Agent skill

Defender For Office 365

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise.

MITAuto-check passedDocuments & Office

Install Defender For Office 365

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-office-365 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-for-office-365 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-for-office-365 .claude/skills/defender-for-office-365 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-for-office-365
GitHub stars
175
Token cost
~2.6k tokens
SKILL.md length
1,086 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise.

  • Works in 9 steps: Confirm licensing and mail flow — Verify… → Enable email authentication — SPF, DKIM,… → Apply preset security policies —… → …
  • Endpoint protection (use defender-for-endpoint)
  • SKILL.md covers When to use, Pick the plan, then the preset, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender For Office 365 is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Covers Plan 1 vs Plan 2 selection, preset security policies (Standard/Strict), Safe Links, Safe Attachments, anti-phishing impersonation protection, configuration analyzer drift detection, Submissions portal triage, Threat Explorer hunting, AIR, and attack simulation training. WHEN: Defender for Office 365, MDO, email…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft 365, Microsoft Defender, Microsoft SharePoint and Microsoft OneDrive. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Endpoint protection (use defender-for-endpoint)
  • M365 oversharing (use purview-copilot-oversharing)

Example prompts

  • “/defender-for-office-365”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Confirm licensing and mail flow — Verify MDO P1 vs P2 in admin centre. Confirm
  2. Enable email authentication — SPF, DKIM, and DMARC for every sending domain.
  3. Apply preset security policies — Standard preset to all users. Strict preset to a
  4. Configure impersonation protection — In the anti-phishing policy (Strict preset
  5. Tenant allow/block lists (TABL) - block first, allow rarely — Use TABL to block
  6. Configuration analyzer monthly — In security.microsoft.com → Email & collaboration →
  7. Operate via Submissions and Threat Explorer — User-reported phish flows into the
  8. AIR + automated triage — Enable AIR for user-reported phish. The investigation
  9. Attack simulation training — Run quarterly campaigns matched to current threat

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender For Office 365 loads about 2.6k tokens when it runs. Until then it costs about 253 tokens; SKILL.md has 1,086 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~253
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 1,086 words, ~2,557 tokens.

Download SKILL.mdSave it as .claude/skills/defender-for-office-365/SKILL.md (or your agent's skills folder).
name
defender-for-office-365
description
Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Covers Plan 1 vs Plan 2 selection, preset security policies (Standard/Strict), Safe Links, Safe Attachments, anti-phishing impersonation protection, configuration analyzer drift detection, Submissions portal triage, Threat Explorer hunting, AIR, and attack simulation training. WHEN: Defender for Office 365, MDO, email security policy, Safe Links, Safe Attachments, anti-phishing, anti-spoofing, impersonation protection, preset security policies, Standard preset, Strict preset, configuration analyzer, phishing protection, attack simulation training, Threat Explorer, Submissions portal, tenant allow block list, BEC, business email compromise, DMARC, MDO Plan 1 vs Plan 2. DO NOT USE for endpoint protection (use defender-for-endpoint) or M365 oversharing (use purview-copilot-oversharing).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender for Office 365

Microsoft Defender for Office 365 (MDO) protects email and collaboration workloads against phishing, malware, spoofing, and business email compromise. It provides preset policies, detonation (Safe Attachments), time-of-click URL protection (Safe Links), post-delivery detection and hunting (Threat Explorer + AIR), and attack simulation training.

When to use

Securing Exchange Online mail flow and Microsoft 365 collaboration (Teams, SharePoint, OneDrive). Use this skill for plan/preset decisions, control configuration, drift detection, and SOC operations on email incidents.

Do not use this skill for endpoint protection (defender-for-endpoint), broader cross-workload investigation (defender-xdr), or SharePoint oversharing before Copilot rollout (purview-copilot-oversharing).

