You are configuring Microsoft Defender for Office 365 to protect against business email compromise (BEC) attacks. Which policy setting should you enable to analyze email sender behavior and detect impersonation attempts?
Impersonation protection within the anti-phishing policy uses mailbox intelligence and spoof detection to model sender behaviour and flag messages impersonating internal users or trusted domains. This satisfies the requirement to analyse sender behaviour and detect business email compromise impersonation attempts.
Why this answer
Anti-phishing policies in Microsoft Defender for Office 365 include impersonation protection settings that analyze sender behavior and detect attempts to impersonate users, domains, or trusted senders. Enabling impersonation protection specifically addresses BEC by using mailbox intelligence and spoof intelligence to identify anomalous sender patterns.
Exam trap
MS-102 often tests the difference between Safe Attachments, Safe Links, anti-malware, and anti-phishing, and candidates may incorrectly associate BEC detection with attachment scanning rather than impersonation protection.
How to eliminate wrong answers
Option A is wrong because Safe Attachments with Dynamic Delivery focuses on detonating attachments in a sandbox and delivering the email without the attachment until scanning completes; it does not analyze sender behavior. Option C is wrong because Safe Links URL scanning protects against malicious URLs, not sender impersonation. Option D is wrong because anti-malware policies filter known malware signatures and do not detect impersonation or BEC tactics.