nerdexam
Microsoft

MS-102 · Question #301

You have a Microsoft 365 E5 subscription that contains a domain named contoso.com. You deploy a new Microsoft Defender for Office 365 anti-phishing policy named Policy1 that has user impersonation…

The correct answer is D. Select Enable mailbox intelligence. To prevent impersonation protection from blocking legitimate emails from trusted external contacts with similar names, enable Mailbox Intelligence.

Submitted by chiamaka_o· Apr 18, 2026Manage security and threats by using Microsoft Defender XDR

Question

You have a Microsoft 365 E5 subscription that contains a domain named contoso.com. You deploy a new Microsoft Defender for Office 365 anti-phishing policy named Policy1 that has user impersonation protection enabled for a user named [email protected]. You discover that Policy1 blocks email messages from a regular contact named [email protected]. You need to ensure that the messages are delivered successfully. What should you do for Policy1?

Options

  • ASelect Enable domains to protect.
  • BConfigure the Phishing email threshold setting.
  • CConfigure which users to protect.
  • DSelect Enable mailbox intelligence.

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    5% (1)
  • D
    77% (17)

Why each option

To prevent impersonation protection from blocking legitimate emails from trusted external contacts with similar names, enable Mailbox Intelligence.

ASelect Enable domains to protect.

'Enable domains to protect' is for protecting specific domains from being impersonated, not for allowing a legitimate external sender who happens to have a similar name to a protected user.

BConfigure the Phishing email threshold setting.

Configuring the 'Phishing email threshold' setting adjusts the aggressiveness of phishing detection but does not specifically address the issue of legitimate external senders being mistakenly identified as impersonators of an internal user.

CConfigure which users to protect.

'Configure which users to protect' is about specifying which internal users are targeted for impersonation protection, not about allowing external senders with similar names.

DSelect Enable mailbox intelligence.Correct

Enabling Mailbox Intelligence in an anti-phishing policy helps to distinguish legitimate senders from impersonators by understanding the user's communication patterns and frequent contacts. This allows the system to recognize '[email protected]' as a trusted contact, preventing false positives for impersonation against '[email protected]'.

Concept tested: Anti-phishing policy configuration and Mailbox Intelligence

Source: https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-phishing-policies-mdo-configure?view=o365-worldwide

Topics

#Microsoft Defender for Office 365#Anti-phishing#Impersonation protection#Email security

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice