0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:40
Guided Lab
1:40–1:50
Bonus
1:50–2:00
Debrief
0:00 – 0:10 Recap · 10 min

Day 2 review & the threat landscape

0:10 – 0:40 Lecture · 30 min

EOP, Defender for Office 365, and the email protection stack

Microsoft's email protection has two layers. Students need to understand both before configuring either.

SettingWhat it controlsRecommended value
Spam confidence level (SCL)Threshold at which mail is classified as spam — lower = more aggressive filteringDefault (5) for most orgs; tune based on false positives
Spam actionWhat happens to messages classified as spam: Move to Junk, Quarantine, or DeleteMove to Junk Email folder for most; Quarantine for high-confidence spam
Bulk email threshold (BCL)Threshold for bulk/marketing mail — lower = more aggressive6 is a reasonable starting point
Safe sender / blocked sender listsPer-policy allow and block lists that override spam filteringAvoid over-populating — every safe-sender entry is a bypass of all filtering
Quarantine policyControls what users can do with their quarantined messages — release, delete, reportAllow users to release non-high-confidence spam; require admin approval for high-confidence
Instructor note: The EOP vs Defender distinction matters operationally. EOP is always on — it cannot be turned off. Defender for Office 365 adds on top but does not replace EOP. Anti-spam and anti-malware settings live in EOP. Safe Attachments and Safe Links are Defender-only. Both are configured in the same portal (security.microsoft.com) which makes them easy to conflate.
0:40 – 1:40 Guided lab · 60 min

Lab 3-C: Configuring email protection for Lakeview Logistics

Students configure anti-spam, anti-phishing, Safe Attachments, Safe Links, and quarantine policies — building a complete email hygiene stack for Lakeview Logistics. Everything is fully functional on Business Standard.

Policy precedence note: When multiple anti-spam or anti-phishing policies apply to the same user, the policy with the lowest priority number wins. The default policy always has the highest priority number (lowest precedence) — it catches anything not covered by custom policies. Custom policies like the executive protection policy created in Step 3 will always take precedence over the default.
Instructor note: Safe Attachments Dynamic Delivery is the best user-experience choice for most orgs — users get the email body immediately while the attachment scans. The alternative (Block) holds the entire message until scanning completes. Worth demonstrating what the placeholder attachment looks like in the inbox so students understand what end users experience while the scan runs.
1:40 – 1:50 Bonus material · 10 min

⭐ Bonus: Threat Explorer & attack simulation

⭐ Bonus A — Threat Explorer
  • Navigate to security.microsoft.comEmail & collaboration → Explorer
  • Explore the All email view — filter by date, sender domain, and detection technology
  • Switch to the Phish view — note what metadata is captured for detected phishing attempts
  • In your Lab Journal: describe three specific pieces of information Threat Explorer captures that Message Trace does not, and explain when you would use Explorer vs Message Trace to investigate a reported phishing email
⭐ Bonus B — Attack Simulation Training (preview)
  • Navigate to security.microsoft.comEmail & collaboration → Attack simulation training
  • Browse the available simulation techniques — credential harvest, malware attachment, link in attachment, drive-by URL, OAuth consent grant
  • Click into any simulation to see the configuration options — do not launch a simulation, but document: what user actions does this simulation test, what payload would the target user see, and what training is assigned to users who click?
  • In your Lab Journal: explain the value of phishing simulation training in an organisation and why sending a simulated phishing email is more effective than telling staff "don't click phishing links"
1:50 – 2:00 Debrief · 10 min

Reflection & preview

Learning outcomes — by end of Day 3, students can…
Distinguish EOP from DefenderDescribe the two-layer protection model and which features belong to each layer
Tune anti-spam policiesAdjust BCL, spam actions, and quarantine settings in the default inbound policy
Create anti-phishing policiesConfigure impersonation protection for specific users and domains with mailbox intelligence
Configure Safe AttachmentsDeploy Dynamic Delivery mode and enable protection for SharePoint, OneDrive, and Teams
Configure Safe LinksEnable time-of-click URL scanning with click-through blocking for email and internal mail
Manage quarantineNavigate the quarantine centre and complete the DMARC reporting mailbox setup
What you need ready
Microsoft Defender portal accessible (security.microsoft.com) All 10 users from Lab 1-C confirmed active Slide deck: EOP vs Defender for Office 365 Lab 3-C step sheet
Day 4 →Course Outline