We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Threat Explorer
Threat Explorer, UAE

Your email investigation window is 30 days. Most breach investigations start later than that.

Threat Explorer searches up to 30 days back, and defaults to yesterday and today. If an incident surfaces in week six, the evidence in this tool is already gone. Knowing that changes both how you investigate and what you export while you still can.

Book an email investigation reviewSee what it can do
Threat Explorer email investigation for UAE organisations
  • 30 daysMaximum search period back
  • 200,000Maximum results exportable to CSV
  • 3,000Users exportable from top targeted users
  • Plan 2Required for Threat Explorer itself
What Threat Explorer gives you

Eight things that decide whether an email investigation succeeds.

Threat Explorer is where an email incident is actually investigated: what arrived, who received it, who clicked, and what happened after delivery. Its value is bounded by a licence, a time window and an export limit, and all three are worth knowing before you need them.

Post-delivery activity, not just delivery decisions

The distinction that matters most. Real-time detections shows malicious email detections at the time of delivery only. Threat Explorer shows all email detections at the time of delivery along with post-delivery activities, which is what an investigation needs after the message has already landed.

Which one you have depends on your plan

Real-time detections is available in Defender for Office 365 Plan 1. Threat Explorer is available in Plan 2. Organisations frequently discover the difference mid incident, which is the worst possible moment to find out what their licence includes.

A 30 day search window

The search period reaches up to 30 days ago, and the default filter is yesterday and today. That default catches people out during an investigation, because a query that returns nothing may simply be looking at the wrong two days rather than proving the message never existed.

Views that differ between the two tools

Malware, Phish and Content malware are available in both. All email, Campaigns and URL clicks are Threat Explorer only. URL clicks in particular is the view most often needed after a phishing incident, and it is the one Plan 1 does not have.

Export limits that shape your method

Up to 200,000 filtered or unfiltered results can be exported to CSV from the details area table, and up to 3,000 users can be exported from top targeted users with their corresponding attempts. Those are generous ceilings and they are ceilings, which matters for large campaigns.

Saved queries and richer filtering

Threat Explorer adds more property filtering options, including the ability to save queries, and more actions than Real-time detections. Saved queries are the difference between an investigation method that exists in somebody head and one the whole team can run consistently.

What is not in there at all

End user spam notifications and system generated messages are not available in Threat Explorer. Microsoft notes these types of messages are available if there is a mail flow rule to override. Searching for something that was never indexed produces a confident and wrong conclusion.

Campaign view for the bigger picture

Campaigns is a Threat Explorer view that groups related messages rather than showing them individually. For a coordinated attack against your organisation, that is the difference between investigating forty separate messages and understanding one campaign with forty deliveries.

The constraint to plan around

Thirty days is the whole window, and the default view shows two of them.

Both facts cause real problems during investigations, and both are fixable with process rather than licensing.

  • The search period reaches up to 30 days ago. Where an incident is discovered late, which is the normal case for anything involving credential theft or a slow-burning compromise, the email evidence may already be outside the window when somebody first goes looking.
  • The default filter is yesterday and today. An analyst who queries without changing the date range and finds nothing has learned that the message did not arrive in the last two days, which is not what they were trying to establish. It is an easy mistake under pressure.
  • The process answer is to export early rather than search late. Up to 200,000 filtered or unfiltered results can be exported to CSV from the details area table, so during any live incident the first action is to pull the relevant data out before the window moves past it.
  • The architectural answer is to send the data somewhere with longer retention. Where email telemetry matters beyond 30 days, that means getting it into a SIEM with a retention period matched to your investigation requirements rather than to the tool default.
Ask us about email telemetry retention
How we approach it

Four things that make email investigation reliable.

The tool is good. What fails is that it is used for the first time under pressure, by somebody who does not know the default date range or which views their licence includes.

We design around the 30 day window rather than ignoring it

The search period reaches up to 30 days ago and no further. Incidents discovered late routinely need data outside it. The two responses are exporting early during any live incident, and moving telemetry somewhere with longer retention where the requirement justifies the cost.

We build saved queries rather than documenting steps

Threat Explorer supports saving queries, and a saved query is a considerably better artefact than a written procedure. It runs the same way for everybody, it does not drift, and it removes the date range mistake by construction rather than by instruction.

We check the licence before we design the method

Real-time detections in Plan 1 shows detections at time of delivery only. Threat Explorer in Plan 2 adds post-delivery activities, the all email, campaigns and URL clicks views, saved queries and more actions. Designing a method that needs URL clicks for a Plan 1 tenant wastes everybody time.

