Impersonation protection has to be told who your executives are. Nobody does it, and then the invoice fraud works.
Every cloud mailbox gets spoof intelligence, DMARC policy honouring and implicit email authentication. What Defender for Office 365 adds is impersonation protection for named senders and domains, mailbox intelligence, and adjustable phishing thresholds. All three require configuration, and in most tenants we review, none of them have been touched.

- Two tiersAll cloud mailboxes, then Defender for Office 365
- Named sendersImpersonation protection must be configured
- AdjustablePhishing email thresholds are a policy setting
- Campaign ViewsCoordinated attacks analysed across the service
Seven controls, and the ones that stop invoice fraud need configuring.
Impersonation protection, for senders and domains you name
Defender for Office 365 anti-phishing policies configure impersonation protection settings for specific message senders and sender domains. The word doing the work is specific. Nothing protects your chief financial officer from being impersonated until somebody enters their name and address into the policy, and in most tenants we review that list is empty or years out of date.
Mailbox intelligence, which learns the sender relationships
Mailbox intelligence settings are configured in the same Defender for Office 365 anti-phishing policy. Rather than matching a static list, this considers who a recipient normally corresponds with, which is how a message from a supplier address that has never written to this person before becomes suspicious without anybody having to predict it in advance.
Adjustable phishing email thresholds
The published policy settings include adjustable phishing email thresholds, which control how aggressive the detection is. That is a real dial with a real trade, and it is a decision rather than a default. Organisations under active business email compromise pressure generally want it higher than the tenant they inherited was configured for.
Spoof intelligence, available to every cloud mailbox
The spoof intelligence insight reviews detected spoofed senders in messages from external and internal domains and lets you manually allow or block them. Anti-phishing policies for all cloud mailboxes turn spoof intelligence on or off, turn unauthenticated sender indicators in Outlook on or off, and specify the action taken for blocked spoofed senders.
Honouring the sender DMARC policy
A setting that controls what happens to messages where the sender fails explicit DMARC checks and their DMARC policy is set to quarantine or reject. That is the difference between respecting what a legitimate sender has asked the world to do with forgeries of their domain, and quietly overriding it, and it is a configuration choice most organisations have never consciously made.
Campaign Views, which show the pattern rather than the message
Microsoft describes machine learning and other heuristics identifying and analysing messages involved in coordinated phishing attacks against the entire service and your organisation. That changes an investigation from one reported message into a view of the campaign it belongs to, including who else received it and what the sending pattern looks like.
Implicit email authentication, on top of the records
Microsoft enhances standard authentication checks for inbound email, meaning sender policy framework, domain keys identified mail and DMARC, with sender reputation, sender history, recipient history, behavioural analysis and other advanced techniques to identify forged senders. Your own authentication records still matter, but the platform is not relying on them alone.
Business email compromise uses forged trusted senders. Impersonation protection is off unless you filled it in.
Microsoft defines the attack precisely, and the control that addresses it is the one that requires the most manual input.
- Quoted: business email compromise uses forged trusted senders, naming financial officers, customers and trusted partners, to trick recipients into approving payments, transferring funds, or revealing customer data.
- The corresponding control is impersonation protection, configured in a Defender for Office 365 anti-phishing policy for specific message senders and sender domains. It protects the people and domains you list, and only those.
- That list needs your executives, your finance team, your board, and the domains of your most significant customers and suppliers. It also needs maintaining, because people join, leave and change roles, and a list built during a project in 2023 protects a leadership team that has since changed.
- The impersonation insight then shows details about detected impersonation attempts, which is both an operational tool and the evidence that the configuration is doing something. An empty insight in an organisation that receives payment instructions by email usually means the policy is empty, not that nobody is trying.
Four things an anti-phishing review finds in almost every tenant.
The impersonation list is empty, or it protects people who left
Impersonation protection covers the specific senders and sender domains you configure. In most tenants that list is either empty or was populated once during a deployment project. Rebuilding it around the current leadership team, the finance function, and the customer and supplier domains that actually appear in payment conversations takes an afternoon.
