Reference

Exchange Security Policy

Microsoft Defender for Office 365 / EOP security policies — anti-phish, anti-spam, Safe Links, Safe Attachments, malware filter, outbound spam, and quarantine policies.

Part of the Exchange inventory.

Scan settings

Default scanning intervalAllowed scanning intervalsData removal during incremental scan
WeeklyDaily, Weekly, Bi-Weekly, Monthly, Never, InitialYes

Properties

Property Type Description Automation placeholder
Action String Primary action of the policy (e.g. Block, Replace, Quarantine, Redirect). {{ExchangeSecurityPolicy.Action}}
Allow Click Through Boolean Whether users can click-through Safe Links warnings. {{ExchangeSecurityPolicy.AllowClickThrough}}
Allowed Sender Domains String[] Domains allow-listed by this anti-spam policy. Highest-risk anti-spam misconfig per Microsoft guidance. {{ExchangeSecurityPolicy.AllowedSenderDomains}}
Allowed Senders String[] {{ExchangeSecurityPolicy.AllowedSenders}}
Bulk Threshold Int32 {{ExchangeSecurityPolicy.BulkThreshold}}
Initially Scanned DateTime Shows when this object was initially found in a scan. {{ExchangeSecurityPolicy.CreatedTime}}
Policy Name String {{ExchangeSecurityPolicy.DisplayName}}
Do Not Rewrite URLs String[] {{ExchangeSecurityPolicy.DoNotRewriteUrls}}
Drift From Standard Baseline Boolean True when the policy deviates from Microsoft's recommended Standard preset. {{ExchangeSecurityPolicy.DriftFromStandard}}
Drift From Strict Baseline Boolean True when the policy deviates from Microsoft's recommended Strict preset. {{ExchangeSecurityPolicy.DriftFromStrict}}
Enable File Filter Boolean {{ExchangeSecurityPolicy.EnableFileFilter}}
Enable Mailbox Intelligence Boolean {{ExchangeSecurityPolicy.EnableMailboxIntelligence}}
Enable Safe Links For Email Boolean {{ExchangeSecurityPolicy.EnableSafeLinksForEmail}}
Enable Safe Links For Office Boolean {{ExchangeSecurityPolicy.EnableSafeLinksForOffice}}
Enable Safe Links For Teams Boolean {{ExchangeSecurityPolicy.EnableSafeLinksForTeams}}
Enable Safe List Boolean {{ExchangeSecurityPolicy.EnableSafeList}}
Enable Spoof Intelligence Boolean {{ExchangeSecurityPolicy.EnableSpoofIntelligence}}
Enable Targeted User Protection Boolean {{ExchangeSecurityPolicy.EnableTargetedUserProtection}}
Enabled Boolean {{ExchangeSecurityPolicy.Enabled}}
End User Quarantine Permissions String {{ExchangeSecurityPolicy.EndUserQuarantinePermissions}}
File Types String[] {{ExchangeSecurityPolicy.FileTypes}}
High Confidence Phish Action String {{ExchangeSecurityPolicy.HighConfidencePhishAction}}
High Confidence Spam Action String {{ExchangeSecurityPolicy.HighConfidenceSpamAction}}
IP Allow List String[] {{ExchangeSecurityPolicy.IPAllowList}}
IP Block List String[] {{ExchangeSecurityPolicy.IPBlockList}}
Impersonation Protection State String {{ExchangeSecurityPolicy.ImpersonationProtectionState}}
Is Default Boolean {{ExchangeSecurityPolicy.IsDefault}}
Last scan update DateTime Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. {{ExchangeSecurityPolicy.LastModifiedTime}}
Phish Spam Action String {{ExchangeSecurityPolicy.PhishSpamAction}}
Phish Threshold Level Int32 1 (Standard) to 4 (Most aggressive). {{ExchangeSecurityPolicy.PhishThresholdLevel}}
Policy Id String {{ExchangeSecurityPolicy.PolicyId}}
Policy Type String Allowed values: AntiPhish, AntiSpam, ConnectionFilter, Malware, OutboundSpam, Quarantine, SafeAttachment, SafeLinks. {{ExchangeSecurityPolicy.PolicyType}}
Quarantine Retention Days Int32 {{ExchangeSecurityPolicy.QuarantineRetentionDays}}
Redirect Address String {{ExchangeSecurityPolicy.RedirectAddress}}
Risk Score Int32 Stores risk score {{ExchangeSecurityPolicy.RiskScore}}
Risk Score Update DateTime Stores risk score update {{ExchangeSecurityPolicy.RiskScoreLastUpdate}}
Risk Score Value String Stores risk score value like Low_Low {{ExchangeSecurityPolicy.RiskScoreValue}}
Safe Attachment Action String Allowed values: Allow, Block, DynamicDelivery, Replace. {{ExchangeSecurityPolicy.SafeAttachmentAction}}
Spam Action String {{ExchangeSecurityPolicy.SpamAction}}
Targeted Users To Protect String[] {{ExchangeSecurityPolicy.TargetedUsersToProtect}}
Track Clicks Boolean {{ExchangeSecurityPolicy.TrackClicks}}
ZAP Enabled Boolean Zero-hour Auto Purge enabled. {{ExchangeSecurityPolicy.ZapEnabled}}

Relations

This object does currently not have any relations.

Segments

Segment Description
Disabled security policies Defender and EOP security policies that are currently disabled.
Policies drifting from Standard Defender and EOP policies that deviate from Microsoft's Standard protection baseline.

Actions

This object does currently not have any actions.

Policy Severity Description
Defender policy drifts from Standard baseline Medium Detects Defender / EOP security policies that deviate from Microsoft's recommended Standard preset.
Safe Links policy allows click-through Medium Detects Safe Links policies where users can click through warnings on phishing URLs.

Last updated: 7/19/2026