Most email security conversations focus entirely on what comes in: phishing emails, malicious attachments, spam. The outbound risk, sensitive data leaving the organisation accidentally or without appropriate controls, is equally real and in many sectors equally regulated, but receives far less attention until an incident forces it into focus. This guide covers how Microsoft 365 addresses both directions through Defender for Office 365 and Microsoft Purview DLP, and how the two work together as a coherent approach rather than separate tools.
Two Different Problems Requiring Two Different Controls
Email security and data loss prevention are complementary controls that address risk from opposite directions. Email security is concerned with what arrives: filtering inbound threats, blocking malicious links and attachments, and flagging suspicious sender patterns before they reach end users. Data loss prevention is concerned with what leaves: identifying sensitive information within messages, documents and files, and applying policy controls when that information is about to move outside the organisation's boundaries.
Most organisations have at least some email security in place, since the inbound threat is visible and its consequences, a phishing attack, a malware infection, arrive quickly and obviously. The outbound risk is less immediately visible, because the consequence of a misdirected email containing customer data may not surface for weeks or months, when a data breach notification obligation or a regulatory enquiry arrives.
How Defender for Office 365 Handles the Inbound Problem
Microsoft Defender for Office 365 provides a layered inbound filtering capability: anti-spam and anti-malware filtering, Safe Links URL checking at the point of click rather than only at delivery, Safe Attachments sandboxing for suspicious files, and anti-phishing policies that apply additional scrutiny to messages attempting to impersonate trusted senders or Microsoft domains. These controls operate at the platform level, applying to every inbound message across every user in the Microsoft 365 tenant rather than relying on individual users having specific software installed.
The effectiveness of these controls depends significantly on how they are configured. Default settings leave known gaps; for example, default anti-phishing policies do not enable impersonation protection for custom domains out of the box. A properly configured Defender for Office 365 deployment closes these gaps as part of initial setup rather than leaving them for a later review.
How Microsoft Purview DLP Handles the Outbound Problem
Microsoft Purview DLP scans content across email, SharePoint, OneDrive and Teams for sensitive information types, defined by Microsoft across hundreds of common patterns, such as UK national insurance numbers, credit card numbers, and health identifiers, or customised to match the specific data a business needs to protect. When a policy match is detected, the configured response can be to notify the user and allow them to confirm their intent, to block the action entirely, or to alert a compliance team, depending on how the policy has been tuned for the sensitivity of the information type and the destination involved.
Because this applies across all Microsoft 365 channels rather than email alone, it catches data leaving through Teams or a SharePoint external sharing link just as readily as an email to the wrong recipient, addressing the reality that sensitive data moves across all of these channels in a modern workplace.
Getting the Policy Tuning Right
The most common failure in DLP implementation is getting the policy sensitivity wrong in either direction. Policies that are too sensitive block legitimate business activity and create staff resistance that ultimately undermines the control altogether. Policies that are too permissive allow the data loss events they were designed to prevent.
Starting DLP in audit mode, where policy matches are logged but no blocking action is taken, allows an organisation to see what the policy would have caught before enforcement begins. Reviewing the audit log against actual business activity then informs calibration, reducing false positives before enforcement goes live rather than discovering them through staff complaints after the fact.
What This Looks Like in Practice
A professional services firm configuring DLP for client data ran its initial policies in audit mode and discovered that a significant volume of external emails triggered the client data policy, most of them entirely legitimate client communications. Refining the policy to allow exceptions for established external domains where client data sharing was a normal part of service delivery reduced the false positive rate dramatically before enforcement began, avoiding the staff friction that blanket enforcement would have created.
An organisation extended its DLP coverage from email to SharePoint after a review identified several document libraries with external sharing enabled more broadly than was appropriate, discovering in audit mode that confidential contract documents had been accessible to external parties through shared links that staff had created without realising the scope of access they provided.
Getting Started on Email Security and DLP
For Microsoft 365 environments, the most immediate priority is confirming that Defender for Office 365 is configured with impersonation protection and Safe Links and Safe Attachments properly enabled, since default settings frequently leave these gaps. DLP can then be introduced in audit mode alongside, building toward enforcement as calibration is refined.
The Advantage Transformation Sprint is a free, no-obligation session that reviews current Microsoft 365 security configuration and identifies the highest-priority gaps in both inbound filtering and outbound data protection.
Protect Both Directions with Microsoft 365 Security
Advantage configures Microsoft Defender for Office 365 and Microsoft Purview DLP for UK SMEs, addressing both inbound email threats and outbound data protection in a single, coherent Microsoft 365 security posture. If you want to close both gaps rather than only the more visible one, speak to our team.
Contact Advantage today or call 020 3004 4600.
Read more about our Cyber Security services or explore Microsoft 365.
Related Resources
Glossary: Email Security and Data Loss Prevention
Phishing Protection in Microsoft 365
Ransomware Protection for SMEs
Glossary: GDPR
Glossary: Cyber Essentials Certification