The phishing thresholds were never a decision
They are adjustable, which means somebody should have chosen. In practice organisations run whatever the tenant was created with. Setting them deliberately, against the actual pressure the business is under and with an understanding of the false positive trade, is a change with a measurable effect and no licensing cost.
The DMARC honouring setting has never been looked at
The setting controls what happens when a sender fails explicit DMARC checks and their own DMARC policy says quarantine or reject. Deciding to honour that is deciding to respect what legitimate senders have published about forgeries of their domain. It sits alongside your own DMARC record work rather than replacing it, and both are worth doing together.
Campaign Views is available and nobody has opened it
Machine learning and heuristics identify and analyse messages involved in coordinated phishing attacks against the whole service and your organisation. When a user reports a suspicious message, that view answers who else received it and what the campaign looks like, in seconds. It is one of the highest value features in the product and among the least used.
Six UAE situations where anti-phishing configuration is the difference.
A firm that authorises payments by email
Business email compromise uses forged trusted senders, and Microsoft names financial officers, customers and trusted partners specifically, to trick recipients into approving payments, transferring funds or revealing customer data. Impersonation protection for those named senders and their domains is the direct control, and it is inert until the list is populated.
A business whose executives are publicly identifiable
Whaling is directed at executives or other high value targets for maximum effect, and in the UAE market leadership teams are frequently listed on the website, quoted in the press and visible on professional networks. That makes reconnaissance trivial, which is exactly the precondition Microsoft describes for spear phishing.
A group that trades with a small set of significant partners
Domain impersonation protection covers the sender domains you specify. Where most of your payment instructions come from a known set of customers and suppliers, protecting those domains explicitly closes the most likely route, and it is a short list that changes rarely, which makes it maintainable.
An operator whose ransomware exposure starts in the inbox
Microsoft states ransomware almost always starts in phishing messages, and that anti-phishing protection cannot decrypt encrypted files but can help detect the initial phishing messages associated with the campaign. That reframes the anti-phishing configuration as ransomware prevention rather than as an email quality issue.
An organisation running phishing simulations without configuring the controls
Attack simulation training lets administrators create fake phishing messages and send them to internal users as an education tool. It is genuinely valuable, and it is not a substitute for configuration. Testing whether people click, while impersonation protection sits empty, measures the human layer and leaves the technical one untouched.
An organisation investigating a reported message
Campaign Views answers the questions that matter during an investigation: how many people received this, is it part of a coordinated attack, and what else came from the same source. Combined with the impersonation insight showing detected impersonation attempts, it turns a single report into an understanding of what is happening.
How UAE organisations configure anti-phishing today.
| Feature | Configured and maintained | Licensed, left at defaults | Basic mailbox protection only |
|---|---|---|---|
Spoof intelligence active | Yes | Yes | Yes |
Sender DMARC policy honoured | Yes | Unverified | Unverified |
Executives protected from impersonation | Yes | No | Not available |
Supplier domains protected | Yes | No | Not available |
Mailbox intelligence configured | Yes | Partly | Not available |
Thresholds set deliberately | Yes | No | Not available |
Impersonation insight reviewed | Yes | No | Not available |
Campaign Views used in investigations | Yes | No | Not available |
Protected lists maintained as people change | Yes | No | Not applicable |
Position against targeted invoice fraud | Defended | Exposed | Exposed |
What every mailbox gets, and what Defender for Office 365 adds.
