What is Microsoft Office 365 Advanced Threat Protection ATP

What is microsoft office 365 advanced threat protection atp

Microsoft 365 Advanced Threat Protection (ATP) — now known as Microsoft Defender for Office 365 — is a cloud-based security solution that protects email and collaboration tools such as Outlook, SharePoint, OneDrive and Teams from phishing, malware, ransomware and other sophisticated attacks.

Microsoft Defender for Office 365 protects organisations by scanning incoming email messages, links, and attachments for malicious content and blocking harmful files in real time. It uses machine learning, behavioural analysis, and threat intelligence to stop attacks before they land, and is particularly effective at detecting and preventing malicious emails — helping organisations avoid business email compromise (BEC) scams and other email-based attacks.

Beyond detection and prevention, ATP gives security teams the tools to identify, prioritise and remediate threats efficiently — including automated investigation and response (AIR), which cuts the time and effort needed to manage incidents, and threat and vulnerability management (TVM) for insight into your security posture. By integrating with other Microsoft security solutions, it delivers a comprehensive approach that protects email systems and collaborative platforms alike.

The short version
  • ATP is the old name for Microsoft Defender for Office 365 — the same cloud security service.
  • Three core protections: Safe Attachments (file detonation), Safe Links (time-of-click URL checks) and anti-phishing (impersonation detection).
  • Protection spans Outlook email plus SharePoint, OneDrive and Teams.
  • Automated investigation and response speeds up triage and remediation.
  • It’s included in Business Premium and E5 — but only protects you once it’s correctly configured and maintained.
Safe Attachments Safe Links Anti-phishing Inbound Delivered

Every message is detonated, its links rewritten and checked, and its sender verified — threats are blocked before clean mail reaches the inbox.

Capabilities

Key features of Office 365 ATP

ATP is equipped with a comprehensive set of features designed to protect users from advanced cyber threats. Safe Attachments scans email attachments for malicious code, blocking harmful files before they reach users’ inboxes. Safe Links provides real-time scanning of URLs in emails and web pages, blocking malicious links and displaying warning pages to alert users. It also offers anti-phishing protection, using machine learning and mailbox intelligence to detect and block phishing attempts — empowering organisations to protect their users, files, and links.

Microsoft Defender for Office 365 (ATP) — capabilities at a glance
CapabilityWhat it doesKey functionsApplies toAdmin outcomes
Safe Attachments (email)Analyses email attachments in a virtual sandbox prior to delivery to identify and block malware.Real-time scanning; detonation in a secure virtual environment; blocks malicious content and files in incoming messages.Email (Outlook); SharePoint; OneDrive; TeamsPrevents delivery of malware and ransomware; reduces risk surface across collaboration tools.
Safe Attachments (Teams)Scans files shared in Microsoft Teams to verify safety.Continuous analysis of shared files; block / open / copy / move / share controls on harmful files.TeamsStops propagation of infected content inside chats and channels.
Safe LinksAnalyses URLs in emails and Office documents; rewrites links to route through Microsoft’s security service.URL scanning and rewriting; time-of-click checks for malicious links; protection against newly identified threats.Email; Office documents; TeamsNeutralises phishing and drive-by attacks even if a URL turns malicious later.
Anti-phishing policiesUses machine learning to detect phishing where senders mimic trusted entities.Impersonation detection; user and domain impersonation protection; reduces business email compromise (BEC).EmailBlocks spoofing and impersonation; protects executives and high-risk users.
Threat intelligence & responseAutomates triage and response; enables proactive discovery of indicators of compromise.Automated Investigation and Response (AIR); threat hunting; IoCs; suspicious-activity detection.Tenant-wide (email, collaboration, identities)Faster detection, prioritisation and remediation; lowers MTTR.
Attack simulation trainingRuns realistic phishing exercises with genuine, non-malicious payloads to improve user awareness.Authentic phishing simulations; tailored training; personalised learning based on outcomes.End users (organisation-wide)Modifies user behaviour; reduces likelihood of successful phishing attacks.
Real-time reports & insightsProvides near-instant visibility into threats and detailed reporting on protection posture.Threat Explorer and real-time detection; reporting on email security, threat status and mail latency.Security portals (Defender / M365)Accelerates investigations; measures effectiveness; informs tuning and policy changes.
Microsoft security ecosystemNative connection with other Microsoft security tools for multi-layered defence.Integrates with Defender for Endpoint, Exchange Online Protection, Defender for Identity and Azure; centralised management via Microsoft Endpoint Manager.Devices; identities; email; cloudUniform policies, improved visibility, more efficient response.
SharePoint, OneDrive & TeamsAdds a layer by scanning files at upload/share; blocks harmful files from being opened, copied, moved or shared.Safe Attachments for SPO/OD/Teams; real-time scanning and notifications; detonation; alerts and reports.SharePoint; OneDrive; TeamsSwift detection and containment; admin notifications and comprehensive reporting.
Under the hood

Threat protection capabilities

ATP delivers comprehensive threat protection to shield organisations from sophisticated cyberattacks. Dynamic delivery enables real-time scanning of email attachments and links without delaying message delivery. By integrating with Exchange Online Protection, ATP adds an extra layer of security to your email environment. The compliance centre lets organisations customise security policies and generate detailed reports, supporting regulatory requirements and internal security standards. Using the advanced security infrastructure of the Microsoft Cloud, ATP provides strong defence against malicious content — including viruses, malware, and phishing attacks — keeping your organisation secure against evolving threats.

