Microsoft 365 Advanced Threat Protection (ATP) — now known as Microsoft Defender for Office 365 — is a cloud-based security solution that protects email and collaboration tools such as Outlook, SharePoint, OneDrive and Teams from phishing, malware, ransomware and other sophisticated attacks.
Microsoft Defender for Office 365 protects organisations by scanning incoming email messages, links, and attachments for malicious content and blocking harmful files in real time. It uses machine learning, behavioural analysis, and threat intelligence to stop attacks before they land, and is particularly effective at detecting and preventing malicious emails — helping organisations avoid business email compromise (BEC) scams and other email-based attacks.
Beyond detection and prevention, ATP gives security teams the tools to identify, prioritise and remediate threats efficiently — including automated investigation and response (AIR), which cuts the time and effort needed to manage incidents, and threat and vulnerability management (TVM) for insight into your security posture. By integrating with other Microsoft security solutions, it delivers a comprehensive approach that protects email systems and collaborative platforms alike.
- ATP is the old name for Microsoft Defender for Office 365 — the same cloud security service.
- Three core protections: Safe Attachments (file detonation), Safe Links (time-of-click URL checks) and anti-phishing (impersonation detection).
- Protection spans Outlook email plus SharePoint, OneDrive and Teams.
- Automated investigation and response speeds up triage and remediation.
- It’s included in Business Premium and E5 — but only protects you once it’s correctly configured and maintained.
Every message is detonated, its links rewritten and checked, and its sender verified — threats are blocked before clean mail reaches the inbox.
Key features of Office 365 ATP
ATP is equipped with a comprehensive set of features designed to protect users from advanced cyber threats. Safe Attachments scans email attachments for malicious code, blocking harmful files before they reach users’ inboxes. Safe Links provides real-time scanning of URLs in emails and web pages, blocking malicious links and displaying warning pages to alert users. It also offers anti-phishing protection, using machine learning and mailbox intelligence to detect and block phishing attempts — empowering organisations to protect their users, files, and links.
| Capability | What it does | Key functions | Applies to | Admin outcomes |
|---|---|---|---|---|
| Safe Attachments (email) | Analyses email attachments in a virtual sandbox prior to delivery to identify and block malware. | Real-time scanning; detonation in a secure virtual environment; blocks malicious content and files in incoming messages. | Email (Outlook); SharePoint; OneDrive; Teams | Prevents delivery of malware and ransomware; reduces risk surface across collaboration tools. |
| Safe Attachments (Teams) | Scans files shared in Microsoft Teams to verify safety. | Continuous analysis of shared files; block / open / copy / move / share controls on harmful files. | Teams | Stops propagation of infected content inside chats and channels. |
| Safe Links | Analyses URLs in emails and Office documents; rewrites links to route through Microsoft’s security service. | URL scanning and rewriting; time-of-click checks for malicious links; protection against newly identified threats. | Email; Office documents; Teams | Neutralises phishing and drive-by attacks even if a URL turns malicious later. |
| Anti-phishing policies | Uses machine learning to detect phishing where senders mimic trusted entities. | Impersonation detection; user and domain impersonation protection; reduces business email compromise (BEC). | Blocks spoofing and impersonation; protects executives and high-risk users. | |
| Threat intelligence & response | Automates triage and response; enables proactive discovery of indicators of compromise. | Automated Investigation and Response (AIR); threat hunting; IoCs; suspicious-activity detection. | Tenant-wide (email, collaboration, identities) | Faster detection, prioritisation and remediation; lowers MTTR. |
| Attack simulation training | Runs realistic phishing exercises with genuine, non-malicious payloads to improve user awareness. | Authentic phishing simulations; tailored training; personalised learning based on outcomes. | End users (organisation-wide) | Modifies user behaviour; reduces likelihood of successful phishing attacks. |
| Real-time reports & insights | Provides near-instant visibility into threats and detailed reporting on protection posture. | Threat Explorer and real-time detection; reporting on email security, threat status and mail latency. | Security portals (Defender / M365) | Accelerates investigations; measures effectiveness; informs tuning and policy changes. |
| Microsoft security ecosystem | Native connection with other Microsoft security tools for multi-layered defence. | Integrates with Defender for Endpoint, Exchange Online Protection, Defender for Identity and Azure; centralised management via Microsoft Endpoint Manager. | Devices; identities; email; cloud | Uniform policies, improved visibility, more efficient response. |
| SharePoint, OneDrive & Teams | Adds a layer by scanning files at upload/share; blocks harmful files from being opened, copied, moved or shared. | Safe Attachments for SPO/OD/Teams; real-time scanning and notifications; detonation; alerts and reports. | SharePoint; OneDrive; Teams | Swift detection and containment; admin notifications and comprehensive reporting. |
Threat protection capabilities
ATP delivers comprehensive threat protection to shield organisations from sophisticated cyberattacks. Dynamic delivery enables real-time scanning of email attachments and links without delaying message delivery. By integrating with Exchange Online Protection, ATP adds an extra layer of security to your email environment. The compliance centre lets organisations customise security policies and generate detailed reports, supporting regulatory requirements and internal security standards. Using the advanced security infrastructure of the Microsoft Cloud, ATP provides strong defence against malicious content — including viruses, malware, and phishing attacks — keeping your organisation secure against evolving threats.