We state what the tool cannot see

End user spam notifications and system generated messages are not available in Threat Explorer unless a mail flow rule overrides them. An analyst who does not know that can search, find nothing, and conclude a message never existed. That is a worse outcome than not searching.

How an engagement runs

Four phases across roughly three to four weeks.

This is a capability and readiness engagement rather than a deployment. The aim is that when an email incident happens, the team already knows the method and the limits.
  1. 01
    Week 1

    Establish what you have and what it can see

    Which plan is licensed and therefore which tool is available, whether URL clicks and campaigns views exist, and what the current retention position is for email telemetry beyond the 30 day window.

    • Licence position confirmed per user group
    • Available views documented
    • Email telemetry retention beyond 30 days established
    • Gaps between capability and requirement identified
  2. 02
    Week 2

    Build the investigation method

    Saved queries for the investigations you actually run: a suspicious sender, a reported phishing message, a user who clicked, a campaign against a department. Saved rather than remembered, so the method survives the person who devised it.

    • Saved queries built for common investigations
    • Date range discipline built into each
    • Export procedure defined with the 200,000 limit in mind
    • Top targeted users export understood at 3,000 users
  3. 03
    Week 3

    Rehearse against a real scenario

    A tabletop or a live-fire exercise using a real reported message, walked through end to end by the people who will do it. This is where the default two day filter, the missing view or the licence gap surfaces, at no cost.

    • Investigation walked through with the actual team
    • Time to answer measured for a standard scenario
    • Gaps found in method or tooling
    • Runbook corrected against what actually happened
  4. 04
    Week 4

    Close the retention gap and hand over

    Where investigations need to reach beyond 30 days, the telemetry has to live somewhere else. That is a SIEM decision with a cost, and it should be made deliberately rather than discovered during an incident that needs 60 day data.

    • Retention requirement stated and costed
    • Ingestion into a SIEM designed where justified
    • Runbook handed to the operational team
    • Review point set against incident volume
Where this matters

Six investigations that live or die on this tool.

Every one of them starts with a question that sounds simple and needs email telemetry to answer honestly.

Who else received this phishing message?

The first question after any reported phish, and the one that determines the size of the response. Threat Explorer answers it directly, and the campaigns view turns forty individual messages into one coordinated attack you can reason about as a whole.

Did anybody actually click the link?

URL clicks is a Threat Explorer view and is not available in Real-time detections, which makes this the single most common reason a Plan 1 tenant discovers its licence limitation. Whether somebody clicked changes the entire shape of the incident response.

A regulated firm evidencing an incident response

Supervisors ask what arrived, who received it, what was done and when. Exported evidence from a defined investigation method answers that far better than a narrative reconstruction, and the 200,000 result export ceiling is generous enough for almost any single incident.

A business responding to a supplier compromise

When a supplier is breached, the question is what they sent you and when. That is a sender-based search across the window, and the answer determines whether this is a monitoring exercise or an incident. Being outside the 30 day window turns it into guesswork.

A provider checking who was targeted

Top targeted users exports up to 3,000 users with their corresponding attempts, which turns a vague sense that leadership gets more phishing into a list with numbers. That list is usually what justifies stronger controls for a specific group.

An organisation building a security operations function

Email is where most incidents begin, so email investigation is where a new function should build its first repeatable method. Saved queries, a rehearsed runbook and a known export procedure are a better starting point than a broader capability nobody has practised.

Three positions

How UAE organisations investigate email incidents.

The right column is common, and it produces investigations that take days and reach uncertain conclusions because nobody had used the tool before the day they needed it.
Licence position known in advance
Method built and rehearsedYes
Tool available, used ad hocPartly
Tool unfamiliarNo
Saved queries exist
Method built and rehearsedYes
Tool available, used ad hocNo
Tool unfamiliarNo
Date range discipline
Method built and rehearsedBuilt into method
Tool available, used ad hocSometimes missed
Tool unfamiliarFrequently missed
Post-delivery activity visible
Method built and rehearsedIf Plan 2
Tool available, used ad hocIf Plan 2
Tool unfamiliarUnknown
Export during live incident
Method built and rehearsedStandard practice
Tool available, used ad hocSometimes
Tool unfamiliarNo
Retention beyond 30 days
Method built and rehearsedDesigned
Tool available, used ad hocNone
Tool unfamiliarNone
Investigation rehearsed
Method built and rehearsedYes
Tool available, used ad hocNo
Tool unfamiliarNo
Time to first answer
Method built and rehearsedMinutes
Tool available, used ad hocHours
Tool unfamiliarDays
Conclusions defensible
Method built and rehearsedYes
Tool available, used ad hocUsually
Tool unfamiliarUncertain
Method survives staff change
Method built and rehearsedYes
Tool available, used ad hocNo
Tool unfamiliarNot applicable
Feature
Method built and rehearsed
Tool available, used ad hoc
Tool unfamiliar
Licence position known in advance
YesPartlyNo
Saved queries exist
YesNoNo
Date range discipline
Built into methodSometimes missedFrequently missed
Post-delivery activity visible
If Plan 2If Plan 2Unknown
Export during live incident
Standard practiceSometimesNo
Retention beyond 30 days
DesignedNoneNone
Investigation rehearsed
YesNoNo
Time to first answer
MinutesHoursDays
Conclusions defensible
YesUsuallyUncertain
Method survives staff change
YesNoNot applicable
Plan 1 against Plan 2

