Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A Microsoft 365 administrator is configuring Microsoft Defender for Office 365. The organization wants to create a custom policy that specifically targets emails containing a highly sensitive keyword related to a new product launch, ensuring these emails are quarantined if received from external senders. Which type of Defender for Office 365 policy should the administrator configure?

  1. ASafe Attachments policy
  2. BAnti-malware policy
  3. CAnti-spam policy
  4. DMail flow rule (transport rule)
Show answer & explanation

Correct answer: D. Mail flow rule (transport rule)

While Defender for Office 365 provides various protections, custom content-based filtering and actions like quarantining based on specific keywords from external senders are best achieved using mail flow rules (transport rules) in Exchange Online, which integrate with Defender for Office 365.

Why the other options are wrong

  • A. Safe Attachments policies detonate attachments in a sandbox environment to detect zero-day malware, which is not relevant for keyword-based content filtering.
  • B. Anti-malware policies scan for malicious attachments and links, not for sensitive keywords within email bodies.
  • C. Anti-spam policies primarily focus on identifying and acting on unsolicited bulk email and phishing attempts, not specific keyword content.

Defender for Office 365 Mail Flow Rules

Mail flow rules (transport rules) in Exchange Online Protection (part of Defender for Office 365) allow administrators to identify and take action on messages that flow through their organization.

  • Offer granular control over email processing.
  • Can be configured with complex conditions and actions (e.g., quarantine, reject, add header).
  • Ideal for custom content filtering, compliance, and specific threat scenarios beyond standard policies.

Memory trick: For custom email content, you need a RULE, not just a standard policy.

More Implement and manage Microsoft Defender XDR questions