Security & identity

Defender for Office 365 anti-phishing: stop CEO fraud and lookalike domains

Configure impersonation, mailbox intelligence and spoof protection in Defender for Office 365 anti-phishing policies to stop executive and lookalike-domain phishing.

12 min read
On this page

To stop CEO fraud and lookalike-domain phishing in Microsoft 365, turn on the impersonation settings in a Defender for Office 365 anti-phishing policy: protect your executives as senders under Enable users to protect, protect your own and your key partners' domains under Enable domains to protect, turn on Enable intelligence for impersonation protection, and set the detections to Quarantine the message with impersonation safety tips enabled. None of these is configured in the default policy, so impersonation attacks go through until you enable them in a preset security policy, the default policy or a custom policy. Keep spoof intelligence and Honor DMARC record policy on to handle forged copies of your real domains.

Who this is for and what you will have

This guide is for Exchange Online and security administrators in organizations with Microsoft Defender for Office 365, either included in the subscription or as an add-on. Spoof settings and the first contact safety tip also exist for every cloud mailbox; the impersonation settings and phishing thresholds don't.

At the end you will have:

  • A clear split between spoof protection (your real domain forged) and impersonation protection (a lookalike).
  • An anti-phishing policy that protects named executives and finance staff, your accepted domains and important partner domains.
  • Mailbox intelligence acting on impersonation, a raised phishing threshold and safety tips turned on.
  • A review routine using the impersonation insight, with a safe way to handle false positives.

Spoofing versus impersonation

Both attacks put a trusted-looking sender in the From address, but they are detected differently:

SpoofingImpersonation
What the attacker doesForges your real domain, for example ceo@contoso.comUses a lookalike domain such as ćóntoso.com, or a real display name with a different address
Email authenticationFails SPF, DKIM, DMARC or composite authenticationCan pass all checks if the attacker set up DNS for the lookalike domain
DetectionSpoof intelligence and the sender's DMARC policyUser and domain impersonation protection, mailbox intelligence
Available inAll cloud mailboxesDefender for Office 365 only

Domain impersonation looks at more than a different top-level domain. Microsoft gives contosososo.com and contoabcdef.com as examples of domains that might be treated as impersonating contoso.com. Spoofing is covered by your SPF, DKIM and DMARC records plus the spoof settings in the same policy, so this guide focuses on the impersonation settings and only sets the spoof actions.

How the policy is structured

An anti-phishing policy has two different lists that are easy to confuse:

  • Users, groups, and domains are the recipients the policy applies to. In a custom policy you must set at least one; the default policy applies to everyone.
  • Users to protect and domains to protect are senders whose identity is protected. A message is checked against them only when it is sent to a recipient in scope.

So a policy that applies to all recipients in contoso.com and protects the CEO as a sender checks every inbound message to every employee for a sender that resembles the CEO.

Limits and defaults

SettingLimit or default
Protected users per policyMaximum 350
Custom protected domains per policyMaximum 50
Trusted senders and domainsMaximum 1,024 entries; domain entries don't include subdomains
Phishing email thresholdDefault 1 - Standard; Standard preset 3; Strict preset 4
Actions for user, domain and mailbox intelligence impersonationDefault Don't apply any action
Time for a new or changed policy to applyUp to 30 minutes

Mailbox intelligence

Mailbox intelligence learns each user's frequent contacts. It is on by default, but it only takes action when Enable intelligence for impersonation protection is also on, which is off by default. Mailbox intelligence suppresses false positives: if a recipient regularly corresponds with a vendor who shares a name with your CEO, messages from that vendor aren't treated as impersonation for that recipient. Note the trade-off Microsoft documents: when both mailbox intelligence settings are on, user and domain impersonation protection don't act on messages between a sender and recipient who have communicated before.

Preset policies or custom policies

Microsoft generally recommends the Standard or Strict preset security policies over custom policies, and you configure the impersonation lists inside the preset. If a recipient is included in a preset policy, settings in the default and custom anti-phishing policies are ignored for that recipient. Choose one approach per recipient so you know which settings apply.