What each tool can actually show you.

The views split is the practical difference between the two plans for an investigator, and it is sharper than the licensing summary suggests.
CapabilityReal-time detections, Plan 1Threat Explorer, Plan 2
Malware viewYesYes
Phish viewYesYes
Content malware viewYesYes
All email viewNoYes
Campaigns viewNoYes
URL clicks viewNoYes
Detections shownAt time of delivery onlyDelivery plus post-delivery activities
Saved queriesNoYes
Property filteringFewer optionsMore options
Available actionsFewerMore
How an engagement runs

Five steps, and the rehearsal is the one that finds the gaps.

Everything before the rehearsal is preparation, and everything after it is correction. The rehearsal is where you learn what your team will actually do at two in the morning.
  1. 1

    Confirm the licence and available views

    Plan 1 gives Real-time detections with malware, phish and content malware views showing detections at time of delivery. Plan 2 gives Threat Explorer, adding all email, campaigns and URL clicks, post-delivery activity, saved queries and more actions. Mixed estates need this per group.

  2. 2

    Build saved queries for the investigations you run

    A reported phishing message, a suspicious sender, a user who may have clicked, a campaign against a department. Saved so they run identically for everybody and the date range is correct by construction rather than by somebody remembering to change it.

  3. 3

    Define the export procedure

    What to export during a live incident, in what order, before the 30 day window moves past the relevant period. The 200,000 result ceiling for details area exports and the 3,000 user ceiling for top targeted users both belong in the procedure rather than in somebody memory.

  4. 4

    Rehearse with the people who will do it

    A real reported message walked end to end by the actual team, timed. This is where the default two day filter, an unavailable view, or a licence gap shows up, and where it costs an afternoon rather than an incident.

  5. 5

    Decide the retention question deliberately

    Where investigations genuinely need to reach beyond 30 days, the telemetry has to go somewhere with a longer retention period, which is a SIEM decision with a cost attached. Making that decision in advance is considerably better than discovering it mid incident.

Straight answers

What organisations ask about Threat Explorer.

Up to 30 days ago, and the default filter is yesterday and today. That default is worth knowing, because a search that returns nothing may only be telling you the message did not arrive in the last two days rather than that it never arrived at all.

Threat Explorer contains the same information and capabilities plus more views, more property filtering including saved queries, and more actions. The functional difference that matters most: Real-time detections shows detections at the time of delivery only, while Threat Explorer also shows post-delivery activities.

Real-time detections is available in Defender for Office 365 Plan 1. Threat Explorer is available in Plan 2. In mixed estates this varies by user group, so it is worth confirming per group rather than assuming the tenant is uniform.

Because URL clicks is a Threat Explorer view and is not available in Real-time detections. It is the most common reason a Plan 1 organisation runs into its licence boundary, and it tends to happen during the exact incident where the answer matters most.

Up to 200,000 filtered or unfiltered results to CSV from the details area table, and up to 3,000 users from top targeted users with their corresponding attempts. Both are generous for a single incident and both are hard ceilings worth knowing before you plan around them.

It groups related messages into a campaign rather than presenting them individually, so a coordinated attack reads as one event with many deliveries. It is available in Threat Explorer only, and it substantially changes how quickly you understand the scale of something.

Three common reasons. The date range still defaults to yesterday and today. The message is older than the 30 day window. Or it is a type that is not indexed: end user spam notifications and system generated messages are not available in Threat Explorer unless a mail flow rule overrides them.

Yes, early. The window moves forward every day, so evidence that is available on day one may be outside the search period by the time an investigation concludes. Exporting the relevant results at the start costs minutes and removes a real risk of losing the record.

