Exchange Online Protection (EOP) - Simply Explained
Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Exchange Online Protection (EOP), Microsoft's built-in email security service that protects every Microsoft 365 mailbox against spam, malware, and phishing attacks. Email remains the number one entry point for cyberattacks. The overwhelming majority of ransomware infections, credential theft, business email compromise, and phishing campaigns all begin with a single email arriving in someone's inbox. Fortunately, every Microsoft 365 tenant already includes Exchange Online Protection, even if administrators never configure it manually. While many organizations rely on it every day, relatively few people understand exactly what it does, where its limitations are, and when additional protection becomes necessary. In this episode, we'll explain how Exchange Online Protection works, explore its three primary security layers, understand Microsoft's Zero-Hour Auto Purge technology, and discuss when organizations should consider upgrading to Microsoft Defender for Office 365. WHAT IS EXCHANGE ONLINE PROTECTION? Exchange Online Protection, commonly known as EOP, is Microsoft's cloud-based email filtering service included with every Microsoft 365 subscription. Rather than requiring organizations to deploy and maintain their own email security servers, Microsoft processes incoming and outgoing mail through its global cloud infrastructure before messages ever reach a user's mailbox. A useful way to understand EOP is to imagine the security guard at the entrance of an office building. Every visitor is checked before entering, suspicious individuals are stopped at the door, and only approved visitors continue inside. Exchange Online Protection performs the same role for email by inspecting every message before it reaches Exchange Online. Out of the box, EOP provides protection against spam, known malware, and basic phishing attempts without requiring additional licensing or complex configuration. For many organizations, it serves as the first and most important layer of email security throughout Microsoft 365. However, while EOP provides an excellent foundation, it is designed to be exactly that—a foundation rather than a complete enterprise security platform. LAYER ONE: ANTI-SPAM PROTECTION The first responsibility of Exchange Online Protection is filtering spam. Every day Microsoft processes enormous volumes of unwanted email, much of which consists of advertising, bulk mail, fraudulent promotions, and automated spam campaigns. Although spam is often considered merely annoying, it also creates the noise that attackers use to hide more dangerous threats. EOP evaluates incoming messages using several different techniques. It checks the reputation of the sending server, analyzes message content for suspicious characteristics, and continuously learns from user feedback whenever messages are marked as junk. Suspicious messages may be delivered directly to the Junk Email folder or quarantined entirely depending on organizational policies. Administrators can also customize filtering behavior, maintain allow and block lists, and adjust filtering aggressiveness to match their security requirements. By removing the overwhelming majority of unwanted messages before users ever see them, Exchange Online Protection dramatically reduces inbox clutter while allowing more advanced security systems to focus on genuinely dangerous attacks rather than processing millions of unwanted advertisements. LAYER TWO: ANTI-MALWARE PROTECTION The second protection layer focuses on malicious attachments. Whenever emails contain files, Exchange Online Protection scans those attachments using Microsoft's malware detection technologies. Known viruses, ransomware, trojans, malicious scripts, and dangerous executable file types are identified before reaching users' inboxes. EOP blocks many commonly abused file formats, including executable programs and scripting files that frequently deliver malware. It also analyzes suspicious attachment behavior using heuristic detection methods to identify known attack patterns. If malware is detected, the email is either quarantined or rejected entirely, preventing users from accidentally opening dangerous attachments. One important limitation, however, is that Exchange Online Protection primarily detects threats Microsoft already recognizes. Brand-new malware variants that have never been observed previously may not yet have detection signatures available. These advanced threats require additional protection provided by Microsoft Defender for Office 365, which analyzes unknown files inside isolated sandbox environments before allowing delivery. For most organizations, EOP effectively blocks the overwhelming majority of known malware while providing a strong first line of defense against email-based attacks. LAYER THREE: ANTI-PHISHING Modern cyberattacks increasingly rely on deception rather than malicious software. Instead of infecting computers directly, attackers convince users to voluntarily reveal passwords, approve fraudulent payments, or visit fake websites that closely resemble legitimate services. Exchange Online Protection combats these attacks through several technologies. Spoof intelligence identifies emails pretending to originate from trusted organizations. Email authentication protocols—including SPF, DKIM, and DMARC—help verify whether sending domains are authorized to send messages on behalf of specific organizations. Machine learning models further evaluate sender behavior to identify suspicious communication patterns. These capabilities significantly reduce basic phishing attacks, particularly those involving spoofed domains or poorly constructed fraudulent messages. However, EOP has limitations. It cannot fully understand organizational relationships or recognize when attackers impersonate specific executives using personal email accounts. Sophisticated business email compromise attacks often require Microsoft's advanced impersonation protection available through Defender for Office 365. Understanding this distinction helps organizations recognize that while EOP blocks many phishing attempts, user awareness and additional security layers remain critically important. ZERO-HOUR AUTO PURGE (ZAP) Even the best security systems occasionally allow suspicious emails into user inboxes. To address this challenge, Microsoft introduced Zero-Hour Auto Purge, commonly known as ZAP. Rather than inspecting messages only when they