Template family: Defender
Applies to: Microsoft Defender for Office 365
Where to find it: Secure → Defender → Templates → Augmentt Default

What this template is for

Anti-phishing policy configured with More Aggressive configuration.

What it actually does

Creates a AntiPhishPolicy in Microsoft Defender for Office 365 configured as follows.

SettingValue
ExcludedDomains(none)
ExcludedSenders(none)
HonorDmarcPolicytrue
DmarcRejectActionReject
SpoofQuarantineTagAdminOnlyAccessPolicy
PhishThresholdLevel3
DmarcQuarantineActionQuarantine
TargetedUsersToProtect(none)
EnableSpoofIntelligencetrue
AuthenticationFailActionQuarantine
TargetedDomainsToProtectmicrosoft.com, paypal.com, amazon.com, google.com, apple.com, facebook.com, linkedin.com, twitter.com
EnableMailboxIntelligencetrue
TargetedUserQuarantineTagDefaultFullAccessPolicy
EnableUnauthenticatedSendertrue
TargetedDomainQuarantineTagDefaultFullAccessPolicy
EnableFirstContactSafetyTipstrue
EnableSimilarUsersSafetyTipstrue
EnableTargetedUserProtectionfalse
ImpersonationProtectionStateManual
TargetedUserActionRecipients(none)
TargetedUserProtectionActionQuarantine
EnableSimilarDomainsSafetyTipstrue
TargetedDomainActionRecipients(none)
TargetedDomainProtectionActionQuarantine
EnableTargetedDomainsProtectiontrue
MailboxIntelligenceQuarantineTagAdminOnlyAccessPolicy
EnableUnusualCharactersSafetyTipstrue
EnableMailboxIntelligenceProtectiontrue
EnableOrganizationDomainsProtectiontrue
MailboxIntelligenceProtectionActionQuarantine
MailboxIntelligenceProtectionActionRecipients(none)

Anything not listed keeps the Microsoft default.


This is an Augmentt Default template, shipped with the product and shared across all customers. Deploying it creates a new policy in the customer tenant; edit the deployed policy rather than the template.