Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Mastering Microsoft 365 Defender

You're reading from  Mastering Microsoft 365 Defender

Product type Book
Published in Jul 2023
Publisher Packt
ISBN-13 9781803241708
Pages 572 pages
Edition 1st Edition
Languages
Authors (2):
Ru Campbell Ru Campbell
Profile icon Ru Campbell
Viktor Hedberg Viktor Hedberg
Profile icon Viktor Hedberg
View More author details

Table of Contents (33) Chapters

Preface 1. Part 1: Cyber Threats and Microsoft 365 Defender
2. Chapter 1: Microsoft and Modern Cybersecurity Threats 3. Chapter 2: Microsoft 365 Defender: The Big Picture 4. Part 2: Microsoft Defender for Endpoint
5. Chapter 3: The Fundamentals of Microsoft Defender for Endpoint 6. Chapter 4: Onboarding Windows Clients and Servers 7. Chapter 5: Getting Started with Microsoft Defender Antivirus for Windows 8. Chapter 6: Advanced Microsoft Defender Antivirus for Windows 9. Chapter 7: Managing Attack Surface Reduction for Windows 10. Chapter 8: Managing Additional Capabilities for Windows 11. Chapter 9: Onboarding and Managing macOS 12. Chapter 10: Onboarding and Managing Linux Servers 13. Chapter 11: Onboarding and Managing iOS and Android 14. Part 3: Microsoft Defender for Identity
15. Chapter 12: Deploying Microsoft Defender for Identity 16. Chapter 13: Managing Defender for Identity 17. Part 4: Microsoft Defender for Office 365
18. Chapter 14: Deploying Exchange Online Protection 19. Chapter 15: Deploying Defender for Office 365 20. Part 5: Microsoft Defender for Cloud Apps
21. Chapter 16: Implementing and Managing Microsoft Defender for Cloud Apps 22. Part 6: Proactive Security and Incident Response
23. Chapter 17: Maintaining Security Hygiene and Threat Awareness 24. Chapter 18: Extended Detection and Response with Microsoft 365 Defender 25. Chapter 19: Advanced Hunting with KQL 26. Chapter 20: Microsoft Sentinel Integration 27. Chapter 21: Understanding Microsoft 365 Defender APIs 28. Part 7: Glossary and Answers
29. Chapter 22: Glossary
30. Chapter 23: Answers 31. Index 32. Other Books You May Enjoy

Deploying Exchange Online Protection

As you can probably tell from the title, this chapter is all about deploying Exchange Online Protection (EOP) within your Microsoft 365 environment. We will cover key aspects of the deployment process, including managing spam and malware protection policies. Email security is something that, even in 2023, is of critical importance; phishing or malware delivered by email are still very common attack vectors when it comes to user or even domain compromises, and EOP can help with this. As such, by following the instructions in this chapter, organizations can effectively deploy EOP and ensure secure and reliable email communication. In a nutshell, we will cover these main topics throughout the chapter:

  • Why is EOP important?
  • What is EOP?
  • How to deploy EOP?

To successfully follow the guides provided in this chapter, you will need to have an account with either Global Administrator or Security Administrator in a Microsoft 365 tenant...

Understanding the importance of EOP

EOP is a cloud-powered email filtering solution from Microsoft. It is designed to safeguard your organization against various email-based threats such as spam, malware, and other security risks. It is the first line of defense when it comes to email-based threats, and it is of utmost importance that your organization has a solution for those threats.

This is not to say that EOP is better at its job than any of the competitors, but as we have seen throughout this book, the Microsoft 365 Defender components and features tie into one another well, and they offer more insights into the current situation when it comes to threats than if you were to use another solution from a third party vendor.

The following diagram shows what capabilities are available in Defender for Office 365. EOP covers the Prevention and Detection aspects:

Figure 14.1 – Capabilities of Microsoft 365 Defender for Office 365

Figure 14.1 – Capabilities of Microsoft 365 Defender for Office 365

Understanding how EOP works

As mentioned previously, EOP is an important part of the security in Microsoft 365 when it comes to detecting and stopping malicious emails from landing in your users’ mailboxes. It is one of the core features in Defender for Office 365 and provides the backbone of your email security.

To understand the way EOP works, we can look at the following diagram and see how it would process an inbound email:

Figure 14.2 – How EOP processes an inbound email

Figure 14.2 – How EOP processes an inbound email

This process can be described as follows:

  1. The inbound email first passes through the connection filtering phase of EOP. This verifies the sender’s reputation, and if the message is caught here, it is most likely spam.
  2. The message is then scanned for malware in the second phase of EOP. If malicious code is identified inside the message or any attachment to that message, the email will be delivered to quarantine, where, by default, only an administrator...

Deploying EOP

As stated earlier in this chapter, the feature is available in all Exchange Online licenses and is therefore already available as soon as the first license lands in the tenant. But that is not enough since the default values could mean that you are exposing your organization to more threats than you might want.

In the previous section, we took a look at how EOP can filter inbound email messages; all of these steps are configurable to provide even better email security in your organization. We will discuss these options in the following sections.

Managing the Allow/Block list in your tenant

The connection filtering part of EOP could produce a false positive, meaning that an email gets flagged as spam when it is a legitimate email. It might also not react to a specific email and fail to tag it as spam when it should. This calls for modifying the tenant Allow/Block list. To do this, we head to the Microsoft 365 Defender portal once more at https://security.microsoft...

Summary

EOP is a valuable resource for organizations looking to implement a reliable and secure email filtering solution. By following the steps outlined in this chapter, administrators can deploy EOP and configure its various features to protect their organization’s email communication from spam, malware, and other security threats. Overall, this chapter is a must-read for any organization seeking to improve the security and reliability of its email communication.

In the next chapter, we will cover how to configure the rest of the Defender for Office 365 suite, focusing on features such as more anti-phishing settings, safe links, and safe attachments.

Questions

To test your understanding of the content covered in this chapter, try out the following questions:

  1. In terms of security capabilities in Microsoft 365 Defender, what capabilities fall under EOP’s remit? Select all that apply:
    1. Anti-spam
    2. Anti-malware
    3. Basic anti-phishing
    4. Safe Links
  2. Can you use EOP if you are not running Exchange Online?
    1. Yes
    2. No
  3. Which page of Microsoft 365 Defender allows us to configure most of EOP’s settings?
    1. Explorer
    2. Threat Policies
    3. Configuration Management
    4. Threat Intelligence

Further reading

You may refer to the following link to expand your knowledge on the topics explored in this chapter:

https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/eop-about?view=o365-worldwide

lock icon The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft 365 Defender
Published in: Jul 2023 Publisher: Packt ISBN-13: 9781803241708
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}