We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Anti-phishing policies
Microsoft 365 anti-phishing policies, UAE

Impersonation protection has to be told who your executives are. Nobody does it, and then the invoice fraud works.

Every cloud mailbox gets spoof intelligence, DMARC policy honouring and implicit email authentication. What Defender for Office 365 adds is impersonation protection for named senders and domains, mailbox intelligence, and adjustable phishing thresholds. All three require configuration, and in most tenants we review, none of them have been touched.

Book an anti-phishing policy reviewSee what each tier gives you
Microsoft 365 anti-phishing policy configuration for UAE organisations
  • Two tiersAll cloud mailboxes, then Defender for Office 365
  • Named sendersImpersonation protection must be configured
  • AdjustablePhishing email thresholds are a policy setting
  • Campaign ViewsCoordinated attacks analysed across the service
What is available

Seven controls, and the ones that stop invoice fraud need configuring.

Microsoft is direct about the reason this matters: with the growing complexity of attacks, it is even difficult for trained users to identify sophisticated phishing messages. The built-in security features for all cloud mailboxes and the additional features in Defender for Office 365 are how you stop relying on people spotting it.

Impersonation protection, for senders and domains you name

Defender for Office 365 anti-phishing policies configure impersonation protection settings for specific message senders and sender domains. The word doing the work is specific. Nothing protects your chief financial officer from being impersonated until somebody enters their name and address into the policy, and in most tenants we review that list is empty or years out of date.

Mailbox intelligence, which learns the sender relationships

Mailbox intelligence settings are configured in the same Defender for Office 365 anti-phishing policy. Rather than matching a static list, this considers who a recipient normally corresponds with, which is how a message from a supplier address that has never written to this person before becomes suspicious without anybody having to predict it in advance.

Adjustable phishing email thresholds

The published policy settings include adjustable phishing email thresholds, which control how aggressive the detection is. That is a real dial with a real trade, and it is a decision rather than a default. Organisations under active business email compromise pressure generally want it higher than the tenant they inherited was configured for.

Spoof intelligence, available to every cloud mailbox

The spoof intelligence insight reviews detected spoofed senders in messages from external and internal domains and lets you manually allow or block them. Anti-phishing policies for all cloud mailboxes turn spoof intelligence on or off, turn unauthenticated sender indicators in Outlook on or off, and specify the action taken for blocked spoofed senders.

Honouring the sender DMARC policy

A setting that controls what happens to messages where the sender fails explicit DMARC checks and their DMARC policy is set to quarantine or reject. That is the difference between respecting what a legitimate sender has asked the world to do with forgeries of their domain, and quietly overriding it, and it is a configuration choice most organisations have never consciously made.

Campaign Views, which show the pattern rather than the message

Microsoft describes machine learning and other heuristics identifying and analysing messages involved in coordinated phishing attacks against the entire service and your organisation. That changes an investigation from one reported message into a view of the campaign it belongs to, including who else received it and what the sending pattern looks like.

Implicit email authentication, on top of the records

Microsoft enhances standard authentication checks for inbound email, meaning sender policy framework, domain keys identified mail and DMARC, with sender reputation, sender history, recipient history, behavioural analysis and other advanced techniques to identify forged senders. Your own authentication records still matter, but the platform is not relying on them alone.

The gap that produces the loss

Business email compromise uses forged trusted senders. Impersonation protection is off unless you filled it in.

Microsoft defines the attack precisely, and the control that addresses it is the one that requires the most manual input.

  • Quoted: business email compromise uses forged trusted senders, naming financial officers, customers and trusted partners, to trick recipients into approving payments, transferring funds, or revealing customer data.
  • The corresponding control is impersonation protection, configured in a Defender for Office 365 anti-phishing policy for specific message senders and sender domains. It protects the people and domains you list, and only those.
  • That list needs your executives, your finance team, your board, and the domains of your most significant customers and suppliers. It also needs maintaining, because people join, leave and change roles, and a list built during a project in 2023 protects a leadership team that has since changed.
  • The impersonation insight then shows details about detected impersonation attempts, which is both an operational tool and the evidence that the configuration is doing something. An empty insight in an organisation that receives payment instructions by email usually means the policy is empty, not that nobody is trying.
Ask us to review your impersonation list
How we approach it

Four things an anti-phishing review finds in almost every tenant.

This is a short engagement with a disproportionate return, because the controls are already licensed and the gaps are consistent across organisations of very different sizes.

The impersonation list is empty, or it protects people who left

Impersonation protection covers the specific senders and sender domains you configure. In most tenants that list is either empty or was populated once during a deployment project. Rebuilding it around the current leadership team, the finance function, and the customer and supplier domains that actually appear in payment conversations takes an afternoon.