SettingDefault policyStandard presetStrict preset
Phishing email threshold134
Users and domains to protectOffOn, with your listsOn, with your lists
Include domains I ownOffOnOn
Intelligence for impersonation protectionOffOnOn
User and domain impersonation actionNo actionQuarantineQuarantine
Mailbox intelligence actionNo actionMove to Junk EmailQuarantine
Impersonation safety tipsOffOnOn
First contact safety tipOffOnOn
Spoof intelligence actionMove to Junk EmailMove to Junk EmailQuarantine

Prerequisites

  • Defender for Office 365, included in your subscription or as an add-on, for the recipients you want to protect.
  • Permissions: Organization Management or Security Administrator in Exchange Online, the Entra ID Security Administrator role, or, if Defender XDR Unified RBAC is active for email and collaboration, Authorization and settings/Security settings/Core Security settings (manage).
  • A list of people attackers are likely to impersonate: CEO, CFO, finance approvers, HR, board members and external advisors, each as a display name and email address.
  • A list of external domains your users trust: banks, payroll and legal partners, key suppliers.
  • Quarantine policies decided for impersonation detections. Without a selection, DefaultFullAccessPolicy is used; the presets use DefaultFullAccessWithNotificationPolicy for user and domain impersonation.
  • Exchange Online PowerShell for the scripted steps.

Step 1: Check what impersonation protection would catch

Before you change anything, open the Defender portal at Email & collaboration > Policies & rules > Threat policies > Anti-phishing (https://security.microsoft.com/antiphishing). If no active policy has impersonation protection configured, the impersonation insight runs in What if mode and shows how many messages would have been detected in the past seven days. Select View impersonations to see the senders and domains involved. Use this to spot partners that resemble your domains before you start quarantining.

Step 2: Create the anti-phishing policy in the portal

  1. On the Anti-phishing page, select Create.
  2. Policy name: enter a name such as Impersonation - All users. You can't rename the policy itself later.
  3. Users, groups, and domains: under Domains, add your accepted domains so every recipient is covered. Subdomains are included unless you exclude them. Members of dynamic distribution groups aren't supported as conditions.
  4. Phishing threshold & protection:
    • Set Phishing email threshold to 3 - More aggressive to match the Standard preset. Higher values increase false positives.
    • Select Enable users to protect, then Manage sender(s) > Add user. Add each internal executive, and external senders such as board members by full email address. Edit the display name if needed; detection compares display name and address together.
    • Select Enable domains to protect, then Include the domains I own and Include custom domains. Add partner domains you don't own but trust.
    • Leave Add trusted senders and domains empty for now.
    • Keep Enable mailbox intelligence selected and select Enable intelligence for impersonation protection.
    • Keep Enable spoof intelligence selected.
  5. Actions:
    • If a message is detected as user impersonation: Quarantine the message, and choose a quarantine policy.
    • If the message is detected as an impersonated domain: Quarantine the message.
    • If mailbox intelligence detects an impersonated user: Move the message to the recipients' Junk Email folders (Standard) or Quarantine the message (Strict).
    • Keep Honor DMARC record policy when the message is detected as spoof selected, with Quarantine the message for p=quarantine and Reject the message for p=reject.
    • If the message is detected as spoof by spoof intelligence: Move the message to the recipients' Junk Email folders or Quarantine the message.
    • Under Safety tips & indicators, select Show first contact safety tip, Show user impersonation safety tip, Show domain impersonation safety tip, Show user impersonation unusual characters safety tip, Show (?) for unauthenticated senders for spoof and Show "via" tag.
  6. Review and select Submit.

If you already use the Standard or Strict preset, enter the same users and domains in the preset's impersonation settings instead of creating a custom policy.

Step 3: Or create it with PowerShell

A PowerShell policy needs two objects: the anti-phish policy with the settings and an anti-phish rule that sets recipients and priority. The policy isn't visible in the portal until a rule references it. TargetedUsersToProtect uses the format "DisplayName;EmailAddress".