| Capability | Tier | Does it work without configuration | |
|---|---|---|---|
| Spoof intelligence and the spoof intelligence insight | All cloud mailboxes | Detection yes, but overriding verdicts is a manual review activity | |
| Anti-phishing policies for all cloud mailboxes | All cloud mailboxes | Defaults apply, but the spoof action and Outlook indicators are choices | |
| Honour the sender DMARC policy on spoof detection | All cloud mailboxes | A configuration decision about quarantine and reject policies | |
| Spoofed senders in the Tenant Allow/Block List | All cloud mailboxes | Entries appear when you override a verdict, or can be created manually | |
| Implicit email authentication | All cloud mailboxes | Yes, it augments SPF, DKIM and DMARC automatically | |
| Impersonation protection for named senders | Defender for Office 365 | No. It protects only the senders you enter | |
| Impersonation protection for named sender domains | Defender for Office 365 | No. It protects only the domains you enter | |
| Mailbox intelligence | Defender for Office 365 | Learns relationships, but the policy settings still need configuring | |
| Adjustable phishing email thresholds | Defender for Office 365 | A dial with a default, and the default is a choice you inherited | |
| Impersonation insight | Defender for Office 365 | Shows what impersonation protection detected, so it reflects your configuration | |
| Campaign Views | Defender for Office 365 | Yes, but only useful if somebody looks at it | |
| Attack simulation training | Defender for Office 365 | No. It is a programme you run, not a setting |
Five steps, and most of the value lands in the first two.
- 1
Inventory the current policies and what they actually contain
Which anti-phishing policies exist, who they apply to, what spoof intelligence and the Outlook unauthenticated sender indicators are set to, what action applies to blocked spoofed senders, and whether the sender DMARC policy honouring setting has ever been considered.
- 2
Rebuild the impersonation lists around the current business
Protected senders covering the current leadership team, finance and payments staff, and anybody whose name appears on payment instructions. Protected sender domains covering the customers and suppliers that matter. Then a named owner, because the list decays as people join, leave and change roles.
- 3
Set thresholds and mailbox intelligence deliberately
Adjustable phishing email thresholds chosen against the pressure the business is actually under rather than inherited from tenant creation, with the false positive trade understood and a route for users to report a message that was wrongly caught.
- 4
Review the spoofed senders list and the insight
Overrides in the spoof intelligence insight become manual allow or block entries on the spoofed senders tab of the Tenant Allow Block List. Those accumulate over years and are rarely revisited, which means a permitted spoof from a supplier relationship that ended in 2022 can still be sitting there.
- 5
Establish the operating rhythm
Somebody who reviews the impersonation insight, somebody who opens Campaign Views when a message is reported, a maintained user reporting route, and an owner for the protected lists. Optionally attack simulation training as the human layer, run alongside the configuration rather than instead of it.
What organisations ask about anti-phishing policies.
Fifteen checks worth running on an existing tenant.
Impersonation
- Who is on the protected senders list?Frequently empty, frequently stale.
- Is the current leadership team on it?People change roles.
- Are finance and payments staff protected?They are the actual target.
- Which sender domains are protected?Key customers and suppliers.
- Does the impersonation insight show activity?Empty usually means unconfigured.
Spoof and authentication
- Is spoof intelligence on?It is a policy setting.
- Do you honour sender DMARC policies?For quarantine and reject.
- Are unauthenticated sender indicators shown?The Outlook visual cue.
- What is the action for blocked spoofed senders?Specified in the policy.
- Has anyone reviewed the spoofed senders list?Overrides accumulate.
Operating it
- What are your phishing thresholds set to?Adjustable, and usually never adjusted.
- Does anyone look at Campaign Views?It shows the pattern, not the message.
- How do users report a suspected phish?And where does it go.
- Is attack simulation training run?It is a programme, not a setting.
- Who maintains the protected lists?They decay without an owner.
The pages around this one.
Open your anti-phishing policy and look at the protected senders list.
If it is empty, or it lists people who no longer work there, you have the most common gap in Microsoft 365 email security and it takes an afternoon to close. If it is current and maintained, you are in a small minority.
Related Services
Explore more solutions that work great with this service
Email Security Audit
Authentication, policy, exceptions, routing, mailboxes
Defender for Office 365
Plan 1 versus Plan 2, and the ten second way to tell which you have
Safe Links
Time-of-click URL checks in mail, Teams and Office
DMARC Audit UAE
Stop exact-domain spoofing, and keep your mail delivering
Phishing Protection
Defender for Office 365, DMARC, simulation campaigns
Attack Simulation Training
Phishing simulation you probably already own, including QR codes
Security Awareness Training
Phishing simulation and behavior-change training
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes