Exchange Online Protection overview

Applies to

  • Exchange Online Protection
  • Microsoft Defender for Office 365 plan 1 and plan 2
  • Microsoft 365 Defender

Exchange Online Protection (EOP) is the deject-based filtering service that protects your arrangement against spam, malware, and other electronic mail threats. EOP is included in all Microsoft 365 organizations with Commutation Online mailboxes.

Note

EOP is too available past itself to protect on-bounds mailboxes and in hybrid environments to protect on-premises Exchange mailboxes. For more than information, see Standalone Exchange Online Protection.

The steps to prepare EOP security features and a comparison to the added security that you get in Microsoft Defender for Part 365, run into protect against threats. The recommended settings for EOP features are bachelor in Recommended settings for EOP and Microsoft Defender for Role 365 security.

The rest of this article explains how EOP works and the features that are bachelor in EOP.

How EOP works

To empathise how EOP works, it helps to see how it processes incoming email:

Graphic of email from the internet or Customer feedback passing into EOP and through the Connection, Anti-malware, Mailflow Rules-slash-Policy Filtering, and Content Filtering, before the verdict of either junk mail or quarantine, or end user mail delivery

  1. When an incoming bulletin enters EOP, it initially passes through connection filtering, which checks the sender'south reputation. The bulk of spam is stopped at this point and rejected by EOP. For more information, run into Configure connection filtering.

  2. Then the bulletin is inspected for malware. If malware is institute in the message or the attachment(s) the bulletin is delivered to quarantine. Past default, only admins can view and interact with malware quarantined messages. Only, admins can create and use quarantine policies to specify what users are immune to do to quarantined messages. To acquire more virtually malware protection, see Anti-malware protection in EOP.

  3. The bulletin continues through policy filtering, where it's evaluated against any mail flow rules (as well known as ship rules) that you lot've created. For example, a rule can transport a notification to a manager when a message arrives from a specific sender.

    In on-bounds arrangement with Exchange Enterprise CAL with Services licenses, Data loss prevention (DLP) checks in EOP also happen at this point.

  4. The bulletin passes through content filtering (anti-spam and anti-spoofing) where harmful messages are identified as spam, loftier confidence spam, phishing, loftier confidence phishing, or bulk (anti-spam policies) or spoofing (spoof settings in anti-phishing policies). You tin configure the action to take on the bulletin based on the filtering verdict (quarantine, move to the Junk Email folder, etc.), and what users tin can do to the quarantined messages using quarantine policies. For more than information, see Configure anti-spam policies and Configure anti-phishing policies in EOP.

A message that successfully passes all of these protection layers is delivered to the recipients.

For more information, encounter Order and precedence of email protection.

EOP datacenters

EOP runs on a worldwide network of datacenters that are designed to provide the best availability. For example, if a datacenter becomes unavailable, email messages are automatically routed to another datacenter without any interruption in service. Servers in each datacenter accept messages on your behalf, providing a layer of separation between your arrangement and the internet, thereby reducing load on your servers. Through this highly available network, Microsoft can ensure that email reaches your organization in a timely manner.

EOP performs load balancing between datacenters but only within a region. If you're provisioned in one region, all your messages will be processed using the mail routing for that region.

EOP features

This department provides a high-level overview of the primary features that are available in EOP.

For data well-nigh requirements, important limits, and feature availability across all EOP subscription plans, see the Exchange Online Protection service clarification.

Notes:

  • EOP uses several URL block lists that help detect known malicious links within messages.
  • EOP uses a vast listing of domains that are known to send spam.
  • EOP uses multiple anti-malware engines assist to automatically protect our customers at all times.
  • EOP inspects the active payload in the bulletin body and all message attachments for malware.
  • For recommended values for protection policies, encounter Recommended settings for EOP and Microsoft Defender for Part 365 security.
  • For quick instructions to configure protection policies, see Protect against threats.
Feature Comments
Protection
Anti-malware Anti-malware protection in EOP

Anti-malware protection FAQ

Configure anti-malware policies in EOP

Inbound anti-spam Anti-spam protection in EOP

Anti-spam protection FAQ

Configure anti-spam policies in EOP

Outbound anti-spam Outbound spam protection in EOP

Configure outbound spam filtering in EOP

Control automatic external email forwarding in Microsoft 365

Connection filtering Configure connection filtering
Anti-phishing Anti-phishing policies in Microsoft 365

Configure anti-phishing policies in EOP

Anti-spoofing protection Spoof intelligence insight in EOP

Manage the Tenant Allow/Cake List

Zero-hour auto purge (ZAP) for delivered malware, spam, and phishing messages ZAP in Substitution Online
Preset security policies Preset security policies in EOP and Microsoft Defender for Part 365

Configuration analyzer for protection policies in EOP and Microsoft Defender for Part 365

Tenant Let/Block Listing Manage the Tenant Allow/Block Listing
Block lists for message senders Create blocked sender lists in EOP
Allow lists for bulletin senders Create prophylactic sender lists in EOP
Directory Based Edge Blocking (DBEB) Use Directory Based Edge Blocking to reject messages sent to invalid recipients
Quarantine and submissions
Admin submission Apply Admin submission to submit suspected spam, phish, URLs, and files to Microsoft
User submissions (custom mailbox) User submissions policy
Quarantine - admins Manage quarantined messages and files as an admin in EOP

Quarantined messages FAQ

Report messages and files to Microsoft

Anti-spam message headers in Microsoft 365

You can analyze the message headers of quarantined messages using the Message Header Analyzer at.

Quarantine - end-users Discover and release quarantined messages as a user in EOP

Employ quarantine notifications to release and study quarantined letters

Quarantine policies

Mail catamenia
Mail flow rules Mail flow rules (transport rules) in Exchange Online

Postal service flow rule weather condition and exceptions (predicates) in Exchange Online

Mail service flow rule actions in Exchange Online

Manage postal service flow rules in Exchange Online

Mail flow dominion procedures in Exchange Online

Accepted domains Manage accepted domains in Exchange Online
Connectors Configure mail flow using connectors in Exchange Online
Enhanced Filtering for Connectors Enhanced filtering for connectors in Exchange Online
Monitoring
Bulletin trace Bulletin trace

Bulletin trace in the Exchange admin center

Email & collaboration reports View email security reports
Mail menstruum reports View mail period reports

Postal service flow reports in the Exchange admin middle

Mail service menses insights Mail flow insights

Mail flow insights in the Exchange admin centre

Auditing reports Auditing reports in the Substitution admin heart
Alert policies Alert policies
Service Level Agreements (SLAs) and back up
Spam effectiveness SLA > 99%
False positive ratio SLA < i:250,000
Virus detection and blocking SLA 100% of known viruses
Monthly uptime SLA 99.999%
Phone and web technical back up 24 hours a day, seven days a week Assist and back up for EOP.
Other features
A geo-redundant global network of servers EOP runs on a worldwide network of datacenters that are designed to help provide the best availability. For more information, see the EOP datacenters section earlier in this article.
Message queuing when the on-premises server cannot have mail Messages in deferral remain in our queues for one solar day. Message retry attempts are based on the fault we get dorsum from the recipient'southward post organisation. On average, messages are retried every 5 minutes. For more data, meet EOP queued, deferred, and bounced messages FAQ.
Part 365 Message Encryption available equally an addition For more information, see Encryption in Office 365.