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
$protectedUsers = "Megan Bowen;megan.bowen@contoso.com","Alex Wilber;alex.wilber@contoso.com","Board Chair;chair@fabrikam.com"
 
New-AntiPhishPolicy -Name "Impersonation - All users" -AdminDisplayName "Executive and partner impersonation protection" `
  -PhishThresholdLevel 3 `
  -EnableTargetedUserProtection $true -TargetedUsersToProtect $protectedUsers -TargetedUserProtectionAction Quarantine `
  -EnableOrganizationDomainsProtection $true `
  -EnableTargetedDomainsProtection $true -TargetedDomainsToProtect fabrikam.com -TargetedDomainProtectionAction Quarantine `
  -EnableMailboxIntelligence $true -EnableMailboxIntelligenceProtection $true -MailboxIntelligenceProtectionAction MoveToJmf `
  -EnableFirstContactSafetyTips $true -EnableSimilarUsersSafetyTips $true -EnableSimilarDomainsSafetyTips $true -EnableUnusualCharactersSafetyTips $true
 
New-AntiPhishRule -Name "Impersonation - All users" -AntiPhishPolicy "Impersonation - All users" -RecipientDomainIs contoso.com -Priority 0

To choose a quarantine policy, add -TargetedUserQuarantineTag, -TargetedDomainQuarantineTag or -MailboxIntelligenceQuarantineTag with the policy name. To add a protected user later without overwriting the list, use the hashtable syntax:

Set-AntiPhishPolicy -Identity "Impersonation - All users" -TargetedUsersToProtect @{Add="Nestor Wilke;nestor.wilke@contoso.com"}

To turn on impersonation protection in the default policy instead, target it by name:

Set-AntiPhishPolicy -Identity "Office365 AntiPhish Default" -EnableOrganizationDomainsProtection $true -EnableTargetedUserProtection $true -TargetedUsersToProtect $protectedUsers -TargetedUserProtectionAction Quarantine -EnableMailboxIntelligenceProtection $true -MailboxIntelligenceProtectionAction Quarantine

Step 4: Review detections and tune

Allow up to 30 minutes for the policy to apply, then check the impersonation insight regularly, especially during the first weeks.

  1. On the Anti-phishing page, select View impersonations, or open https://security.microsoft.com/impersonationinsight.
  2. On the Domains tab, review each Sender Domain, the Impersonated domain(s) it resembles, the Policy that caught it and the message count for the last seven days. The details flyout shows Whois data such as the domain creation date, which helps separate a newly registered lookalike from a long-standing partner.
  3. On the Users tab, check the User type column. Protected user means a match against your list; Mailbox Intelligence means a match based on contact history.
  4. Use Explorer investigation in the flyout to see every message from that sender and what happened to it.

When a detection is a genuine partner, use Select impersonation policy to modify and turn on Add to the allowed to impersonation list in the flyout. That adds the sender or domain to the policy's Trusted senders and domains list (ExcludedSenders and ExcludedDomains in PowerShell). Add only the exact sender or domain; trusted domain entries don't include subdomains, so add each subdomain you need separately.

Set-AntiPhishPolicy -Identity "Impersonation - All users" -ExcludedDomains fabrikam-payroll.com -ExcludedSenders invoices@fabrikam.com

A comma-separated value like this replaces whatever is already in ExcludedDomains and ExcludedSenders, so read the current lists with Get-AntiPhishPolicy first and include the existing entries in the new value.

Microsoft also documents that system messages from noreply@email.teams.microsoft.com, noreply@emeaemail.teams.microsoft.com and no-reply@sharepointonline.com can be added as trusted senders if they are flagged as impersonation.

For false positives outside impersonation, such as a spoof or bulk verdict, use admin submissions and the Tenant Allow/Block List as described in fixing email false positives with the Tenant Allow/Block List.

Verify the configuration

  • On the Anti-phishing page, confirm the policy's Status is On and check its Priority relative to other custom policies.
  • In PowerShell, confirm the settings and rule:
Get-AntiPhishPolicy -Identity "Impersonation - All users" | Format-List PhishThresholdLevel,EnableTargetedUserProtection,TargetedUsersToProtect,TargetedUserProtectionAction,EnableOrganizationDomainsProtection,TargetedDomainsToProtect,TargetedDomainProtectionAction,EnableMailboxIntelligenceProtection,MailboxIntelligenceProtectionAction,ExcludedSenders,ExcludedDomains
Get-AntiPhishRule | Format-Table Name,Priority,State
  • Check the message header of a detected message: the SFTY field in X-Forefront-Antispam-Report shows 9.20 for a user impersonation safety tip, 9.19 for domain impersonation and 9.25 for the first contact tip.