first arrive, ZAP continuously reevaluates emails already delivered to users. If Microsoft's threat intelligence later determines that a previously accepted message is actually malicious, ZAP automatically removes it from affected mailboxes without requiring administrator intervention. This creates an important safety net for situations where malware signatures or phishing intelligence become available shortly after delivery. Recent enhancements extend ZAP beyond traditional email by allowing it to remove malicious content from Microsoft Teams conversations and even Deleted Items folders when updated threat intelligence identifies newly discovered attacks. For users, this process usually happens invisibly. Potentially dangerous emails simply disappear before they can cause harm, significantly reducing exposure to emerging threats discovered after initial delivery. WHERE EOP REACHES ITS LIMITS Although Exchange Online Protection provides excellent baseline protection, it isn't designed to defend against every possible attack. Unknown malware hidden inside password-protected archives, highly targeted executive impersonation campaigns, malicious links that become dangerous only after email delivery, and sophisticated business email compromise attacks often extend beyond EOP's capabilities. Exchange Online Protection also doesn't perform real-time link analysis when users click URLs or execute unknown attachments inside secure sandbox environments. As attackers increasingly adopt phishing-as-a-service platforms and AI-generated social engineering campaigns, organizations facing elevated security risks often require additional protection beyond basic email filtering. Understanding these limitations doesn't diminish EOP's value—it simply helps organizations make informed decisions about when stronger protection becomes appropriate. WHEN SHOULD YOU UPGRADE TO MICROSOFT DEFENDER FOR OFFICE 365? Microsoft Defender for Office 365 builds directly upon Exchange Online Protection by adding advanced threat detection capabilities. Safe Attachments executes suspicious files inside isolated virtual environments before delivery, identifying previously unknown malware that signature-based detection cannot recognize. Safe Links continuously evaluates URLs at the moment users click them, preventing attacks where websites become malicious only after emails have already been delivered. Defender also introduces executive impersonation protection, learning organizational relationships to identify highly targeted phishing attacks that EOP alone cannot detect. Organizations handling sensitive information, regulated industries, executive leadership teams, financial operations, or frequent external communication generally benefit significantly from Defender's additional protection. Rather than replacing Exchange Online Protection, Defender extends it with deeper intelligence, automated investigation capabilities, and significantly stronger defense against today's most sophisticated email attacks.
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.
🚀 Want to be part of m365.fm?
Then stop just listening… and start showing up.
👉 Connect with me on LinkedIn and let’s make something happen:
- 🎙️ Be a podcast guest and share your story
- 🎧 Host your own episode (yes, seriously)
- 💡 Pitch topics the community actually wants to hear
- 🌍 Build your personal brand in the Microsoft 365 space
This isn’t just a podcast — it’s a platform for people who take action.
🔥 Most people wait. The best ones don’t.
👉 Connect with me on LinkedIn and send me a message:
"I want in"
Let’s build something awesome 👊
00:00:00,000 --> 00:00:03,800
Welcome to another episode of Microsoft Knowledge Nuggets on M365.
2
00:00:03,800 --> 00:00:05,200
FM, I'm Mirko Peters.
3
00:00:05,200 --> 00:00:07,920
Today's topic is something every business relies on, but rarely
4
00:00:07,920 --> 00:00:09,760
thinks about email security.
5
00:00:09,760 --> 00:00:11,200
Here's a number that should stop you.
6
00:00:11,200 --> 00:00:15,440
90% of all cyber attacks on businesses start in one place, the inbox,
7
00:00:15,440 --> 00:00:18,960
not a hacked server, not a compromised app, just a single email.
8
00:00:18,960 --> 00:00:22,240
And if you're like most people, you assume your email is protected, you're right.
9
00:00:22,240 --> 00:00:25,720
It is, but you probably don't know how aware that protection stops.
10
00:00:25,720 --> 00:00:28,320
By the end of this episode, you'll know exactly what
11
00:00:28,320 --> 00:00:31,680
exchange online protection does, where its limits are and whether you need something
12
00:00:31,680 --> 00:00:35,440
more, we'll cover three filtering layers, a safety net that catches what slips
13
00:00:35,440 --> 00:00:38,440
through and the upgrade decision that could save your business.
14
00:00:38,440 --> 00:00:39,960
Here's the simplest definition.
15
00:00:39,960 --> 00:00:42,600
What exactly is exchange online protection?
16
00:00:42,600 --> 00:00:47,200
Exchange online protection or EOP is the built in email security layer that
17
00:00:47,200 --> 00:00:49,400
comes with every Microsoft 365 plan.
18
00:00:49,400 --> 00:00:52,320
No extra cost, no setup required for basic protection.
19
00:00:52,320 --> 00:00:53,200
It's just there.
20
00:00:53,200 --> 00:00:56,560
Think of it like the front gate security guard at your office building that
21
00:00:56,560 --> 00:01:00,480
guard checks everyone who walks in, looks at their badge, verifies they belong.
22
00:01:00,480 --> 00:01:03,440
But once they're through the door, the guard doesn't follow them around.
23
00:01:03,440 --> 00:01:04,960
And that's exactly what EOP does.
24
00:01:04,960 --> 00:01:09,240
It has three core jobs, stops, bam, block malware and catch basic fishing.
25
00:01:09,240 --> 00:01:10,360
Everything runs in the cloud.
26
00:01:10,360 --> 00:01:12,880
So you don't have to maintain servers or update software.
27
00:01:12,880 --> 00:01:14,080
Here's the key point.
28
00:01:14,080 --> 00:01:17,960
EOP is always on, even if you never touch a single setting.
29
00:01:17,960 --> 00:01:21,640
You could buy a Microsoft 365 license, never open the admin center.
30
00:01:21,640 --> 00:01:25,120
And EOP would still be filtering your email, but it's not a full security
31
00:01:25,120 --> 00:01:27,160
suite. It's the foundation, the bare minimum.
32
00:01:27,160 --> 00:01:30,160
And since you're already paying for it as a beginner, you might as well understand
33
00:01:30,160 --> 00:01:30,680
what you've got.
34
00:01:30,680 --> 00:01:33,000
Layer one, anti spam.
35
00:01:33,000 --> 00:01:35,960
Let's start with the first layer, the one that handles the most noise.
36
00:01:35,960 --> 00:01:40,680
Spam, spam is volume about 99% of unwanted email is just bulk junk.
37
00:01:40,680 --> 00:01:44,280
Newsletters you never signed up for, promotional offers, random garbage,
38
00:01:44,280 --> 00:01:46,000
but spam isn't just annoying.
39
00:01:46,000 --> 00:01:48,200
It's also the cover that attack us hide behind.
40
00:01:48,200 --> 00:01:50,360
So how does EOP filter it?
41
00:01:50,360 --> 00:01:51,040
Three ways.
42
00:01:51,040 --> 00:01:52,480
First connection filtering.
43
00:01:52,840 --> 00:01:56,960
EOP checks the IP address of the sending server against known reputation lists.
44
00:01:56,960 --> 00:02:01,000
If that IP has a history of sending spam, the message gets blocked before it
45
00:02:01,000 --> 00:02:02,240
even reaches your mailbox.
46
00:02:02,240 --> 00:02:06,440
Second, content filtering, EOP scans the actual words and patterns in the email.
47
00:02:06,440 --> 00:02:09,960
Subject lines, body text embedded links, it looks for signs of spam.
48
00:02:09,960 --> 00:02:12,600
Third, bulk, complained feedback loops.
49
00:02:12,600 --> 00:02:16,720
If enough people mark a sender, a spam EOP learns and starts blocking that sender
50
00:02:16,720 --> 00:02:18,280
for everyone, the goal is simple.
51
00:02:18,280 --> 00:02:21,720
Keep spam out of your inbox without accidentally deleting legitimate mail.
52
00:02:21,840 --> 00:02:23,280
So what happens to flag spam?
53
00:02:23,280 --> 00:02:25,520
It goes to quarantine or to the user's junk folder.
54
00:02:25,520 --> 00:02:29,560
Admins can customize which one, for example, say a sender from a known spam list
55
00:02:29,560 --> 00:02:30,600
tries to send you an offer.
56
00:02:30,600 --> 00:02:35,320
EOP sees the IP recognizes it and blocks the message before you ever see it.
57
00:02:35,320 --> 00:02:37,400
Most users never notice this happening.
58
00:02:37,400 --> 00:02:40,440
It's completely invisible when it works, but admins have controls.
59
00:02:40,440 --> 00:02:43,760
You can adjust how aggressive the filter is, standard or strict.
60
00:02:43,760 --> 00:02:46,120
You can set a loud and blocked sender lists.
61
00:02:46,120 --> 00:02:50,920
You can configure quarantine notifications, so users know when something was held back.
62
00:02:51,360 --> 00:02:52,200
Why does this matter?
63
00:02:52,200 --> 00:02:56,320
Because spam is the bulk of all email attacks, filtering it out reduces the noise
64
00:02:56,320 --> 00:02:57,080
for the other layers.
65
00:02:57,080 --> 00:03:00,920
That means the anti-malware and anti-fishing systems can focus on the real threats
66
00:03:00,920 --> 00:03:02,280
instead of drowning in junk.
67
00:03:02,280 --> 00:03:05,640
Layer two, anti-malware, spam is mostly annoying.
68
00:03:05,640 --> 00:03:07,200
Malware is dangerous.
69
00:03:07,200 --> 00:03:09,480
So let's talk about the second layer, anti-malware.
70
00:03:09,480 --> 00:03:13,160
This is what catches viruses, ransomware and trojans hidden inside attachments.
71
00:03:13,160 --> 00:03:14,000
Here's how it works.
72
00:03:14,000 --> 00:03:17,840
When an email arrives with an attachment, EOP inspects that file in real time
73
00:03:17,840 --> 00:03:19,720
against a database of known malware signatures.
74
00:03:20,200 --> 00:03:24,080
It also uses heuristics, behavioral patterns that suggest something is off.
75
00:03:24,080 --> 00:03:25,440
So what exactly does it block?
76
00:03:25,440 --> 00:03:29,040
By default, EOP blocks executable files like X and us,
77
00:03:29,040 --> 00:03:31,760
X-KR, it blocks scripts like VBEs and .js.
78
00:03:31,760 --> 00:03:35,600
It blocks archives that contain suspicious code, a whole list of common dangerous
79
00:03:35,600 --> 00:03:36,160
file types.
80
00:03:36,160 --> 00:03:37,920
But here's the critical limitation.
81
00:03:37,920 --> 00:03:39,920
EOP does not sandbox unknown files.
82
00:03:39,920 --> 00:03:42,440
They can only catch threats that have already been identified.
83
00:03:42,440 --> 00:03:45,880
If a brand new piece of malware lands in your inbox that nobody has ever seen
84
00:03:45,880 --> 00:03:47,920
before, EOP has no signature for it.
85
00:03:47,920 --> 00:03:49,120
So that message gets delivered.
86
00:03:49,360 --> 00:03:52,600
Catching zero-day malware requires defender for Office 365,
87
00:03:52,600 --> 00:03:56,800
which detonates those unknown files in an isolated sandbox to see what they actually do.
88
00:03:56,800 --> 00:03:58,280
Let's make this concrete.
89
00:03:58,280 --> 00:04:01,640
Say someone sends you a PDF with an embedded macro that's known to be malicious.
90
00:04:01,640 --> 00:04:05,320
EOP recognizes that signature quarantines the message and you never see it.
