The Security Feature Most Microsoft 365 Admins Ignore

image

One of the first things I do when looking at a Microsoft 365 environment is check what security is actually doing. Not what has been configured. Not what the Secure Score says. Not what someone remembers setting up six months ago. I want to see what is really happening right now.

That’s why I’m a big fan of the reporting options built into Microsoft Defender for Office 365.

Too many organisations spend time configuring Safe Links, Safe Attachments, anti-phishing policies and quarantine settings, then never look back. The assumption is that because the settings exist, they must be working. In reality, security is something you need to measure continuously, not configure once and forget. The Microsoft documentation highlights a range of Defender for Office 365 reports that provide visibility into how email protection is performing and what threats are being stopped before they reach users. View Defender for Office 365 reports [learn.microsoft.com]

Security Is About Evidence

I regularly see organisations investing in security tools but struggling to answer simple questions:

  • How much phishing is being blocked?

  • Are malicious attachments being detected?

  • How quickly is email being processed?

  • Are threats still arriving in user mailboxes?

The Defender reports help answer those questions.

The real value isn’t the graphs and dashboards. The value comes from having evidence. Security conversations change dramatically when you can point to data rather than assumptions.

Imagine sitting down with management and showing that thousands of malicious messages were blocked last month before users ever saw them. That’s a much stronger discussion than simply saying, “Our email security is working.”

It’s Not Just About Blocking Threats

One report that often catches my attention is mail latency. Security processing adds time to message delivery, particularly when attachments need deeper inspection. The report helps you understand whether protection measures are impacting mail flow. Mail latency report [learn.microsoft.com]

Another area worth reviewing is post-delivery activity. No security platform catches everything immediately. Sometimes a threat is identified after a message has already arrived in a mailbox. Defender’s automated remediation features can remove those messages automatically, but unless you’re reviewing reports, you may never know how often that’s happening. Post-delivery activities report [learn.microsoft.com]

This is an important lesson for any organisation using Microsoft 365. Security isn’t only about prevention. It’s also about detection and response.

Why This Matters More in the Age of Copilot

As organisations adopt Microsoft 365 Copilot, the quality and security of their Microsoft 365 environment becomes even more important.

Copilot works across Outlook, Teams, SharePoint and OneDrive. The more information available inside Microsoft 365, the more valuable Copilot becomes. However, that also means security teams need confidence that threats are being managed effectively.

I’ve seen organisations focus heavily on Copilot deployment while overlooking the visibility tools already sitting inside Microsoft Defender. Before chasing the next AI capability, make sure you understand what is happening inside your environment today.

A practical example might be reviewing a phishing campaign shown in Defender reports and then using Microsoft 365 Copilot in Excel to analyse trends over time or prepare management summaries from the collected data. That’s a real-world workflow that combines security visibility with AI assistance.

Stop Flying Blind

One of the biggest mistakes I see in small and medium businesses is treating security as a set-and-forget exercise. Security policies get deployed, everyone feels confident, and then nobody checks whether the controls are actually delivering the expected outcome.

The Defender for Office 365 reports provide the missing feedback loop.

If you’re already paying for Microsoft Defender for Office 365 through licences such as Microsoft 365 Business Premium, E5 or Defender for Office 365 plans, these reports are often sitting there waiting to be used. Defender for Office 365 reports [learn.microsoft.com]

My recommendation is simple. Schedule time every month to review the data. Look at what is being blocked, what is slipping through, and how protection is performing over time. Trends are often more important than individual incidents.

Security isn’t about having controls. It’s about knowing whether those controls are working.

And in my experience, the organisations that regularly review their security reports are almost always in a stronger position than those that don’t.

Keeping tabs on Azure costs via email

A common concern that holds many back from using all the resources available in Azure is consumption billing aka being billed for what you use rather than a flat fee as you get with Microsoft 365 services.

Here’s a way to keep an eye on those costs daily via email.

Firstly, login to the Azure portal as an administrator and then navigate to Cost Management + Billing. Next, you want to set up the report that you want to see daily.

Screenshot 2025-01-19 094010

For me I want to see Cost Analysis for the current monthly with accumulated costs, grouped by resource, granularity daily and as a stacked column as shown above. When you have it the way you want select the Save option on the menu at the top of the page.

Screenshot 2025-01-19 095243

You’ll be asked for a name, as you see above. Select Save when complete. 

Screenshot 2025-01-19 095532

Also on the menu at the top, now select Subscribe as shown above.

Screenshot 2025-01-19 095742

Select the Add option from the Subscribe to emails option that appears on the right as shown above.

Screenshot 2025-01-19 100019

You should see the View you just saved at the top. Now complete the rest of the fields as desired. Personally, I select the option to include a CSV and want the report every day. The only challenge is that you can only specify a maximum end date 12 months out from the day you configure this. You’ll need to return annually to update this.

Screenshot 2025-01-19 100354

Select Save at the bottom of screen and you should now see your configuration listed as shown above.

Screenshot 2025-01-19 100809

You’ll get a summary email confirming these settings as shown above.

Screenshot 2025-01-19 100531

You should now start receiving a summary email on at the frequency your selected as shown above. You’ll see a screen shot of the report and a CSV attachment if you elected to include that.

Hopefully, this option provides greater piece of mind when it comes to monitoring costs with Azure. Remember, you can create as many subscription reports as you want to see a range of different details if desired.

Scheduling compliance reports

image

If you go into the Microsoft 365 Security portal and locate the Reports option from the menu on the left and expand it, you should find the Dashboard option. This option, when selected, will show a range of reports like that shown above. You can get more details by simply selecting the body of the tile you wish to view. Here, I’ll select the Spam detections tile to get further information.

image

You’ll now see a more focused report but you’ll also notice that many graphs have the Create schedule in the top right hand corner as shown. Selecting this allows you to schedule a report to be delivered via email.

image

By selecting Create schedule you should see a tile appear from the right with the above options that you can configure.

image

If you scroll down to the bottom of the window you will see that there is a Customize schedule option as shown above.

image

Selecting this will give you much greater options as shown above.

image

Once you have saved your schedule, you will then receive a regular email like that show above with the report you configured. You’ll note that there is also a CSV file attached that you can use for further analysis.

image

You can adjust the schedules you have configured via the Manage schedules option as shown above.

As yet, I haven’t found an easy way to configure these using PowerShell. There is way using the Microsoft Graph but that requires some setup so I’m trying to find a way just to use a pure script. If I work that out, I’ll post an article on how to do it. Till then, you’ll just have to manually go in a select and configure the reports you wish to receive regularly.