Not in this tool. That requires the telemetry to have been sent somewhere with longer retention, which in practice means a SIEM. Deciding whether you need that, and paying for it, is a design decision that should be made before an incident rather than during one.

In Threat Explorer, yes. Saved queries are one of the specific additions over Real-time detections, and they are the most underrated one. A saved query makes an investigation method reproducible across a team and removes the date range error by construction.

Anybody who might be first responder to a reported phishing message, which is usually wider than the security team. The tool is not difficult, and the difference between someone who has used it before and someone who has not is measured in hours during an incident.

No, they are complementary. Threat Explorer is a purpose-built email investigation surface with views and actions. Advanced hunting is a query language across a broader dataset. Most email investigations start in Threat Explorer, and the ones that need to cross into endpoint or identity move to hunting.

In Threat Explorer, yes. Microsoft states Threat Explorer shows all email detections at the time of delivery along with post-delivery activities, whereas Real-time detections shows detections at the time of delivery only. Post-delivery is where zero-hour purge and manual remediation appear.

Top targeted users, which exports up to 3,000 users with corresponding attempts. It usually confirms what people suspect and, more usefully, quantifies it, which is what justifies applying stronger authentication or stricter policy to a specific group.

We scope by team size and how much runbook work is needed. The free first step: open the tool, change the date range to the last 30 days, and see how long it takes somebody to answer who else received a given message. That time is your current incident response speed.

In Threat Explorer, yes. More property filtering options including the ability to save queries is one of the specific additions over Real-time detections. A saved query is the most durable form an investigation method can take, because it runs identically for everybody who uses it.

Filtered or unfiltered results from the details area table, up to 200,000 rows, exported to CSV. There is also a separate export from top targeted users covering up to 3,000 users with their corresponding attempts, which is a different dataset answering a different question.

Anybody who might be first responder to a reported phishing message, which is usually wider than the security team alone. The tool is not difficult, and the gap between somebody who has used it before and somebody meeting it during an incident is measured in hours.

More actions than Real-time detections offers, which is one of the specific additions in the Plan 2 experience alongside more views and more property filtering options. That matters during an incident, because moving from finding affected messages to acting on them stays in one place.

Yes. Export chart data exports filtered or unfiltered chart data to CSV, separately from the details area table export which covers up to 200,000 results. Two exports answering different questions, and worth knowing about before you try to reconstruct a chart by hand.
Readiness check

Fifteen questions to answer before the next incident.

These take an afternoon. Answering them during an incident instead costs considerably more than an afternoon.

Capability

  • Do we have Plan 1 or Plan 2?
    It determines which tool you get.
  • Can we see URL clicks?
    Threat Explorer only.
  • Can we see campaigns?
    Threat Explorer only.
  • Can we see post-delivery activity?
    Threat Explorer only.
  • Is the licence uniform across users?
    Mixed estates are common.

Method

  • Do we have saved queries?
    Or does the method live in one head.
  • Does everyone change the date range?
    Default is yesterday and today.
  • Who runs an email investigation at 2am?
    Name them.
  • Have we ever rehearsed one?
    Not during a real incident.
  • How long does a standard search take us?
    Measure it.

Retention

  • Do we need to look back beyond 30 days?
    Most investigations eventually do.
  • Where does email telemetry go afterwards?
    If anywhere.
  • Do we export during live incidents?
    Before the window moves.
  • Do we know the 200,000 export limit?
    It matters for large campaigns.
  • Are system generated messages in scope?
    They are not in Threat Explorer.
Related reading

The pages around this one.

Defender for Office 365

The product these investigation tools belong to.

Learn more

KQL threat hunting

Where investigations go when they cross beyond email.

Learn more

Quarantine policies

What happens to the messages an investigation finds.

Learn more
Next step

Open Threat Explorer, set the range to 30 days, and time how long it takes to answer one question.

Who else received a given message. That number is your current email incident response speed, and it is usually the first thing worth improving.

Book an email investigation reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Defender for Office 365

Plan 1 versus Plan 2, and the ten second way to tell which you have

Learn more

KQL Threat Hunting

Hunting across Defender data, and turning it into detections

Learn more

Quarantine Policies

Who can see, act on and release blocked mail

Learn more

Tenant Allow/Block List

Manual overrides that do more than you expect

Learn more

Anti-Phishing Policies

Impersonation protection, spoof handling and thresholds

Learn more

Defender XDR

Eleven signal sources, one incident, and containment without a human

Learn more

Incident Response

24/7 incident response and forensics in Dubai

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy