Microsoft Defender for Office 365: Protecting Email and Collaboration Tools
A company wants to protect against malware and phishing attacks in email and collaboration tools like Microsoft Teams. Which Microsoft security solution should they use?
Quick Answer
The answer is Microsoft Defender for Office 365, as it is the dedicated Microsoft security solution for safeguarding email and collaboration tools like Microsoft Teams against malware and phishing attacks. This solution works by scanning email attachments, links, and Teams messages in real time to block malicious content before it reaches users, leveraging threat intelligence and automated investigation to neutralize advanced threats. On the SC-900 exam, this question tests your ability to map Microsoft security services to their specific workloads—Defender for Office 365 is the go-to for messaging and collaboration, while Defender for Endpoint covers devices, Defender for Cloud Apps acts as a CASB for shadow IT, and Defender for Identity protects on-premises Active Directory. A common trap is confusing these tools, so remember the memory tip: “Office for mail and Teams, Endpoint for machines, Cloud Apps for apps, Identity for on-prem AD.”
⚠ Common exam trap
Test-takers frequently confuse the broad 'Defender' branding and assume any Defender product covers all security scenarios, but each solution is scoped to a specific layer (email/collaboration, cloud apps, endpoints, or identity), and the question's focus on email and Teams directly points to Defender for Office 365.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Office 365
Microsoft Defender for Office 365 (formerly Office 365 ATP) is the correct solution because it is specifically designed to protect email and collaboration tools like Microsoft Teams from malware, phishing, and other threats. It includes features such as Safe Links, Safe Attachments, and anti-phishing policies that scan URLs and attachments in real-time, and it integrates directly with Exchange Online and Teams to block malicious content before it reaches users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for Office 365
Why this is correct
Defender for Office 365 applies anti-phishing, anti-malware and Safe Links/Attachments policies across Exchange Online, Teams and SharePoint, satisfying the stem's email and collaboration requirement. Defender for Cloud Apps handles CASB visibility, not mail-borne threat filtering.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker governing sanctioned SaaS usage and shadow IT, not inbound email or Teams phishing filtering. It is tempting because it covers cloud apps, but it would be correct when controlling unsanctioned application access and session policies.
- ✗
Microsoft Defender for Endpoint
Why it's wrong here
Microsoft Defender for Endpoint protects devices through endpoint detection and response, not email messages or Teams collaboration content. It is tempting because it blocks malware on workstations, but it would be correct when securing laptops and servers rather than filtering phishing links delivered through Exchange Online.
- ✗
Microsoft Defender for Identity
Why it's wrong here
Microsoft Defender for Identity monitors on-premises Active Directory signals for identity-based attacks such as lateral movement, not email or Teams malware and phishing. It is tempting because it is a Defender workload, but it would be correct when detecting compromised credentials and reconnaissance against domain controllers.
Go deeper
Related to this question
Learn chapter
Conditional Access Policies
Key term
Collaboration
Collaboration in Microsoft 365 refers to the integrated tools and services that enable people to work together in real time, share information, and coordinate tasks from anywhere.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to protect against ransomware by detecting and blocking malicious files in email attachments. Which Microsoft security solution should be used?
easy- A.Microsoft Defender for Identity
- B.Microsoft Defender for Cloud Apps
- ✓ C.Microsoft Defender for Office 365
- D.Microsoft Defender for Endpoint
Why C: Microsoft Defender for Office 365 includes Safe Attachments and Safe Links features that scan email attachments in real-time using detonation chambers and machine learning to detect and block ransomware and other malicious files. This solution is specifically designed to protect Exchange Online and SharePoint Online from threats delivered via email, making it the correct choice for blocking malicious attachments.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.