0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:45
Lab 7-A
1:45–1:55
Bonus
1:55–2:00
Debrief
0:00 – 0:10Recap · 10 min

Week 6 close & the threat surface gap

0:10 – 0:40Lecture · 30 min

Defender for Microsoft 365 — the email and collaboration security layer

Defender for M365 sits in front of the collaboration workloads students have already configured. Every email, file, and link that passes through Exchange Online, SharePoint, OneDrive, and Teams is inspected before it reaches the user.

The email security stack — what sits where

External sender
Exchange Online Protection (EOP)
Anti-spam · Anti-malware · Spoof intelligence · Connection filtering
Included in all M365 plans
Safe Attachments
Detonates attachments in a sandbox before delivery
Requires Defender for M365
Safe Links
Rewrites URLs, checks at click-time
Requires Defender for M365
User inbox
Clean message delivered
(or quarantined)
Policy typeWhat it doesDefault policy exists?Where configured
Safe AttachmentsSandbox-detonates attachments before deliveryYes — Built-in protection (limited)security.microsoft.com → Email & collaboration → Policies & rules → Threat policies
Safe LinksRewrites and time-of-click-checks URLsYes — Built-in protection (limited)security.microsoft.com → Email & collaboration → Policies & rules → Threat policies
Anti-phishingImpersonation protection, mailbox intelligence, spoof intelligenceYes — Office 365 AntiPhish Defaultsecurity.microsoft.com → Email & collaboration → Policies & rules → Threat policies
Anti-malwareEOP-level malware scanning (separate from Safe Attachments)Yes — Defaultsecurity.microsoft.com → Email & collaboration → Policies & rules → Threat policies
Instructor note: The mail flow diagram is worth drawing on the board. The layered inspection model — EOP first, then Safe Attachments, then Safe Links, then delivery — is unintuitive to students who think of email as arriving all at once. The sandbox detonation step (Safe Attachments holds the attachment in a VM, watches what it does, then decides whether to deliver or quarantine) is the detail that makes threat protection feel real rather than abstract. 5 minutes on this before moving to policy configuration.
0:40 – 1:45Guided lab · 65 min

Lab 7-A: Configuring Defender for M365 threat policies

Students verify licence assignment, configure Safe Attachments with Dynamic Delivery, configure Safe Links with URL rewriting and Teams protection, harden the anti-phishing policy with impersonation protection for Lakeview Logistics VIPs, and investigate the tenant's email threat landscape in Threat Explorer.

Licence propagation takes time: After assigning Defender for M365 Plan 2 licences to users, it can take up to 30 minutes for Safe Attachments and Safe Links policies to begin applying. If policies appear configured but Threat Explorer shows no scanning data, this is normal for a new tenant — data populates as email flows.
Instructor note: Step 6 (Threat Explorer) is deliberately open-ended. New trial tenants won't have much real threat data — that's fine. The goal is navigational familiarity: students should be able to find a message, read its threat metadata, and describe the investigation workflow. The Lab Journal question about recalling Sarah Chen's phishing email is the most practically valuable exercise — it mirrors what an IT admin would actually do on a Monday morning after a weekend phishing attack.
1:45 – 1:55Bonus · 10 min

⭐ Bonus: Preset security policies and DMARC configuration

⭐ Bonus A — Apply a Standard preset security policy
  • Navigate to Threat policies → Preset security policies. Review what Standard protection and Strict protection include — these are Microsoft-managed bundles that apply EOP + Defender for M365 settings simultaneously
  • Apply Standard protection to all users in your domain. Note: this may override some settings you configured manually — review what the preset applies vs what your custom policies do
  • In your Lab Journal: what is the advantage of preset security policies over individual custom policies? What is the disadvantage? When would you use each in a production environment?
⭐ Bonus B — Verify DMARC, DKIM, and SPF for your domain
  • Navigate to security.microsoft.com → Email & collaboration → Policies & rules → Threat policies → Email authentication settings
  • Review the DKIM tab — confirm signing is enabled for your subdomain. If not, enable it and publish the CNAME records (Intune DNS from Week 1 connects here)
  • Use an external tool (mxtoolbox.com/dmarc) to check whether a DMARC record exists for your subdomain. If not, the Threat Explorer authentication column will show DMARC = none for all inbound mail
  • In your Lab Journal: explain what each of SPF, DKIM, and DMARC protects against and why all three are required for complete email authentication
1:55 – 2:00Debrief · 5 min

Reflection & preview

Learning outcomes — by end of Day 1, students can…

Explain the email security stackDescribe EOP, Safe Attachments, and Safe Links as distinct layers with different threat coverage
Configure Safe AttachmentsCreate a policy with Dynamic Delivery and SharePoint/Teams protection enabled
Configure Safe LinksCreate a policy with URL rewriting, click tracking, and Teams coverage
Harden anti-phishingAdd VIP impersonation protection and configure quarantine actions
Navigate Threat ExplorerFilter by threat type and read email metadata including authentication results
Describe an investigation workflowExplain how to find and recall a phishing email using Threat Explorer

What you need ready

E5 Security trial active (from Week 5) Defender for M365 Plan 2 licences assigned to all users security.microsoft.com accessible All 10 Lakeview Logistics user accounts active with mailboxes
Day 2 →Week 7 Overview