The phishing thresholds were never a decision

They are adjustable, which means somebody should have chosen. In practice organisations run whatever the tenant was created with. Setting them deliberately, against the actual pressure the business is under and with an understanding of the false positive trade, is a change with a measurable effect and no licensing cost.

The DMARC honouring setting has never been looked at

The setting controls what happens when a sender fails explicit DMARC checks and their own DMARC policy says quarantine or reject. Deciding to honour that is deciding to respect what legitimate senders have published about forgeries of their domain. It sits alongside your own DMARC record work rather than replacing it, and both are worth doing together.

Campaign Views is available and nobody has opened it

Machine learning and heuristics identify and analyse messages involved in coordinated phishing attacks against the whole service and your organisation. When a user reports a suspicious message, that view answers who else received it and what the campaign looks like, in seconds. It is one of the highest value features in the product and among the least used.

Where this matters most

Six UAE situations where anti-phishing configuration is the difference.

Microsoft names four attack categories: spear phishing, whaling, business email compromise and the phishing that initiates ransomware. Each maps to a different part of the configuration.

A firm that authorises payments by email

Business email compromise uses forged trusted senders, and Microsoft names financial officers, customers and trusted partners specifically, to trick recipients into approving payments, transferring funds or revealing customer data. Impersonation protection for those named senders and their domains is the direct control, and it is inert until the list is populated.

A business whose executives are publicly identifiable

Whaling is directed at executives or other high value targets for maximum effect, and in the UAE market leadership teams are frequently listed on the website, quoted in the press and visible on professional networks. That makes reconnaissance trivial, which is exactly the precondition Microsoft describes for spear phishing.

A group that trades with a small set of significant partners

Domain impersonation protection covers the sender domains you specify. Where most of your payment instructions come from a known set of customers and suppliers, protecting those domains explicitly closes the most likely route, and it is a short list that changes rarely, which makes it maintainable.

An operator whose ransomware exposure starts in the inbox

Microsoft states ransomware almost always starts in phishing messages, and that anti-phishing protection cannot decrypt encrypted files but can help detect the initial phishing messages associated with the campaign. That reframes the anti-phishing configuration as ransomware prevention rather than as an email quality issue.

An organisation running phishing simulations without configuring the controls

Attack simulation training lets administrators create fake phishing messages and send them to internal users as an education tool. It is genuinely valuable, and it is not a substitute for configuration. Testing whether people click, while impersonation protection sits empty, measures the human layer and leaves the technical one untouched.

An organisation investigating a reported message

Campaign Views answers the questions that matter during an investigation: how many people received this, is it part of a coordinated attack, and what else came from the same source. Combined with the impersonation insight showing detected impersonation attempts, it turns a single report into an understanding of what is happening.

Three positions

How UAE organisations configure anti-phishing today.

The middle column is the overwhelming majority. The licences are held, the defaults are running, and the settings that address targeted attacks were never filled in.
Spoof intelligence active
Configured and maintainedYes
Licensed, left at defaultsYes
Basic mailbox protection onlyYes
Sender DMARC policy honoured
Configured and maintainedYes
Licensed, left at defaultsUnverified
Basic mailbox protection onlyUnverified
Executives protected from impersonation
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Supplier domains protected
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Mailbox intelligence configured
Configured and maintainedYes
Licensed, left at defaultsPartly
Basic mailbox protection onlyNot available
Thresholds set deliberately
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Impersonation insight reviewed
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Campaign Views used in investigations
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot available
Protected lists maintained as people change
Configured and maintainedYes
Licensed, left at defaultsNo
Basic mailbox protection onlyNot applicable
Position against targeted invoice fraud
Configured and maintainedDefended
Licensed, left at defaultsExposed
Basic mailbox protection onlyExposed
Feature
Configured and maintained
Licensed, left at defaults
Basic mailbox protection only
Spoof intelligence active
YesYesYes
Sender DMARC policy honoured
YesUnverifiedUnverified
Executives protected from impersonation
YesNoNot available
Supplier domains protected
YesNoNot available
Mailbox intelligence configured
YesPartlyNot available
Thresholds set deliberately
YesNoNot available
Impersonation insight reviewed
YesNoNot available
Campaign Views used in investigations
YesNoNot available
Protected lists maintained as people change
YesNoNot applicable
Position against targeted invoice fraud
DefendedExposedExposed
The two tiers

What every mailbox gets, and what Defender for Office 365 adds.

