The Microsoft Defender portal at security.microsoft.com has quietly become the front door for most of Microsoft 365 security: endpoint protection, email and collaboration protection, cloud app discovery, hunting, exposure management, and increasingly Microsoft Sentinel. Microsoft’s secure-by-default posture means the out-of-box configuration is better than it used to be. It is still not the configuration most organizations should be running.
Two quick orientation notes before the settings themselves. The portal’s menus run deep, and some of the most useful configuration hides under Settings, where entire pages of endpoint and Defender XDR options live that never appear in the main navigation. And if you want a ready-made hardening checklist, the recommendations under Exposure Management rank improvements by their impact on your Microsoft Secure Score, which makes them a practical work queue rather than just a report. With that, here are the settings we keep coming back to, tenant after tenant.
Handle Antivirus Exclusions Through Policies, Not One-Off Changes
Exclusion requests never stop. A line-of-business vendor insists their folder be excluded from scanning, a database server needs its data path left alone, and the temptation is to make the change wherever is fastest. The right place is endpoint security policies, and there is a detail worth internalizing: the same policies appear in both the Microsoft Defender portal and the Microsoft Intune admin center. They are not two policy sets to keep synchronized. They are one policy set with two doors, and for organizations still moving endpoint configuration off Group Policy into Intune, it is the same modern management plane doing the work.
Within an antivirus policy you can define excluded file paths, extensions, and processes, with equivalent options for Windows, macOS, and Linux. The real power is in assignment. Policies target Microsoft Entra security groups, including groups synchronized from on-premises Active Directory, and every assignment supports both include and exclude. Apply an exclusion policy to all users but exclude the contractors group, or build separate policies for the specific segments that need them. Every exclusion reduces protection, so scoping exclusions to only the devices that genuinely need them is the difference between a managed risk and a blind spot. Expect to end up with several small, well-named policies rather than one policy that does everything, and that is a good outcome.
Switch Safe Attachments to Dynamic Delivery
Under Email and Collaboration, the threat policies include defaults for anti-phishing, anti-spam, anti-malware, Safe Attachments, and Safe Links that are always on, cannot be deleted, and, helpfully, can now be edited. The Safe Attachments policy is the one we adjust most often.
Safe Attachments detonates incoming attachments before users can open them, and the policy decides what happens while that scan runs. Blocking outright means email waits on scanning. Our preferred setting is Dynamic Delivery: the message is delivered immediately with a placeholder where the attachment will be, and the real attachment is released the moment scanning confirms it is safe. Malicious attachments are quarantined. Users see their mail arrive on time, the protection stays fully intact, and the only change to their experience is occasionally waiting a minute or two before opening a file. That trade is worth making in nearly every tenant.
Know What Your Outbound Spam Policy Is Doing
Everyone configures inbound protection. The outbound spam policy does its work quietly, and two of its behaviors surprise administrators on a regular basis.
The first is automatic forwarding. The default setting, labeled Automatic - System-controlled, now means forwarding is disabled: inbox rules, mailbox forwarding, and automation that pushes mail to external recipients are all blocked out of the box. That is the correct default, and it also breaks legitimate workflows, most commonly help desk ticketing platforms like Zendesk or Freshdesk that depend on forwarded mail. The fix is not to open forwarding for everyone. Create a custom outbound spam policy scoped to the specific mailboxes that need it, and leave the default in place for everyone else.
The second is sending limits. The policy enforces per-hour and per-day recipient limits and watches for anomalous sending behavior. We watched a client discover this the hard way when a well-intentioned bulk email campaign, sent straight from a user mailbox, tripped the policy and got blocked mid-send. If a department is planning a legitimate mass mailing, it belongs in a proper bulk email platform, and your team should know these thresholds exist before the marketing calendar finds them for you.
Put Attack Simulation Training on Autopilot
Attack simulation training, included with Microsoft 365 E5 or Microsoft Defender for Office 365 Plan 2, lets you send realistic but harmless phishing campaigns to your own users, complete with landing pages and automatically assigned training for anyone who clicks. The feature most people miss is simulation automations, which remove the part where a human has to remember to run them.
An automation lets you select multiple social engineering techniques and payloads, then run simulations on a randomized schedule across a date range. We set some clients up with roughly quarterly randomized simulations and let the automation run. The ongoing effort drops to periodically reviewing the reports: who clicked, who reported, and whether the assigned training actually got completed. Security awareness programs fail when they depend on someone remembering to run them, and this one does not have to.
Learn Threat Explorer Before You Need It
Email filters are good. They are not perfect. The day a convincing phishing message slips past the filters and lands in fifty mailboxes is the wrong day to learn a new tool, and Threat Explorer, part of Defender for Office 365 Plan 2, is the tool for exactly that day.
Explorer lets you search all mail flowing through the tenant by sender, subject, recipient, URL, and more. Find the campaign, select every matching message, and take action in bulk: move messages to deleted items, soft delete, hard delete, or submit them to Microsoft for analysis. Each remediation gets a name and lands in the Action Center with a full history, so there is an audit trail for what was removed and when. Outside of incidents, Explorer doubles as a reporting surface for top clicked URLs and most-targeted users, and queries you build can be saved for reuse. Spend twenty minutes in it on a calm day so it is familiar on a bad one.
Use Defender for Cloud Apps to See What AI Your Users Are Actually Using
Microsoft Defender for Cloud Apps, included with Microsoft 365 E5, leverages signals from devices onboarded to Defender for Endpoint to build a picture of every cloud application in use across your organization: which apps, how much traffic, which users, and even where each app is headquartered. It is consistently one of the more eye-opening screens to show a leadership team.
The category drawing all the attention right now is generative AI. The cloud app catalog tracks nearly 38,000 applications, more than 1,400 of them in the generative AI category, and cloud discovery shows you exactly which ones have real usage in your environment. From there, governance is a tag: mark an app as unsanctioned and, on devices onboarded to Defender for Endpoint with network protection enabled, access gets blocked automatically. We have clients whose AI policy allows only Microsoft 365 Copilot, and the enforcement mechanism was unsanctioning the rest of the generative AI category in bulk. Visibility into where your data is going is the prerequisite for every AI governance conversation, a theme we explored in Why Microsoft 365 Governance Matters More Than Ever in the Age of AI.
Conclusion
None of these are the flashy corners of the Defender portal. They are the settings that quietly keep problems small: exclusions that stay scoped, attachments that arrive scanned, forwarding that only works where it should, users who get tested before attackers test them, an incident response tool you already know, and a real answer to the question of what AI tools are in use. The portal gives you the controls; the defaults only take you partway. Identity deserves the same deliberate pass, which is why we walk through the Entra ID settings every admin should review in a companion piece. If you want a second set of eyes on your Defender configuration, or you are moving to Microsoft 365 E5 and want to actually use what you are paying for, reach out and let’s talk.