Pick the plan, then the preset

If you need...Plan / SKUNotes
Safe Links, Safe Attachments, anti-phish, anti-spam, anti-malwareMDO Plan 1Bundled with M365 Business Premium and E3 add-on
Threat Explorer, Real-time detections, AIR, attack simulation training, automated investigationMDO Plan 2Bundled with M365 E5 / MDO P2
Cross-tenant secure collaboration (B2B/B2C with MDO)MDO P1 or P2Apply preset to guest senders too
PosturePreset to applyWho it fits
Default healthy baseline, low admin overheadStandard presetMost enterprises - apply to all users
High-target, regulated, or executive-heavy estateStrict presetTier-0 admins, finance, exec mailboxes
Custom carve-out (e.g. vendor with broken SPF)Custom policy with priority above presetUse sparingly - documents drift risk

Rule of thumb: apply Standard preset to all users as the floor, Strict preset to high-risk groups (executives, finance, IT admins, legal) as the ceiling. Custom policies only where presets genuinely don't fit - every custom policy is a future drift source.

Approach

  1. Confirm licensing and mail flow — Verify MDO P1 vs P2 in admin centre. Confirm Exchange Online accepts mail directly (or via an upstream gateway). MDO with a third-party secure email gateway (SEG) in front is a common pattern but reduces some detections - use Enhanced Filtering for Connectors to preserve original sender IP. Verify: Get-EnhancedFilteringConfig shows your inbound connector configured.

  2. Enable email authentication — SPF, DKIM, and DMARC for every sending domain. DMARC starts at p=none (monitor), moves to quarantine, then reject. Without DMARC, spoofing detections are weaker. Verify: DMARC at p=reject with aggregate reports flowing for 30+ days.

  3. Apply preset security policies — Standard preset to all users. Strict preset to a targeted group (executives, finance, IT admins). Presets auto-update to Microsoft's recommendations; custom policies do not. Verify: Preset policy report shows ≥ 95% of users covered by Standard or Strict.

  4. Configure impersonation protection — In the anti-phishing policy (Strict preset includes this), add the specific users (executives, CFO, exec assistants) and domains (your own, partner domains often impersonated) to impersonation protection. Mailbox intelligence on automatically learns the rest. Verify: anti-phishing policy shows 5-15 protected users (don't list everyone - dilutes detection) and 1-3 trusted domains.

  5. Tenant allow/block lists (TABL) - block first, allow rarely — Use TABL to block confirmed bad senders/URLs/files. Allow entries are temporary (30-day max) and override detections, so use sparingly and review weekly. Verify: allow list has < 20 entries and no permanent allows for high-risk domains.

  6. Configuration analyzer monthly — In security.microsoft.com → Email & collaboration → Policies & rules → Configuration analyzer. Shows drift vs Standard/Strict. Apply recommendations or document why not. Verify: drift score = 0 against the preset you target.

  7. Operate via Submissions and Threat Explorer — User-reported phish flows into the Submissions portal. Triage daily, mark false positives, update tenant allow/block lists. Use Threat Explorer (P2) for ad-hoc hunts (e.g. all messages from a sender domain in past 7 days).

  8. AIR + automated triage — Enable AIR for user-reported phish. The investigation playbook auto-pulls similar messages, soft-deletes them, and creates an incident if warranted.

  9. Attack simulation training — Run quarterly campaigns matched to current threat intelligence (e.g. payroll-themed in pay-week, vendor-themed in procurement cycle). Assign training only to clickers and credential submitters - blanket training erodes engagement.

Show full SKILL.md (464 more words)Show less

Guardrails

  • Presets > custom policies. Presets get Microsoft's tuning updates automatically. Every custom policy is a maintenance commitment.
  • Don't disable Safe Links rewriting for "user experience". The rewrite is the detection - removing it removes Safe Links entirely. Use the Do not rewrite list for specific allow-listed services instead.
  • Impersonation protection on a small specific list. Listing every user dilutes the detection. 5-15 named protected users; let mailbox intelligence handle the rest.
  • Allow entries in TABL are temporary. They override detections. 30-day max, review weekly, remove or replace with a proper exclusion.
  • DMARC reject is the goal, not p=none. p=none is a 30-day monitor stop, not a destination.
  • MDO + third-party SEG = configure Enhanced Filtering. Otherwise MDO sees the SEG IP as the sender and detections degrade.
  • Don't bypass MDO with mail flow rules. Exception rules ("skip filtering for messages from X") are how attackers slip through. Use TABL or impersonation exclusions instead.

