Add Think Technology as a trusted source What is Advanced Threat Protection | Think Technology

What is Advanced Threat Protection and why does your business need it?

Email security concept graphic surrounded by cyber threat terms such as virus, hacking, spyware and phishing

A Brisbane accounting firm we work with received what looked like a routine invoice email. The sender’s name matched a known supplier. The link appeared to go to a SharePoint document. Standard antivirus flagged nothing. It was only Microsoft Defender for Office 365 that caught the spoofed domain, detonated the link in a sandbox, and blocked delivery before the email ever reached the inbox.

That is advanced threat protection (ATP) doing its job. ATP is a layer of security designed to stop attacks that traditional tools like antivirus and basic email filters miss. It prevents, detects, and responds to sophisticated threats across your email, collaboration tools, and cloud environment. As attacks grow more targeted and AI-assisted, ATP has moved from a “nice to have” to a core part of any serious security setup.

For Queensland SMEs, the threat picture has sharpened. The ACSC’s Annual Cyber Threat Report 2024-25 recorded more than 84,700 cybercrime reports in the financial year, an average of one every six minutes, with businesses reporting an average loss of $80,850 per incident. Most of those incidents started with something routine: an email, a link, a Teams notification.

What Microsoft Defender for Office 365 actually is

The product previously called “Microsoft ATP” is now Microsoft Defender for Office 365, and it sits within the broader Microsoft Defender XDR (extended detection and response) platform. The name changed; the purpose did not. It protects your Microsoft 365 environment from phishing, malware, business email compromise (BEC), and a growing range of novel attack types that basic email filtering cannot catch.

Microsoft Defender for Office 365 comes in two tiers. Plan 1 is included in Microsoft 365 Business Premium and covers Safe Links, Safe Attachments, anti-phishing rules, and real-time threat detection. Plan 2, included in Microsoft 365 E5, adds advanced threat hunting, automated investigation and response, and attack simulation training for staff. Both plans feed into the unified Defender XDR portal, giving your security team a single view across email, endpoints, identities, and cloud apps.

Gartner named Microsoft a Leader in its 2026 Magic Quadrant for Endpoint Protection, continuing a run of recognition that reflects the product’s consistent performance across enterprise and SMB deployments. For businesses on Microsoft 365this protection is already within reach of your existing licensing.

How ATP analyses a threat from the moment an email arrives

Every inbound email goes through several checks before it reaches a user’s inbox. Understanding what happens at each stage helps you see why layered analysis catches more than any single tool.

  • IP reputation check. The system checks the sending IP address against a continuously updated global library of known malicious senders. Emails from flagged sources are blocked or quarantined before content is even examined.
  • Sender verification. ATP checks whether the sending domain is spoofed, whether the sender’s display name is impersonating a known brand or person, and whether SPF, DKIM, and DMARC records align. Emails that fail these checks are flagged or blocked.
  • Safe Attachments (sandbox detonation). Attachments are opened in an isolated environment before delivery. If the file attempts to run malicious code, drop a payload, or contact an external server, it is blocked. This catches zero-day malware that no signature database has seen yet.
  • Safe Links (time-of-click URL scanning). URLs in emails, Teams messages, Word, Excel, PowerPoint, and OneNote are rewritten and scanned at the moment a user clicks them. If the destination has turned malicious after delivery, the link is blocked and the user sees a warning.
  • AI-powered phishing analysis. Defender for Office 365 uses large language models to analyse email content, tone, urgency signals, and impersonation patterns. This catches sophisticated business email compromise attempts that look legitimate to a human reader.

What has changed since 2024: the threats ATP now defends against

The threat landscape has shifted. Attackers are now using AI to write more convincing phishing emails, to scale impersonation campaigns, and to automate multi-stage attacks. The ACSC warns that AI tools allow threat actors to run phishing and impersonation activity more efficiently than ever before.

Three specific attack types are worth calling out for Australian SMEs in 2026.

QR code phishing (quishing). Attackers embed malicious URLs inside QR codes in emails, attachments, or even printed materials. Because QR codes are not plain text, older email filters cannot read them. Microsoft Defender for Office 365 now extracts and scans URLs embedded in QR codes through Threat Explorer and Advanced Hunting, giving security teams visibility into this attack type. This is one of the more significant additions to the product’s detection capabilities in the past 12 months.

Business email compromise. BEC remains the most common incident type responded to by Australian incident response firms. These attacks use spoofed or compromised email accounts to redirect payments or extract sensitive information. ATP’s impersonation protection, combined with AI-powered content analysis, is the main technical control that catches BEC before it reaches a finance team.

MFA bypass via session hijacking. Multi-factor authentication (MFA) is essential, but attackers have adapted. Adversary-in-the-middle phishing kits capture session tokens after a user authenticates, bypassing MFA entirely. Defender for Office 365, working alongside Microsoft Entra ID, can detect suspicious session activity and trigger automated responses such as disabling compromised accounts or removing malicious inbox rules.

Safe Links protection across Microsoft 365 apps

Safe Links does more than scan email. It works across Outlook, Microsoft Teams, Word, Excel, PowerPoint, OneNote, SharePoint, and OneDrive. Every URL a user clicks in any of these apps is checked at the moment of click, not just at the time the message was received.

Microsoft has extended this to Teams specifically. Near real-time URL protection now flags known malicious links in Teams messages as a warning at delivery, and messages found to contain malicious URLs up to 48 hours after delivery also receive a warning. For businesses where Teams has replaced email for much of their internal communication, this is a meaningful expansion of coverage.