91
00:04:05,320 --> 00:04:07,200
The malware never touches your computer.
92
00:04:07,200 --> 00:04:08,080
That's the good news.
93
00:04:08,080 --> 00:04:09,560
What happens to detected malware?
94
00:04:09,560 --> 00:04:11,760
The message gets quarantined or rejected entirely.
95
00:04:11,760 --> 00:04:13,120
It never reaches your inbox.
96
00:04:13,120 --> 00:04:16,480
There's a backup system called zero-hour autopage, ZAP for short.
97
00:04:17,040 --> 00:04:20,040
If a malicious attachment somehow gets delivered and then Microsoft's threat
98
00:04:20,040 --> 00:04:24,200
intelligence updates, ZAP can retroactively remove that message from your inbox.
99
00:04:24,200 --> 00:04:25,640
We'll cover ZAP in detail later.
100
00:04:25,640 --> 00:04:27,520
But for now, here's why this matters to you.
101
00:04:27,520 --> 00:04:30,200
Most ransomware starts as a malware-laden email.
102
00:04:30,200 --> 00:04:34,040
Someone opens an attachment and within minutes their entire company is locked out of
103
00:04:34,040 --> 00:04:34,560
its files.
104
00:04:34,560 --> 00:04:38,400
EOP catches the known stuff, which is still the vast majority of attacks.
105
00:04:38,400 --> 00:04:41,640
It won't stop everything, but it stops enough to make a real difference.
106
00:04:41,640 --> 00:04:43,680
Layer three, anti-fishing.
107
00:04:43,680 --> 00:04:46,120
So now we get to the layer that fools people the most.
108
00:04:46,400 --> 00:04:48,760
Fishing is different from spam and malware.
109
00:04:48,760 --> 00:04:49,760
It's not about code.
110
00:04:49,760 --> 00:04:53,440
It's about trickery, fake login pages that look identical to the real thing,
111
00:04:53,440 --> 00:04:55,880
urgent requests that demand immediate action.
112
00:04:55,880 --> 00:04:58,160
Sender addresses that are slightly misspelled,
113
00:04:58,160 --> 00:05:00,720
Microsoft and Com instead of Microsoft.com.
114
00:05:00,720 --> 00:05:03,120
This is social engineering, not a technical exploit.
115
00:05:03,120 --> 00:05:05,360
So what does EOP actually do against fishing?
116
00:05:05,360 --> 00:05:06,280
Three main things.
117
00:05:06,280 --> 00:05:07,800
First, spoof intelligence.
118
00:05:07,800 --> 00:05:10,760
EOP checks whether the senders address has been forged.
119
00:05:10,760 --> 00:05:14,680
If an email claims to be from your bank, but the underlying authentication fails,
120
00:05:14,680 --> 00:05:15,920
EOP flags it.
121
00:05:16,320 --> 00:05:18,840
Second, it verifies email authentication protocols.
122
00:05:18,840 --> 00:05:20,680
That's SPF, decam and demarc.
123
00:05:20,680 --> 00:05:24,600
These are technical records in DNS that confirm the sender is allowed to use a domain.
124
00:05:24,600 --> 00:05:28,680
Third, it uses machine learning models that look at sender behavior patterns
125
00:05:28,680 --> 00:05:30,040
to spot anything suspicious.
126
00:05:30,040 --> 00:05:31,920
But here's what EOP does not do.
127
00:05:31,920 --> 00:05:34,200
It does not detect impersonation of specific people.
128
00:05:34,200 --> 00:05:37,080
So if an email looks like it's from your CEO asking for gift cards,
129
00:05:37,080 --> 00:05:39,040
EOP probably won't see that as dangerous.
130
00:05:39,040 --> 00:05:41,840
It can't learn who your executives are and protect them directly.
131
00:05:41,840 --> 00:05:43,960
That requires defender for Office 365.
132
00:05:43,960 --> 00:05:45,600
It also doesn't scan links at click time.
133
00:05:45,800 --> 00:05:49,760
If a link in an email looks clean when it arrives, but turns malicious two hours later,
134
00:05:49,760 --> 00:05:51,560
EOP won't catch it.
135
00:05:51,560 --> 00:05:52,800
Let's use an example.
136
00:05:52,800 --> 00:05:55,120
You get an email that appears to be from your boss.
137
00:05:55,120 --> 00:05:57,080
The display name says Sarah Johnson.
138
00:05:57,080 --> 00:05:59,840
The message says she needs you to buy gift cards for a client,
139
00:05:59,840 --> 00:06:01,840
but the actual sender address is Sarah.
140
00:06:01,840 --> 00:06:03,280
chasehanson@gmail.com.
141
00:06:03,280 --> 00:06:04,680
A zero instead of an O.
142
00:06:04,680 --> 00:06:08,720
EOP might flag this of the domain looks suspicious or if authentication fails,
143
00:06:08,720 --> 00:06:11,960
but it won't recognize that Sarah Johnson is your actual boss.
144
00:06:11,960 --> 00:06:13,880
And this is a targeted impersonation attack.
145
00:06:13,880 --> 00:06:14,920
That's a big gap.
146
00:06:14,960 --> 00:06:16,200
And this is where D mark comes in.
147
00:06:16,200 --> 00:06:21,440
D mark is a DNS record that tells receiving mail servers what to do with emails that fail authentication.
148
00:06:21,440 --> 00:06:24,120
If you publish a strict D mark policy for your domain,
149
00:06:24,120 --> 00:06:27,800
it becomes much harder for attackers to spoof your company's email addresses.