The benefits of ATP
Implementing Office 365 Advanced Threat Protection brings a wide range of benefits to organisations seeking to safeguard their business, users, and data. By defending against malicious attacks and sophisticated cyber threats, ATP helps minimise the risk of data breaches and security incidents. Its automated investigation and response capabilities enable rapid action against detected threats, reducing downtime and enhancing overall security posture. Native integration with Microsoft Teams and other collaboration tools ensures protection extends across all platforms, supporting secure communication and file sharing. The result is improved compliance, reduced risk, and a more resilient security environment — an essential investment for any business.
How it fits together
Microsoft 365 ecosystem
Defender for Office 365 works closely with Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams — extending protection across every collaboration platform and your document libraries.
Extended detection & response
It collaborates with Microsoft Defender for Endpoint to deliver XDR — a cohesive security stance across email, endpoints and cloud applications.
Regulatory compliance
Comprehensive audit logs and reports help meet obligations including Australia’s Cyber Security Act 2024 and the ASD Essential Eight, while supporting data analysis and productivity.
Security posture management
Built-in tools recommend and apply security configurations, helping you continuously strengthen defences against email and collaboration threats.
User education and awareness
- Policy tips and notifications. Defender for Office 365 surfaces guidance and alerts that inform users about possible threats and promote safe practices — building a culture of security awareness.
- Simulations and training. Built-in phishing-simulation tools and specialised training programs help users recognise and react to phishing attempts and other threats.
- Priority account protection. Advanced measures and configuration options for high-risk accounts — executives and other sensitive users — ensure the most critical accounts get the highest level of protection.
Getting ATP actually working for you
ATP only protects you when it’s switched on and configured correctly. Safe Attachments, Safe Links, anti-phishing policies, priority-account protection and attack-simulation training all need to be set up, tuned and monitored — and kept current as threats evolve. Too often the licences are paid for but the protection is left at defaults.
PIP’s managed Microsoft 365 service deploys, configures and manages Microsoft Defender for Office 365 as part of your subscription — so the protection you’re paying for is active, tuned to your business, and watched by an Australian team. Defender for Office 365 is included with Microsoft 365 Business Premium and E5, and we’ll help you pick and roll out the right plan.
Explore PIP’s managed Microsoft 365 →Advanced protection for every business
In Australia, Microsoft Office 365 Advanced Threat Protection is a vital security solution for businesses seeking to protect themselves from suspicious behaviour and advanced threats. With Safe Attachments, Safe Links and anti-phishing at its core, ATP provides strong protection against phishing, malicious links and other sophisticated threats. By integrating with Microsoft Defender and using machine learning and mailbox intelligence, it delivers an enhanced security posture and automated investigation capabilities. As a cloud-based service, it’s straightforward to implement and manage — so businesses gain stronger security, improved compliance, and reduced risk, safeguarding their users, data and operations.
Common questions
Is Microsoft ATP the same as Microsoft Defender for Office 365?
What does ATP Safe Attachments do?
What is the difference between Safe Attachments and Safe Links?
Which Microsoft 365 plans include Defender for Office 365 (ATP)?
Let PIP switch on and manage your protection
Defender for Office 365 is only as good as its configuration. PIP deploys, tunes and manages your Microsoft 365 security — so the protection is real, not just licensed.
Explore managed Microsoft 365 → Or contact PIP today →