This matters because phishing is no longer confined to email. Attackers send malicious links through Teams direct messages, channel posts, and calendar invites. Without Safe Links coverage across collaboration tools, your email security and your collaboration security become two separate problems.

How Defender for Office 365 connects to the broader security picture

Microsoft Defender for Office 365 does not operate in isolation. It feeds signals into Microsoft Defender XDR, which brings together email, endpoint, identity, and cloud app security into a single incident view. When Defender for Office 365 detects a malicious email, that signal can trigger an automated investigation, contain a compromised user account, and remove malicious messages already delivered, all without manual intervention.

This automated response capability matters because, on average, cyberattacks move laterally within an organisation in 72 minutes. Manual triage cannot keep up at that speed. Automated investigation and response, available in Plan 2, closes the gap by acting on threats faster than a human team can respond.

The platform also draws on Microsoft’s global threat intelligence, which processes signals at a scale no individual business or regional security vendor can match. Microsoft Security processes trillions of signals daily across its global customer base, feeding that intelligence back into detection models in near real-time.

What to check if you are already on Microsoft 365

Many businesses on Microsoft 365 Business Premium already have access to Defender for Office 365 Plan 1 through their existing licence. The protection is not always switched on or properly configured out of the box. Here are four things worth reviewing.

  • Safe Attachments policy. Check whether a Safe Attachments policy is active and applied to all users, not just a subset. The default setting in some tenants is off.
  • Safe Links policy. Confirm Safe Links is configured for email and for Teams, Word, Excel, and PowerPoint. Coverage across collaboration apps is often missed.
  • Anti-phishing and impersonation protection. Verify that impersonation protection is set up for your key domains, executives, and common supplier names. This is where BEC attacks are most often caught.
  • Quarantine and alert review. Set up a regular review of quarantined messages and Defender alerts. ATP catches threats, but someone needs to be checking what it has caught.

If you are unsure what is configured in your tenant, an IT security assessment will show you exactly what is active and what is not.

What TTA sees with Brisbane SMEs on Microsoft 365

Across the businesses we support in Brisbane and South-East Queensland, a common pattern stands out. Defender for Office 365 is included in their Microsoft 365 licence, but it was never properly configured when the tenant was set up. Safe Attachments is off. Impersonation protection covers the primary domain but not the trading names or commonly spoofed supplier domains. Safe Links is active for email but not for Teams.

The result is a product that costs nothing extra but delivers a fraction of its potential protection. The fixes are not complicated. They require someone who knows what to look for and how to apply the right policies. For a business that relies on Microsoft 365 for most of its daily work, getting this right is one of the highest-value security improvements available.

We also see businesses that have moved to Business Premium specifically for the security features, and then never revisit the configuration after the initial setup. Defender for Office 365 updates frequently. New detection capabilities arrive, new threat types emerge, and policies that were adequate 12 months ago may not cover what is landing in inboxes today. A periodic review keeps the configuration current.

If your business handles sensitive client data, operates in a regulated industry, or is working toward the ACSC Essential EightDefender for Office 365 is one of the controls that directly supports your compliance posture. Email security and application control work together; neither substitutes for the other.

Frequently asked questions about Advanced Threat Protection

What is the difference between Microsoft Defender for Office 365 and basic Microsoft 365 email protection?

Basic Microsoft 365 email protection catches known spam and malware using signature-based filtering. Microsoft Defender for Office 365 goes further. It detonates attachments in a sandbox, scans URLs at the moment of click, detects spoofed senders, and uses AI to identify business email compromise attempts. It catches threats that have never been seen before, not just known bad content.

Does my existing Microsoft 365 licence include advanced threat protection?

If your business is on Microsoft 365 Business Premium, Defender for Office 365 Plan 1 is included. This covers Safe Links, Safe Attachments, real-time threat detection, and anti-phishing policies. Plan 2, which adds automated investigation, advanced threat hunting, and attack simulation training, is included in Microsoft 365 E5 or available as a standalone add-on.

Is advanced threat protection enough on its own to protect a business?

ATP is a strong layer of email and collaboration security, but it works best as part of a broader security approach. It should sit alongside multi-factor authentication, endpoint protection, DNS filtering, and staff awareness training. The ACSC Essential Eight framework provides a practical checklist of the controls that matter most for Australian businesses across all attack surfaces.

What are the newest threats that Defender for Office 365 now defends against?

As of mid-2026, Microsoft Defender for Office 365 includes specific detection for QR code phishing, where malicious URLs are hidden inside QR codes in emails or attachments. It also detects AI-generated phishing content, mail bombing attacks, and MFA bypass attempts using adversary-in-the-middle techniques. These capabilities have been added since 2024 in response to shifts in attacker behaviour.

How do we know if our Microsoft 365 advanced threat protection is actually configured correctly?

Having the licence is not the same as having protection. Safe Attachments, Safe Links, and impersonation protection policies each need to be actively configured and applied to all users. The Microsoft Defender portal includes a configuration analyser that compares your settings to recommended baselines. A qualified IT partner can also audit your tenant and identify gaps in your current setup.

Where to from here?

If you want to know whether your Microsoft 365 environment is properly protected, we can review your Defender for Office 365 configuration and identify any gaps. Whether you are setting up ATP for the first time or want to check your existing setup is current, the team at TTA works with businesses across Brisbane and South-East Queensland to get this right. Start a conversation with us here.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.