150
00:06:27,800 --> 00:06:32,000
EOP uses D mark information when it's available, but it can't enforce it for you.
151
00:06:32,000 --> 00:06:33,280
You have to set it up yourself.
152
00:06:33,280 --> 00:06:34,760
That's why user awareness matters.
153
00:06:34,760 --> 00:06:38,520
Even with EOP, some fishing emails will get through, especially the targeted ones.
154
00:06:38,520 --> 00:06:43,720
EOP can add safety tips to emails like a warning that says this sender is not verified,
155
00:06:44,080 --> 00:06:45,320
but those have to be enabled.
156
00:06:45,320 --> 00:06:46,360
So here's the takeaway.
157
00:06:46,360 --> 00:06:48,920
Classics, bam filtering can't stop social engineering.
158
00:06:48,920 --> 00:06:52,440
EOP's anti-fishing blocks a lot of basic fishing, but it has clear limits.
159
00:06:52,440 --> 00:06:55,320
And those limits are exactly where attackers focus their efforts.
160
00:06:55,320 --> 00:06:59,000
The retroactive safety net zero hour auto purge.
161
00:06:59,000 --> 00:07:03,400
So what happens when a bad email slips through those three layers, it will no filter is perfect.
162
00:07:03,400 --> 00:07:05,400
That's where zero hour auto purge comes in.
163
00:07:05,400 --> 00:07:07,640
Zap for short, this is EOP's safety net.
164
00:07:07,640 --> 00:07:08,520
Here's how it works.
165
00:07:08,520 --> 00:07:12,000
Zap continuously scans messages that were already delivered to inboxes.
166
00:07:12,000 --> 00:07:15,840
If Microsoft's threat intelligence updates in a new verdict comes in,
167
00:07:15,840 --> 00:07:19,600
say a message that looked clean two hours ago is now flagged as malware.
168
00:07:19,600 --> 00:07:21,640
Zap automatically removes it.
169
00:07:21,640 --> 00:07:23,920
No one has to push a button, it just happens.
170
00:07:23,920 --> 00:07:26,280
The window is 48 hours from delivery.
171
00:07:26,280 --> 00:07:29,480
That might not sound like a lot, but it covers most delayed detections.
172
00:07:29,480 --> 00:07:33,160
Attackers often use tricks where a file or link is benign when it arrives,
173
00:07:33,160 --> 00:07:35,080
then turns malicious hours later.
174
00:07:35,080 --> 00:07:36,320
Zap catches that shift.
175
00:07:36,320 --> 00:07:39,560
It covers spam, fishing, high confidence fishing, and malware.
176
00:07:39,560 --> 00:07:42,960
Each verdict triggers a different action based on your existing policies,
177
00:07:42,960 --> 00:07:45,680
usually moving the message to quarantine or the junk folder.
178
00:07:45,680 --> 00:07:50,360
Now here's something new, as of early 2026, Zap expanded to two additional places.
179
00:07:50,360 --> 00:07:52,600
First, Microsoft Teams chat messages.
180
00:07:52,600 --> 00:07:55,680
If a malicious link or file gets shared in a Teams chat,
181
00:07:55,680 --> 00:07:59,000
Zap can retroactively remove it for everyone in that conversation.
182
00:07:59,000 --> 00:08:00,640
Second, the deleted items folder.
183
00:08:00,640 --> 00:08:01,800
This one matters a lot.
184
00:08:01,800 --> 00:08:06,520
Previously, if a user deleted a malicious email themselves, Zap wouldn't touch it.
185
00:08:06,520 --> 00:08:08,440
It was already gone, but here's the problem.
186
00:08:08,440 --> 00:08:10,320
Deleted items can be restored.
187
00:08:10,320 --> 00:08:13,240
So now Zap scans the deleted items folder too.
188
00:08:13,240 --> 00:08:15,320
If it finds something dangerous at quarantines at there,
189
00:08:15,320 --> 00:08:18,720
that means even emails users threw away thinking they were harmless get cleaned up.
190
00:08:18,720 --> 00:08:21,360
And here's the best part, no admin action needed.
191
00:08:21,360 --> 00:08:25,160
Zap is enabled by default for every single exchange online mailbox.
192
00:08:25,160 --> 00:08:26,000
You didn't turn it on.
193
00:08:26,000 --> 00:08:27,760
It was just there from day one.
194
00:08:27,760 --> 00:08:29,200
Let me give you a concrete example.
195
00:08:29,200 --> 00:08:32,920
Say a malicious PDF gets through your initial filters because it's a brand new variant.
196
00:08:32,920 --> 00:08:35,520
No signature exists for it yet, so it lands in your inbox.
197
00:08:35,520 --> 00:08:38,280
Two hours later, Microsoft's threat intelligence team
198
00:08:38,280 --> 00:08:39,720
updates their signatures.
199
00:08:39,720 --> 00:08:42,000
They've now identified that file as dangerous.
200
00:08:42,000 --> 00:08:45,760
Zap scans your inbox, finds that email and moves it to quarantine.
201
00:08:45,760 --> 00:08:46,680
Silently.
202
00:08:46,680 --> 00:08:47,760
You never knew it was there.
203
00:08:47,760 --> 00:08:48,840
You never clicked it.
204
00:08:48,840 --> 00:08:51,400
And by the time you check your email later, it's already gone.
205
00:08:51,400 --> 00:08:52,600
What does the user see?
206
00:08:52,600 --> 00:08:54,160
The email disappears from their inbox.
207
00:08:54,160 --> 00:08:57,920
They might get a quarantine notification depending on how their admin set things up.
