Configuring Anti-Phishing Policies in Microsoft Defender
Microsoft 365
phishing
Defender
email security
policy
By Kerry · Updated 03/05/26 07:09 AM
Microsoft Defender for Office 365 includes anti-phishing policies that use machine learning and impersonation detection to block phishing emails. Configure them in the Microsoft 365 Defender portal (security.microsoft.com) under Email & Collaboration > Policies & Rules > Threat policies > Anti-phishing.
In the default policy, enable impersonation protection for key executives (CEO, CFO, IT Director) by adding their names under Protected users. Enable domain impersonation protection and add your company's domain. Set the action for detected impersonation to "Quarantine the message" rather than just "Move to Junk."
Enable mailbox intelligence — this learns from each user's contact patterns to detect unusual senders. Review the impersonation insight report weekly to tune policies. False positives (legitimate emails flagged) can be whitelisted under the policy's Trusted senders section.