About the Microsoft Defender for Office 365 trial


Get started quickly with our easy to use Microsoft Defender for Office 365 playbook. This playbook will help you make the most of your free trial by showing you how to safeguard your organization with Microsoft Defender for Office 365.

Microsoft Defender for Office 365 safeguards your organization against malicious threats that are posed by email messages, links (URLs), and collaboration tools. Defender for Office 365 includes:

  • Threat protection policies: Define threat-protection policies to set the appropriate level of protection for your organization.
  • Reports: View real-time reports to monitor Defender for Office 365 performance in your organization.
  • Threat investigation and response capabilities: Use leading-edge tools to investigate, understand, simulate, and prevent threats.
  • Automated investigation and response capabilities: Save time and effort investigating and mitigating threats.

A Microsoft Defender for Office 365 trial is an easy way to try out the capabilities of Defender for Office 365 Plan 2 for free, after only a few clicks. These high level capabilities are described in the following table:

Feature Description
Exclusive settings in anti-phishing policies Get user impersonation protection, domain impersonation protection, mailbox intelligence, and advanced phishing thresholds.
Safe Attachments Inspect email attachments and other files in a controlled detonation environment to catch new and evasive malware.
Safe Links Perform time-of-click checks to ensure URLs that might have passed initial inspection have not been weaponized.
Threat Trackers* Use informative widgets and views to identify cybersecurity issues that might impact your organization.
Threat Explorer* Hunt with near real-time information about threats in your Office 365 email.
Automated investigation and response (AIR)* Automatically locate and remediate threat objects as alerts are triggered.
Attack simulation training* Train your users to identify phishing attacks and respond appropriately.
Campaign Views* Investigate and respond to large-scale malicious email activity.
Reports using Defender for Office 365 capabilities View reports including threat protection status, URL threat protection, mail latency, and more.
Priority account protection* Users that you identify as Priority accounts are tagged in alerts, reports, and investigations so they stand out. You can also use the Priority tag in filters.

* This feature is exclusive to Defender for Office 365 Plan 2.

Set up a Defender for Office 365 trial

A trial allows organizations to easily set up and configure the Defender for Office 365 capabilities. During setup, policies that are exclusive to Defender for Office 365 (specifically, Safe Attachments for email messages, Safe Links for email messages and Microsoft Teams, and impersonation protection in anti-spam policies) are applied using the Standard template for preset security policies.

By default, these policies are scoped to all users in the organization, but during or after the setup of the trial, you can change the policy assignment to specific users.

Other workloads are also available for protection (for example, Safe Attachments for SharePoint, OneDrive, and Microsoft Teams and Safe Links for supported Office 365 apps.

During the setup of the trial, response functionality that's exclusive to Defender for Office 365 Plan 2 (for example, AIR and Threat Explorer) is also set up for the entire organization. No policy scoping is required.


As part of the trial setup, the Defender for Office 365 licenses are automatically applied to the organization. The licenses are free of charge for the first 90 days.

The licensing card for the trial shows the following information:

The Licensing card in the Microsoft Defender for Office 365 trial.

  • Usage type section:

    • Trial: The number of trial Defender for Office 365 licenses that are available for you to use.


      In other locations, you might see the value 300 for your number of available trial licenses. This value is incorrect (unless your organization happens to have exactly 300 users). The number of trial licenses that are available to you corresponds the size of your organization, not the arbitrary value 300.

    • Paid: The number of paid Defender for Office 365 licenses (if any).

  • Usage section: How many of your users are covered by Defender for Office 365 policies.

    • Detection & response only: The total number of users that are included in the following scenarios:
      • During the trial, you scoped the policies to specific users.
      • You have custom polices that are scoped to specific users.
    • Full protection: The total number of users that are protected by Defender for Office 365 Plan 2 features (AIR, Threat Explorer, Attack simulation training, etc.).


To start or end the trial, you need to be a member of the Global Administrator or Security Administrator roles in Azure Active Directory. For details, see About admin roles.

Additional information

After you start the trial, it might take up to 2 hours for the changes and updates to be available. And, admins must log out and log back in to see the changes.


The Defender for Office 365 trial is gradually rolling out to existing customers who meet specific criteria and who don't have existing Defender for Office 365 Plan Plan 2 licenses (included in their subscription or as an add-on).

Terms and conditions

For more information, see Microsoft Defender for Office 365 Trial Terms & Conditions.

Frequently asked questions

Q: How do I extend the trial?

A: See Extend your trial.

Q: What happens to my data after the trial expires?

A: After your trial expires, you'll have access to your trial data (data from features in Defender for Office 365 that you didn't have previously) for 30 days. After this 30 day period, all policies and data that were associated with the Defender for Office 365 trial will be deleted.

Q: How many times can I use the Defender for Office 365 trial in my organization?

A: A maximum of 2 times. If your first trial expires, you need to wait at least 30 days after the expiration date before you can enroll in the Defender for Office 365 trial again. After your second trial, you can't enroll in another trial.

Learn more about Defender for Office 365

Defender for Office 365 helps organizations secure their enterprise by offering a comprehensive slate of capabilities.

You can also learn more about Defender for Office 365 at this interactive guide.

Microsoft Defender for Office 365 conceptual diagram.


A robust filtering stack prevents a wide variety of volume-based and targeted attacks including business email compromise, credential phishing, ransomware, and advanced malware.


Industry-leading AI detects malicious and suspicious content and correlates attack patterns to identify campaigns designed to evade protection.

Investigation and hunting

Powerful experiences help identify, prioritize, and investigate threats, with advanced hunting capabilities to track attacks across Office 365.

Response and remediation

Extensive incident response and automation capabilities amplify your security team's effectiveness and efficiency.

Awareness and training

Rich simulation and training capabilities along with integrated experiences within client applications build user awareness.

Security posture

Recommended templates and configuration insights help customers get and stay secure.

Give feedback

Your feedback helps us get better at protecting your environment from advanced attacks. Share your experience and impressions of product capabilities and trial results.