Capabilities as published. The right hand column is whether the control works out of the box or requires you to supply information, which is ours.
CapabilityTierDoes it work without configuration
Spoof intelligence and the spoof intelligence insightAll cloud mailboxesDetection yes, but overriding verdicts is a manual review activity
Anti-phishing policies for all cloud mailboxesAll cloud mailboxesDefaults apply, but the spoof action and Outlook indicators are choices
Honour the sender DMARC policy on spoof detectionAll cloud mailboxesA configuration decision about quarantine and reject policies
Spoofed senders in the Tenant Allow/Block ListAll cloud mailboxesEntries appear when you override a verdict, or can be created manually
Implicit email authenticationAll cloud mailboxesYes, it augments SPF, DKIM and DMARC automatically
Impersonation protection for named sendersDefender for Office 365No. It protects only the senders you enter
Impersonation protection for named sender domainsDefender for Office 365No. It protects only the domains you enter
Mailbox intelligenceDefender for Office 365Learns relationships, but the policy settings still need configuring
Adjustable phishing email thresholdsDefender for Office 365A dial with a default, and the default is a choice you inherited
Impersonation insightDefender for Office 365Shows what impersonation protection detected, so it reflects your configuration
Campaign ViewsDefender for Office 365Yes, but only useful if somebody looks at it
Attack simulation trainingDefender for Office 365No. It is a programme you run, not a setting
How a review runs

Five steps, and most of the value lands in the first two.

This is typically a two to four week engagement. The controls are already licensed in most tenants, so the output is configuration and a maintenance owner rather than a purchase.
  1. 1

    Inventory the current policies and what they actually contain

    Which anti-phishing policies exist, who they apply to, what spoof intelligence and the Outlook unauthenticated sender indicators are set to, what action applies to blocked spoofed senders, and whether the sender DMARC policy honouring setting has ever been considered.

  2. 2

    Rebuild the impersonation lists around the current business

    Protected senders covering the current leadership team, finance and payments staff, and anybody whose name appears on payment instructions. Protected sender domains covering the customers and suppliers that matter. Then a named owner, because the list decays as people join, leave and change roles.

  3. 3

    Set thresholds and mailbox intelligence deliberately

    Adjustable phishing email thresholds chosen against the pressure the business is actually under rather than inherited from tenant creation, with the false positive trade understood and a route for users to report a message that was wrongly caught.

  4. 4

    Review the spoofed senders list and the insight

    Overrides in the spoof intelligence insight become manual allow or block entries on the spoofed senders tab of the Tenant Allow Block List. Those accumulate over years and are rarely revisited, which means a permitted spoof from a supplier relationship that ended in 2022 can still be sitting there.

  5. 5

    Establish the operating rhythm

    Somebody who reviews the impersonation insight, somebody who opens Campaign Views when a message is reported, a maintained user reporting route, and an owner for the protected lists. Optionally attack simulation training as the human layer, run alongside the configuration rather than instead of it.

Straight answers

What organisations ask about anti-phishing policies.

Microsoft lists what all organisations with cloud mailboxes have: spoof intelligence with the spoof intelligence insight for reviewing and manually allowing or blocking detected spoofed senders, anti-phishing policies for all cloud mailboxes, the ability to honour a sender DMARC policy when a message is detected as spoof, allow and block entries for spoofed senders in the Tenant Allow Block List, and implicit email authentication.

Anti-phishing policies with impersonation protection settings for specific message senders and sender domains, mailbox intelligence settings, and adjustable phishing email thresholds. Plus the impersonation insight showing details of detected impersonation attempts, Campaign Views for coordinated attacks, and attack simulation training for creating fake phishing messages as an education tool.

No, and this is the single most important thing on this page. It is configured for specific message senders and sender domains, which means it protects the people and domains you enter and nothing else. A policy with an empty protected senders list provides no impersonation protection at all, and that is the most common finding in the reviews we run.

The people an attacker would impersonate to move money or extract data. In practice that means the chief executive, the chief financial officer and the finance team, anybody who signs off payments, and often board members and the company secretary. Microsoft describes business email compromise as using forged trusted senders including financial officers, which is the population to start from.

Impersonation protection covers sender domains as well as senders. Where your payment instructions and contract conversations come from a defined set of counterparties, adding those domains closes the route where a lookalike domain is used instead of a lookalike display name. It is a short list, it changes rarely, and it is worth maintaining.

A Defender for Office 365 policy setting, configured alongside impersonation protection and phishing thresholds. Rather than relying on a static list, it considers the sender relationships a recipient normally has, which is how a message from an address that has never corresponded with this person before can be treated differently from one that has.

