Your practice
You set the baseline you’re targeting, decide who signs off on a quarantine release or a blocked-sender override, and tell your client what "security basics" means before they buy it.
Email security & Defender Sécurité courriel et Defender
Plans names a security baseline and a regular review inside Plus without ever spelling out the tools behind it. This page does: mailbox-level threat protection (Microsoft Defender for Office 365 where a client’s licence already includes it, or the equivalent filtering controls in whatever email platform they run), sender-authentication records that stop spoofed mail, and short awareness nudges when a real attempt gets through — named as their own resellable line, not a vague review bullet.
You set the baseline you’re targeting, decide who signs off on a quarantine release or a blocked-sender override, and tell your client what "security basics" means before they buy it.
We check the agreed email-security settings against that baseline, triage what the filtering layer flags, and send a short nudge to a user only when a real attempt got through — not a running compliance score.
For a client whose email already runs through Microsoft 365 or another hosted platform, but whose spam/phishing filtering, sender-authentication records, and end-user awareness have never been checked against an agreed baseline.
The baseline you want enforced (what Defender or the platform’s native filtering should already catch), who approves releasing a quarantined message or adding a sender override, and whether awareness nudges should go to the user directly or through your practice first.
What you get: A baseline that’s actually been checked instead of assumed, and a small number of real attempts turned into short user-facing nudges — not a bigger alert feed nobody reads.
What we hand back: A baseline review note naming what was checked, what drifted, and a requested decision — the same format as every other review on this site.
Defender for Office 365 exists at more than one licence level, and some tenants have none of it — only the mailbox platform’s native filtering. What we can check depends on what’s actually turned on, not on what the plan name implies.
Releasing a held message can also release whatever made it suspicious. Name one approver for that call before the first quarantine ticket arrives, not while a user is waiting.
Sending a note to a user after every filtered spam message would train them to ignore it. Agree on the threshold — a real click, a reported attempt, a targeted spoof — before the first nudge goes out.
Sender-authentication records apply per domain. A client with a second brand domain or a legacy domain still receiving mail needs that named explicitly, or it sits outside the baseline by default.
No. This is a baseline check and awareness nudges inside the Plus review line, not a security practice or SOC. Describe it to your client as what it actually is: checked settings and short nudges, not continuous monitoring.
It’s reported through the same escalation path as any other request. A confirmed compromise is treated as an incident with a named approver deciding next steps — not folded quietly into the next baseline review.