Why it matters

The benefits of ATP

Implementing Office 365 Advanced Threat Protection brings a wide range of benefits to organisations seeking to safeguard their business, users, and data. By defending against malicious attacks and sophisticated cyber threats, ATP helps minimise the risk of data breaches and security incidents. Its automated investigation and response capabilities enable rapid action against detected threats, reducing downtime and enhancing overall security posture. Native integration with Microsoft Teams and other collaboration tools ensures protection extends across all platforms, supporting secure communication and file sharing. The result is improved compliance, reduced risk, and a more resilient security environment — an essential investment for any business.

Integration & compliance

How it fits together

Microsoft 365 ecosystem

Defender for Office 365 works closely with Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams — extending protection across every collaboration platform and your document libraries.

Extended detection & response

It collaborates with Microsoft Defender for Endpoint to deliver XDR — a cohesive security stance across email, endpoints and cloud applications.

Regulatory compliance

Comprehensive audit logs and reports help meet obligations including Australia’s Cyber Security Act 2024 and the ASD Essential Eight, while supporting data analysis and productivity.

Security posture management

Built-in tools recommend and apply security configurations, helping you continuously strengthen defences against email and collaboration threats.

People & awareness

User education and awareness

  • Policy tips and notifications. Defender for Office 365 surfaces guidance and alerts that inform users about possible threats and promote safe practices — building a culture of security awareness.
  • Simulations and training. Built-in phishing-simulation tools and specialised training programs help users recognise and react to phishing attempts and other threats.
  • Priority account protection. Advanced measures and configuration options for high-risk accounts — executives and other sensitive users — ensure the most critical accounts get the highest level of protection.

Getting ATP actually working for you

ATP only protects you when it’s switched on and configured correctly. Safe Attachments, Safe Links, anti-phishing policies, priority-account protection and attack-simulation training all need to be set up, tuned and monitored — and kept current as threats evolve. Too often the licences are paid for but the protection is left at defaults.

PIP’s managed Microsoft 365 service deploys, configures and manages Microsoft Defender for Office 365 as part of your subscription — so the protection you’re paying for is active, tuned to your business, and watched by an Australian team. Defender for Office 365 is included with Microsoft 365 Business Premium and E5, and we’ll help you pick and roll out the right plan.

Explore PIP’s managed Microsoft 365
For Australian business

Advanced protection for every business

In Australia, Microsoft Office 365 Advanced Threat Protection is a vital security solution for businesses seeking to protect themselves from suspicious behaviour and advanced threats. With Safe Attachments, Safe Links and anti-phishing at its core, ATP provides strong protection against phishing, malicious links and other sophisticated threats. By integrating with Microsoft Defender and using machine learning and mailbox intelligence, it delivers an enhanced security posture and automated investigation capabilities. As a cloud-based service, it’s straightforward to implement and manage — so businesses gain stronger security, improved compliance, and reduced risk, safeguarding their users, data and operations.

FAQ

Common questions

Is Microsoft ATP the same as Microsoft Defender for Office 365?
Yes. Advanced Threat Protection (ATP) is the former name — it is now called Microsoft Defender for Office 365. It is the same cloud-based service that protects email and collaboration tools such as Outlook, SharePoint, OneDrive and Teams.
What does ATP Safe Attachments do?
Safe Attachments detonates email attachments in an isolated virtual environment before delivery, so malware and ransomware are identified and blocked before they reach a user’s inbox. The same scanning extends to files shared in SharePoint, OneDrive and Teams.
What is the difference between Safe Attachments and Safe Links?
Safe Attachments analyses files, while Safe Links analyses URLs. Safe Links rewrites links to route through Microsoft’s checking service and re-checks them at time-of-click, so a link that turns malicious after delivery is still blocked.
Which Microsoft 365 plans include Defender for Office 365 (ATP)?
It is included in Microsoft 365 Business Premium and the E5 enterprise plan, and can be added to other plans. PIP can configure and manage it for you as part of a managed Microsoft 365 subscription.
Managed Microsoft 365

Let PIP switch on and manage your protection

Defender for Office 365 is only as good as its configuration. PIP deploys, tunes and manages your Microsoft 365 security — so the protection is real, not just licensed.

Explore managed Microsoft 365 Or contact PIP today →
Scroll to Top