Common anti-patterns

  • "Use only custom policies because preset is too strict" - Locks you out of Microsoft's automatic tuning. Apply preset; carve out specific exclusions.
  • "Disable Safe Links rewriting because it breaks the helpdesk link" - Removes the detection. Add the specific URL to Do not rewrite.
  • "Allow this vendor domain in TABL permanently" - Permanent allow = permanent bypass. Fix the underlying SPF/DKIM/DMARC issue at the sender or use a connector-level allow.
  • "Add all 5,000 users to impersonation protection" - Detection becomes noise. Target the top-impersonated 10-50 named users.
  • "DMARC at p=none indefinitely" - You're collecting reports but never enforcing. Quarantine within 60 days, reject within 90.
  • "User-reported phish goes to a shared mailbox we check weekly" - Use the Submissions portal so AIR and Threat Explorer fire. Shared mailbox loses the tooling.
  • "Attack simulation training assigned to everyone every quarter" - Engagement collapses. Target clickers and credential submitters only.
  • "MDO behind a third-party SEG with default config" - All inbound looks like it's from the SEG IP. Enable Enhanced Filtering for Connectors.

Example prompts

  • Apply the Standard preset to all users and Strict preset to executives and finance.
  • Configure DMARC for our domain - go from p=none to p=reject in 90 days.
  • Set up impersonation protection for our CFO and partner domains.
  • Compare current MDO settings against the Strict preset using configuration analyzer.
  • Plan MDO Plan 1 vs Plan 2 - what hunting and AIR capabilities do we lose without P2?
  • Triage user-reported phish via the Submissions portal and update tenant allow/block list.
  • Run a payroll-themed attack simulation in pay-week and assign training to clickers only.
  • Configure Enhanced Filtering for Connectors - we have a third-party SEG in front of EXO.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-for-office-365 of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender For Office 365 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender For Office 365 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender For Office 365 this skillvinayaklatthe/microsoft-security-skills175—~2.6kAutomated safety check: PassMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence
Workiq Previewmicrosoft/work-iq1k—~3.3kAutomated safety check: PassCustom licence
Msgraph Filesautomateyournetwork/netclaw676—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Msgraph Files

    automateyournetwork/netclaw

    Read OneDrive and SharePoint files via the Microsoft 365 MCP server — list folder contents, fetch item metadata, inspect versions and sharing permissions.

    676 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Msgraph Visio

    automateyournetwork/netclaw

    Upload and retrieve Visio (.vsdx) and other diagram files in OneDrive/SharePoint via the Microsoft 365 MCP server.

    676 GitHub stars~1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Defender For Office 365

What does Defender For Office 365 do?

Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise. Defender For Office 365 is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Office 365 (MDO) — protection for email and collaboration (Teams, SharePoint, OneDrive) against phishing, malware, spoofing, and business email compromise.

When should I use Defender For Office 365?

Defender For Office 365 fits situations like: endpoint protection (use defender-for-endpoint); M365 oversharing (use purview-copilot-oversharing).

How do I install Defender For Office 365 in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-office-365 -a claude-code`. Or copy the skill folder (skills/defender-for-office-365 in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-for-office-365 in your project. Claude Code loads it when a task matches its description.

How do I install Defender For Office 365 in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-office-365 -a codex`. Or copy the skill folder (skills/defender-for-office-365 in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-for-office-365 in your project. Codex loads it when a task matches its description.

Can I use Defender For Office 365 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-office-365 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-for-office-365, .gemini/skills/defender-for-office-365, .github/skills/defender-for-office-365 and .opencode/skills/defender-for-office-365 in your project.

What does Defender For Office 365 need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender For Office 365 is instructions for the agent only.

Does Defender For Office 365 access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Defender For Office 365 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender For Office 365 use?

Defender For Office 365 is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender For Office 365 use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender For Office 365?

Skills that share tags, products or a category with Defender For Office 365: Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars), Workiq (microsoft/work-iq, 1k stars) and Workiq Preview (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender For Office 365?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.