**What is Microsoft Defender for Office 365 in the first place? **
It is a cloud-based service that provides security measures in the Microsoft 365 environment.
When using Exchange Online, Teams, SharePoint, and OneDrive, it protects against phishing, malware, and other threats.
How can **I use it? **
As a prerequisite, Microsoft Defender for Office 365 **offers two plans: P1 and P2. **
The two main features introduced this time, "Safe Links" and "Safe Attachments", are included in P1.
P2 is upward compatible with P1, and advanced security measures such as "attack simulation training" and "automatic investigation and response" are also possible.
Based on the difference between these plans, there are two main ways to use Microsoft Defender for Office 365.
(1) Purchase a Microsoft 365 license that includes Microsoft Defender for Office 365
Below is a description of which Microsoft 365 licenses are included in each plan.
P1:Microsoft 365 Business Premium
P2:Microsoft 365 E5、Office 365 E5
It's important to note that Microsoft 365 E3, which is widely used by companies with more than 300 employees, does not include either P1 or P2.
If you want to use it, you will need to purchase it alone or upgrade to E5.
If you have a business with 300 or fewer employees using Business Basic or Business Standard, you will need to purchase it separately or upgrade to Business Premium or E5.
Business Premium is recommended for companies with less than 300 employees, as it provides other security measures required by companies, such as EDR products, at a cost-effective price.
(2) Buy Microsoft Defender for Office 365 separately
As of February 2025, P1 costs 299 yen per month and P2 costs 749 yen per month per user. Individual purchases are more expensive, so we recommend that you purchase licenses that include these.

Quoted from the official Microsoft website:
https://www.microsoft.com/ja-jp/security/business/siem-and-xdr/microsoft-defender-office-365
Main Function Introduction
From here, we will explain the two main functions of Microsoft Defender for Office 365 in detail.
(1) Secure Links
This feature checks in real time whether the links that exist on Microsoft 365 are okay.

In the specific case,
・Malicious links are sent by email
・Malicious links are sent from people who invited guests in Teams.
- Contains malicious links in Word and Excel
etc., but it is possible to respond to all of the above.
In addition, it will check when you click on the link, not when you receive it, so even if the link is rewritten after receiving it, you can respond.
Admins can also use the Defender portal to see who clicked on what links.
### (2) Secure Attachments
This feature checks in real time whether the files sent/shared on Microsoft 365 are okay. The idea is the same as the secure link.
Especially in email, it parses attachments in the sandbox before the email reaches the recipient. As a result of the analysis, if there is no problem, the email will be delivered as it is, and if there is a problem, it will not be delivered and will be blocked.
Traditional security products often block compared to known attacks, and there are cases where they are defenseless against unknown attacks. However, Microsoft Defender for Office 365 provides real-time analysis on the sandbox, including unknown attacks. Because it is on a sandbox, the analysis does not affect the recipient's environment.
Conclusion
In this article, we have explained the main functions of Microsoft Defender for Office 365. This product is a powerful security measure just by introducing it. However, there are cases where an alert occurs, and as a company, you need to take appropriate action.
(Example) When an email containing malware is detected and an alert is issued, the administrator blocks the sending domain
There are two main things to do:
- Real-time analysis of alerts
・Formulation and implementation of countermeasures
To do this properly, you need a dedicated security expert. However, in-house production of all of these systems is a major hurdle for many companies.
**We provide SOC service "Colorkrew Security" for companies that do not have such a system. **
In addition to monitoring logs and alerts 24 hours a day, 365 days a year, we also support subsequent analysis and formulation of countermeasures.
In addition to Microsoft Defender for Office 365, it is also compatible with other Microsoft Defender series, as well as the following products, enabling integrated security operation monitoring.
・WAF (AWS WAF, Azure WAF, etc.)
・EDR (Cybereason, CrowdStrike, etc.)
・SaaS (Slack, Dropbox, etc.)
・Firewall (Fortigate, Meraki, etc.)
- PC operation logs (SKYSEA Client View, LANSCOPE Endpoint Manager, etc.)
If you are interested in monitoring security operations, please contact us. Our team is here to provide support tailored to your security needs.