What you are evaluating
Plan 2 is the scored scope. Exchange Online filtering, Plan 1 and Plan 2 are not interchangeable; cross-product endpoint response and additional identity products are outside this assessment.
A useful evaluation context
A useful comparison for a Microsoft 365 organization that wants advanced mail investigation within its existing provider; independently test its important mail paths.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Safe Attachments and other threat policies add controls for supported messages and collaboration content.
- Plan 2 provides Threat Explorer, incidents and automated investigation and response.
- Quarantine policies distinguish user visibility, release requests and administrator-controlled release.
Where it fits in the work
- Confirm Plan 2 entitlement and deploy threat policies to a test population.
- Inspect a synthetic message in Explorer and connect its verdict to the applied policy.
- Approve the appropriate action and verify quarantine or restoration in the mailbox.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A harmless test attachment is deliberately quarantined in a training mailbox.
Evidence to look for
Show the message evidence and explain why an end user can request release but cannot override certain malware or high-confidence phishing restrictions.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which users and shared mailboxes require the selected license?
- Who can inspect message content and approve release?
- Which collaboration workloads receive the same policy and which have different behavior?
Names you may encounter: Microsoft Defender for O365 · MDO. Historical names do not establish current availability or feature equivalence.