.
  • Monitor what changes. Use the Microsoft Defender portal and Microsoft Secure Score to track new detections, review improvement actions, and prioritize follow-up configuration work.

If you use a third-party secure email gateway

If your organization routes email through a third-party secure email gateway such as Proofpoint, Mimecast, or Barracuda before it reaches Microsoft 365, you should review your configuration now. In many environments, it is recommended to configure Enhanced Filtering for Connectors, preserve original sender details in Exchange Online, and decide which service will handle link rewriting to avoid unnecessary overlap. If you are evaluating a broader consolidation of your email security stack, our guides on defense in depth and migration to Defender for Office 365 can help.

Protection also extends to Microsoft Teams

The plan also extends protection to Microsoft Teams chats and channels. That includes protection for shared links and files, post-delivery removal of malicious content, admin controls to manage enforcement, and user reporting to help your security team investigate suspicious messages faster. For practitioners, this adds another layer of coverage across the collaboration tools users rely on every day.

Learn more

For implementation guidance, visit the Microsoft Defender for Office 365 security documentation, review the step-by-step guides, and use the preset policy, defense in depth, migration, and connector configuration resources linked above to plan your rollout.

Updated Jun 18, 2026
Version 2.0