208
00:08:57,920 --> 00:08:59,440
But most of the time it's invisible.
209
00:08:59,440 --> 00:09:00,640
The threat just vanishes.
210
00:09:00,640 --> 00:09:01,440
Why does this matter?
211
00:09:01,440 --> 00:09:03,080
Because a tag detection isn't instant.
212
00:09:03,080 --> 00:09:06,920
There's always a gap between when a threat arrives and when it gets identified.
213
00:09:06,920 --> 00:09:08,360
Zap covers that gap.
214
00:09:08,360 --> 00:09:12,640
It's the safety net underneath everything else and it works for every single EOP customer,
215
00:09:12,640 --> 00:09:16,080
whether you're a solo freelancer or a thousand person company.
216
00:09:16,080 --> 00:09:17,520
The limits of EOP.
217
00:09:17,520 --> 00:09:22,000
So Zap is great at catching what slips through, but it has limits and so does EOP overall.
218
00:09:22,000 --> 00:09:25,200
Let's be straight about what this free layer can and can't do.
219
00:09:25,200 --> 00:09:27,240
EOP handles volume filtering really well.
220
00:09:27,240 --> 00:09:31,200
Commodity spam, known malware, basic phishing, it blocks that stuff at scale.
221
00:09:31,200 --> 00:09:35,360
Microsoft's own SLA says it catches over 99% of spam with a false positive rate below
222
00:09:35,360 --> 00:09:37,680
1 in 250,000.
223
00:09:37,680 --> 00:09:41,680
Those are solid numbers for everyday threats, but for targeted sophisticated attacks, EOP
224
00:09:41,680 --> 00:09:42,680
isn't enough.
225
00:09:42,680 --> 00:09:43,680
Here's where it falls short.
226
00:09:43,680 --> 00:09:44,840
No sandbox detonation.
227
00:09:44,840 --> 00:09:49,360
If an attachment is brand new and nobody has ever seen it, EOP can't open it in a safe
228
00:09:49,360 --> 00:09:50,880
environment to see what it does.
229
00:09:50,880 --> 00:09:52,960
It just delivers the message and hopes for the best.
230
00:09:52,960 --> 00:09:55,160
That's a big gap, no real-time link scanning.
231
00:09:55,160 --> 00:09:58,960
EOP checks URLs when the email arrives, but it doesn't check them again when you click.
232
00:09:58,960 --> 00:09:59,960
Attackers know this trick.
233
00:09:59,960 --> 00:10:04,000
They send a clean link, wait for it to pass inspection, then flip it to malicious after delivery.
234
00:10:04,000 --> 00:10:05,320
EOP won't catch that.
235
00:10:05,320 --> 00:10:06,800
No impersonation protection.
236
00:10:06,800 --> 00:10:11,800
EOP can detect spoofed domains like Microsoft, comments that of Microsoft.com, but it can't
237
00:10:11,800 --> 00:10:15,560
learn who your CEO is and flag emails pretending to be them.
238
00:10:15,560 --> 00:10:19,520
That's a completely different level of detection, and no automated investigation or response.
239
00:10:19,520 --> 00:10:23,560
If a threat does get through, EOP can't hunt for it across your environment, find other
240
00:10:23,560 --> 00:10:26,440
affected users, or automatically clean things up.
241
00:10:26,440 --> 00:10:28,080
That requires Defender Plan 2.
242
00:10:28,080 --> 00:10:30,200
Now look at the real threat landscape right now.
243
00:10:30,200 --> 00:10:35,040
Recent research shows 50% of attacks can bypass endpoint-only defenses entirely.
244
00:10:35,040 --> 00:10:39,000
When phishing as a service kits are making sophisticated attacks cheap and accessible, for a few
245
00:10:39,000 --> 00:10:41,880
hundred dollars, criminals can buy a complete phishing kit.
246
00:10:41,880 --> 00:10:44,680
Fake websites, email templates, even tech support.
247
00:10:44,680 --> 00:10:47,880
This isn't scriptkitties anymore, it's organized crime with a subscription model.
248
00:10:47,880 --> 00:10:49,120
Here's a real example.
249
00:10:49,120 --> 00:10:53,400
Say an attacker sends a zero-day malware sample hidden inside a password protected archive.
250
00:10:53,400 --> 00:10:54,920
EOP can't open that archive.
251
00:10:54,920 --> 00:10:56,880
It has no way to inspect the contents.
252
00:10:56,880 --> 00:10:58,200
The message gets delivered.
253
00:10:58,200 --> 00:11:02,680
But Defender for Office 365, it can detonate that file in an isolated sandbox, enter
254
00:11:02,680 --> 00:11:05,880
the password and see exactly what the malware does.
255
00:11:05,880 --> 00:11:07,120
That's the difference.
256
00:11:07,120 --> 00:11:08,640
The real world impact is serious.
257
00:11:08,640 --> 00:11:12,640
A business running only EOP is vulnerable to business email compromise.
258
00:11:12,640 --> 00:11:17,760
BEC attacks where someone impersonates an executive and tricks an employee into wiring money
259
00:11:17,760 --> 00:11:19,440
or sharing sensitive data.
260
00:11:19,440 --> 00:11:20,800
These attacks don't use malware.
261
00:11:20,800 --> 00:11:22,080
They use psychology.
262
00:11:22,080 --> 00:11:25,040
And EOP has no defense against that, but here's the good news.
263
00:11:25,040 --> 00:11:28,160
EOP still stops the vast majority of commodity attacks.