They are adjustable, which means the current value is a setting rather than a fact, and in most tenants nobody chose it. Whether to raise it depends on the pressure the business is under and the tolerance for false positives, which is a business conversation as much as a technical one. What we would not do is leave it inherited without anybody having looked.

It controls what happens to messages where the sender fails explicit DMARC checks and their published DMARC policy is set to quarantine or reject. Honouring it means treating a forged message the way the legitimate domain owner asked the world to treat it. It sits alongside publishing your own DMARC record rather than replacing that work.

Spoof intelligence deals with messages that forge a sending domain, including your own, and is available to all cloud mailboxes. Impersonation protection, in Defender for Office 365, deals with messages that imitate a specific person or domain you have named, often using a lookalike address or display name rather than a forged one. Both matter and they catch different attacks.

When you override a verdict in the spoof intelligence insight, Microsoft states the spoofed sender becomes a manual allow or block entry that appears only on the spoofed senders tab of the Tenant Allow Block List page. You can also create entries manually before spoof intelligence has detected the sender, which is useful when you know a legitimate sender will be flagged.

Microsoft describes machine learning and other heuristics identifying and analysing messages involved in coordinated phishing attacks against the entire service and your organisation. Practically, it answers the questions that follow a user report: who else got this, is it part of something larger, and what does the sending pattern look like. It is available and almost never used.

No, and treating it as a substitute is a mistake we see regularly. It lets administrators create fake phishing messages and send them to internal users as an education tool, which measures and improves the human layer. Running simulations while impersonation protection sits unconfigured tests your people against attacks your technology was never told to stop.

It can, which is why the review includes a reporting route for messages that were wrongly caught and why threshold changes are made deliberately rather than maximally. The two changes least likely to cause disruption, and among the highest value, are populating the impersonation lists and reviewing the accumulated spoofed sender overrides.

The protected sender list needs maintaining whenever the leadership or finance team changes, which in most organisations means at least annually and realistically at each significant appointment. The spoofed senders override list is worth an annual review because entries accumulate and outlive the relationships that justified them. Thresholds are worth revisiting after any incident.

This is a small engagement, typically two to four weeks, and we usually fold it into a wider Defender for Office 365 assessment alongside the Safe Links configuration and your email authentication records. The controls are already licensed in most tenants, so the output is configuration and an owner rather than a purchase.
The policy review

Fifteen checks worth running on an existing tenant.

Anti-phishing policy is one of the few security controls where the review consistently finds the same three gaps in almost every organisation. These are the checks that find them.

Impersonation

  • Who is on the protected senders list?
    Frequently empty, frequently stale.
  • Is the current leadership team on it?
    People change roles.
  • Are finance and payments staff protected?
    They are the actual target.
  • Which sender domains are protected?
    Key customers and suppliers.
  • Does the impersonation insight show activity?
    Empty usually means unconfigured.

Spoof and authentication

  • Is spoof intelligence on?
    It is a policy setting.
  • Do you honour sender DMARC policies?
    For quarantine and reject.
  • Are unauthenticated sender indicators shown?
    The Outlook visual cue.
  • What is the action for blocked spoofed senders?
    Specified in the policy.
  • Has anyone reviewed the spoofed senders list?
    Overrides accumulate.

Operating it

  • What are your phishing thresholds set to?
    Adjustable, and usually never adjusted.
  • Does anyone look at Campaign Views?
    It shows the pattern, not the message.
  • How do users report a suspected phish?
    And where does it go.
  • Is attack simulation training run?
    It is a programme, not a setting.
  • Who maintains the protected lists?
    They decay without an owner.
Related reading

The pages around this one.

Defender for Office 365

The product these policies belong to, and the rest of what it does.

Learn more

Safe Links

URL protection, reviewed in the same engagement and usually with findings of its own.

Learn more

DMARC audit

Your own authentication records, which sit alongside honouring other senders policies.

Learn more
Next step

Open your anti-phishing policy and look at the protected senders list.

If it is empty, or it lists people who no longer work there, you have the most common gap in Microsoft 365 email security and it takes an afternoon to close. If it is current and maintained, you are in a small minority.

Book an anti-phishing policy reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Email Security Audit

Authentication, policy, exceptions, routing, mailboxes

Learn more

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

Safe Links

Time-of-click URL checks in mail, Teams and Office

Learn more

DMARC Audit UAE

Stop exact-domain spoofing, and keep your mail delivering

Learn more

Phishing Protection

Defender for Office 365, DMARC, simulation campaigns

Learn more

Attack Simulation Training

Phishing simulation you probably already own, including QR codes

Learn more

Security Awareness Training

Phishing simulation and behavior-change training

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy