Microsoft 365 filters a lot of spam and obvious phishing by default. Business email compromise is designed to slip past exactly that kind of filtering.
Microsoft 365 includes real, genuinely useful email filtering out of the box: spam filtering, malware scanning, and basic anti-phishing checks across every mailbox. It catches a meaningful share of obvious attacks. What it's not designed to fully stop on its own is the more targeted category: messages that look legitimate, from a sender that looks right, asking for something plausible.
Microsoft's own documentation on anti-phishing protection in Microsoft Defender for Office 365 is a good starting point for understanding exactly what's included at which licence tier — worth checking directly rather than assuming.
| Protection | Included by default | What layered security adds |
|---|---|---|
| Spam / bulk mail | Yes, strong out of the box | Refinement, fewer false positives |
| Known malware attachments | Yes | Sandboxing of unknown/novel files |
| Obvious phishing links | Yes | Time-of-click re-checking as threats evolve |
| Domain impersonation / lookalikes | Partial | Dedicated detection & alerting |
| Business email compromise | Weak — no malware to catch | Sender-behaviour analysis |
| Teams / SharePoint links | Limited | Extended protection beyond the inbox |
Business email compromise (BEC) rarely looks like a typical phishing email. There's often no suspicious link, no obvious malware attachment — just a message that appears to come from a real supplier, a real executive, or a real customer, asking for a bank detail change, an urgent invoice payment, or sensitive information. Because it doesn't trip the usual "this looks like spam" signals, it's exactly the kind of attack that slips past default filtering and relies on a person, under time pressure, making a fast decision.
Layered email security adds detection that goes beyond content scanning:
No filtering layer, however good, replaces a team that knows what to look for and feels comfortable flagging something that feels off — including when it turns out to be nothing. Security awareness training works best when it's ongoing and realistic, not a once-a-year slide deck nobody remembers by month three.
Three quick, concrete questions worth answering this week:
If any of those answers is "not sure," that's the actual starting point — not a bigger tooling purchase.
Yes, to a degree that varies by licence tier — but built-in protection is designed to catch broad, obvious threats. Targeted attacks like business email compromise are specifically designed to look legitimate enough to get past that layer.
Enforce MFA on every mailbox without exception, and put a documented, phone-based verification step in place for any bank detail or payment change request — most successful BEC attacks succeed because that second step doesn't exist.
Yes — technical filtering and trained staff catch different things. A well-crafted message that passes every technical check still relies on a person acting on it; training is what stops that last step.
Book a free security assessment and we'll show you exactly what's covered today and what isn't.