264
00:11:28,160 --> 00:11:32,280
The drive-by phishing, the mass market ransomware, the obvious spam it all gets filtered before
265
00:11:32,280 --> 00:11:33,280
you ever see it.
266
00:11:33,280 --> 00:11:36,360
For the average small business, EOP is a solid foundation.
267
00:11:36,360 --> 00:11:37,920
It's just not the whole house.
268
00:11:37,920 --> 00:11:41,360
When you need Defender for Office 365, so when do you need to upgrade?
269
00:11:41,360 --> 00:11:46,120
Let's talk about Defender for Office 365 because this is where EOP's gaps get filled.
270
00:11:46,120 --> 00:11:48,840
Defender plan one runs about $2 per user per month.
271
00:11:48,840 --> 00:11:53,000
It's included in Microsoft 365 Business Premium and E5 subscriptions.
272
00:11:53,000 --> 00:11:57,160
And as of August 2026, Microsoft is rolling it into E3 as well, so if you're on E3 check
273
00:11:57,160 --> 00:11:59,600
your licensing because you might already have it.
274
00:11:59,600 --> 00:12:00,840
What does plan one add?
275
00:12:00,840 --> 00:12:02,000
Three big things.
276
00:12:02,000 --> 00:12:03,000
Safe attachments.
277
00:12:03,000 --> 00:12:05,480
This is the sandbox detonation we talked about earlier.
278
00:12:05,480 --> 00:12:09,320
When an unknown file arrives, Defender opens it in an isolated environment and watches
279
00:12:09,320 --> 00:12:10,320
what it does.
280
00:12:10,320 --> 00:12:14,000
If it tries to encrypt files or phone home to a command server, Defender catches it and
281
00:12:14,000 --> 00:12:15,000
blocks delivery.
282
00:12:15,000 --> 00:12:16,000
EOP can't do that.
283
00:12:16,000 --> 00:12:17,000
Safe links.
284
00:12:17,000 --> 00:12:20,480
This scans every URL at the moment you click it, not just when the email arrives.
285
00:12:20,480 --> 00:12:25,000
If a link was clean at delivery but turns malicious two hours later, Safe links catches it.
286
00:12:25,000 --> 00:12:27,000
It blocks the page before you ever see it.
287
00:12:27,000 --> 00:12:29,720
This closes the time gap that attackers love to exploit.
288
00:12:29,720 --> 00:12:31,680
Impersonation protection.
289
00:12:31,680 --> 00:12:36,400
Defender learns who your executives are, your CEO, your CFO, your HR director.
290
00:12:36,400 --> 00:12:39,320
It builds a relationship map of who they normally email.
291
00:12:39,320 --> 00:12:43,040
Then when a message arrives pretending to be one of them, Defender flags it, even if
292
00:12:43,040 --> 00:12:46,280
the sending domain passes all authentication checks.
293
00:12:46,280 --> 00:12:50,800
That's the difference between catching a spoofed domain and catching a targeted CEO fraud attempt.
294
00:12:50,800 --> 00:12:52,120
Now there's Defender plan two.
295
00:12:52,120 --> 00:12:55,000
That's about $5 per user per month, included in E5.
296
00:12:55,000 --> 00:12:57,600
Plan two adds investigation and response capabilities.
297
00:12:57,600 --> 00:13:00,840
Threat Explorer gives you 30 days of detailed message to let me know.
298
00:13:00,840 --> 00:13:05,400
You can answer questions like who else received this phishing email and who clicked the link
299
00:13:05,400 --> 00:13:07,000
in minutes instead of hours.
300
00:13:07,000 --> 00:13:13,160
An automated investigation and response, AIR runs playbooks automatically when a user reports
301
00:13:13,160 --> 00:13:14,160
phishing.
302
00:13:14,160 --> 00:13:18,840
It finds all affected recipients, evaluates clicks and queues remediation for approval that
303
00:13:18,840 --> 00:13:21,040
can reduce dwell time from days to minutes.
304
00:13:21,040 --> 00:13:22,040
So how do you decide?
305
00:13:22,040 --> 00:13:23,600
Here's a practical guide.
306
00:13:23,600 --> 00:13:28,480
If you're a small business in a low-risk industry with basic needs, EOP might be sufficient.
307
00:13:28,480 --> 00:13:30,800
But seriously consider Defender plan one anyway.
308
00:13:30,800 --> 00:13:33,640
The cost is tiny compared to what are single-breach costs.
309
00:13:33,640 --> 00:13:38,000
If your business has executives who are visible targets and let's be honest, most do, Defender
310
00:13:38,000 --> 00:13:39,960
plan one is almost mandatory.
311
00:13:39,960 --> 00:13:43,800
Business email compromise attacks target the people with authority to move money or approve
312
00:13:43,800 --> 00:13:44,800
payments.
313
00:13:44,800 --> 00:13:46,080
EOP alone won't stop them.
314
00:13:46,080 --> 00:13:49,640
If you have regulatory requirements or handle high volumes of sensitive email, consider
315
00:13:49,640 --> 00:13:50,720
plan two.
316
00:13:50,720 --> 00:13:53,480
The automation and hunting capabilities make a real difference when you need to prove
317
00:13:53,480 --> 00:13:55,000
compliance and respond quickly.
318
00:13:55,000 --> 00:13:56,000
Here's a real example.
319
00:13:56,000 --> 00:13:58,680
A 50-person company fell for a fake invoice last year.
320
00:13:58,680 --> 00:14:02,120
An email that looked exactly like the Avengers Standard Billing format.