Troubleshooting

"The email address already exists" when adding a protected user. The user is already protected in another anti-phishing policy. The error appears only in the portal; TargetedUsersToProtect in PowerShell accepts the same user in more than one policy.

Policy settings have no effect for some users. Those users are probably in the Standard or Strict preset policy, which overrides default and custom anti-phishing policies. Check the preset's assignments, or a higher-priority custom policy that covers them.

An obvious impersonation from a known contact wasn't caught. With mailbox intelligence and intelligence for impersonation protection both on, impersonation checks don't act when the sender and recipient have communicated before. Review the message in Threat Explorer and report it as phishing through admin submissions.

A partner whose name matches an executive is quarantined. Add that specific sender address to trusted senders in the detecting policy, rather than lowering the action for all impersonation detections.

No safety tips appear. Safety tips aren't stamped on S/MIME-signed messages or on messages allowed by your organizational settings. The first contact tip is also skipped for mailboxes created less than seven days ago and messages delivered by a bypass spam filtering (SCL -1) mail flow rule.

DMARC reject or quarantine actions don't apply. If your MX record points to a third-party filter in front of Microsoft 365, Honor DMARC policy only works when Enhanced Filtering for Connectors is enabled on the inbound connector.

Changes fail with 403 or CmdletAccessDeniedException. If your permissions are correct, Microsoft notes this can be an Exchange Online RBAC configuration issue that requires a backend refresh through Microsoft Support.

Checklist

  • Impersonation insight reviewed in What if mode before enforcing.
  • Executives, finance approvers and key external senders added as protected users (up to 350 per policy).
  • Accepted domains and important partner domains protected (up to 50 custom domains).
  • Intelligence for impersonation protection on; phishing threshold at 3 or 4.
  • User and domain impersonation set to quarantine with a deliberate quarantine policy.
  • Safety tips and the first contact tip turned on.
  • Spoof intelligence on and Honor DMARC policy kept with quarantine and reject actions.
  • Each recipient covered by exactly one intended policy (preset or custom).
  • Trusted senders and domains kept short, exact and reviewed regularly.

References

Questions people ask

Is impersonation protection turned on by default in Defender for Office 365?

No. The default anti-phishing policy provides spoof protection and mailbox intelligence, but user impersonation, domain impersonation, intelligence for impersonation protection and the higher phishing thresholds aren't configured. Turn them on in the Standard or Strict preset security policy, the default policy, or a custom policy.

How many users can I protect from impersonation?

Each anti-phishing policy can protect up to 350 users (display name and email address pairs) and up to 50 custom domains. Trusted senders and domains, the exceptions list, can hold up to 1,024 entries.

What is the difference between spoofing and impersonation?

Spoofing forges your real domain in the From address and is caught by SPF, DKIM, DMARC and composite authentication. Impersonation uses a lookalike domain or a matching display name with a different address, so the message can pass authentication; only impersonation protection in Defender for Office 365 detects it.

Why is a legitimate partner flagged as impersonating my CEO?

The sender's display name or domain resembles a protected user or domain. Add the sender or domain to Trusted senders and domains in the policy that detected it, which you can do from the impersonation insight flyout. Trusted domain entries don't cover subdomains.

Defender for Office 365Exchange Online ProtectionAnti-phishingMailbox intelligence
  1. Fix email false positives with submissions and the Tenant Allow/Block List

    Release wrongly blocked email in Microsoft 365 the safe way: admin submissions, expiring Tenant Allow/Block List allow entries, and the allow methods to avoid.

  2. A Microsoft 365 tenant security baseline you can apply in a day

    Harden a new or existing Microsoft 365 tenant in one working day: emergency access, admin roles, MFA and legacy auth, app consent, email protection, external forwarding, audit logging and Secure Score.

  3. Find and remove malicious inbox and forwarding rules after a BEC

    After a compromised mailbox, find hidden inbox rules, SMTP forwarding and delegate access in Exchange Online, remove them safely and block external auto-forwarding so the attacker can't come back.