321
00:14:02,120 --> 00:14:03,440
The finance team paid it.
322
00:14:03,440 --> 00:14:04,960
$20,000 gone.
323
00:14:04,960 --> 00:14:08,520
Defender's impersonation protection would have caught that email because it recognized
324
00:14:08,520 --> 00:14:10,040
the vendor domain was slightly off.
325
00:14:10,040 --> 00:14:11,800
EOP alone didn't flag it.
326
00:14:11,800 --> 00:14:12,800
And here's the thing.
327
00:14:12,800 --> 00:14:17,520
The cost of a breach lost data, ransomware payouts, reputation damage, customer trust.
328
00:14:17,520 --> 00:14:20,240
Dwarfs the per-user cost of Defender by orders of magnitude.
329
00:14:20,240 --> 00:14:23,120
$2 per user per month is less than a cup of coffee.
330
00:14:23,120 --> 00:14:26,440
A single ransomware attack can cost hundreds of thousands.
331
00:14:26,440 --> 00:14:27,680
How it all fits together.
332
00:14:27,680 --> 00:14:30,360
So here's how these pieces actually connect.
333
00:14:30,360 --> 00:14:31,960
That's where the real understanding comes from.
334
00:14:31,960 --> 00:14:33,240
EOP is the base layer.
335
00:14:33,240 --> 00:14:38,360
It's always on, handles the bulk filtering, and stops about 99% of the noise before it ever
336
00:14:38,360 --> 00:14:39,360
reaches you.
337
00:14:39,360 --> 00:14:41,280
That's the foundation.
338
00:14:41,280 --> 00:14:43,720
Defender plan one adds the smart layer on top.
339
00:14:43,720 --> 00:14:48,040
Real-time link scanning, sandbox analysis for attachments, impersonation detection.
340
00:14:48,040 --> 00:14:50,360
This is where those targeted attacks get caught.
341
00:14:50,360 --> 00:14:53,800
Defender plan two sits above that with investigation and automation.
342
00:14:53,800 --> 00:14:56,600
Threat hunting automated response campaign correlation.
343
00:14:56,600 --> 00:14:59,720
This takes you from reactive cleanup to proactive defense.
344
00:14:59,720 --> 00:15:02,480
Together they form Microsoft's email security stack.
345
00:15:02,480 --> 00:15:03,960
And here's the important point.
346
00:15:03,960 --> 00:15:05,840
They're not three separate tools.
347
00:15:05,840 --> 00:15:07,560
It's one system with three tiers.
348
00:15:07,560 --> 00:15:10,840
You buy what you need and the integration is already built in.
349
00:15:10,840 --> 00:15:12,320
Remember the office building analogy.
350
00:15:12,320 --> 00:15:15,640
EOP is the front gate security guard checking IDs.
351
00:15:15,640 --> 00:15:18,920
Defender plan one is the security cameras and badge readers inside.
352
00:15:18,920 --> 00:15:21,360
Watching what people do after they get through the door.
353
00:15:21,360 --> 00:15:25,480
Defender plan two is the security operations center monitoring everything, connecting signals
354
00:15:25,480 --> 00:15:27,400
and dispatching response.
355
00:15:27,400 --> 00:15:29,600
Integration matters because the pieces talk to each other.
356
00:15:29,600 --> 00:15:33,320
When a user reports a fishing email, Defender automatically connects that report with other
357
00:15:33,320 --> 00:15:34,640
signals across the stack.
358
00:15:34,640 --> 00:15:37,080
It checks if the same sender targeted other users.
359
00:15:37,080 --> 00:15:39,400
It looks for similar patterns in email traffic.
360
00:15:39,400 --> 00:15:42,560
It connects dots that a human analyst would take hours to find.
361
00:15:42,560 --> 00:15:44,480
And Zap works across all layers.
362
00:15:44,480 --> 00:15:49,000
Whether a verdict comes from EOP's signature database or Defender sandbox analysis,
363
00:15:49,000 --> 00:15:53,040
if the determination changes after delivery, Zap removes that message retroactively.
364
00:15:53,040 --> 00:15:55,760
It's the common safety net underneath everything.
365
00:15:55,760 --> 00:15:57,240
Here's the real knowledge nugget.
366
00:15:57,240 --> 00:16:00,400
Email security isn't a single product you buy and forget about.
367
00:16:00,400 --> 00:16:02,680
It's layers that build on each other.
368
00:16:02,680 --> 00:16:06,560
Buy what you need but understand the gaps because the gaps are exactly where attackers are
369
00:16:06,560 --> 00:16:08,040
looking.
370
00:16:08,040 --> 00:16:09,520
So what should you do now?
371
00:16:09,520 --> 00:16:10,520
Start with something free.
372
00:16:10,520 --> 00:16:13,680
Check that your domain has a DMR record published in DNS.
373
00:16:13,680 --> 00:16:17,320
That alone improves EOP's effectiveness against spoofing attacks.
374
00:16:17,320 --> 00:16:22,200
Second, if your organization deals with sensitive data or has visible executives, trial defender
375
00:16:22,200 --> 00:16:25,680
plan one, the cost is small and the protection is significant.
376
00:16:25,680 --> 00:16:27,680
And remember, no tool catches everything.
377
00:16:27,680 --> 00:16:28,920
Train your users to spot fishing.
378
00:16:28,920 --> 00:16:30,440
They're the last line of defense.
379
00:16:30,440 --> 00:16:34,280
Hit subscribe for more plain English breakdowns of Microsoft security and drop a comment
380
00:16:34,280 --> 00:16:35,280
if this helped.