01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
Security

Microsoft Defender for Office 365 Plan 1 Now Included in E3 Licences: What UK SMEs Must Enable This Month (August 2026)

August 8, 2026 Meridian Micro
paperwork mixup

Microsoft has completed a significant licensing update this month that brings advanced email security features to hundreds of thousands of UK small and medium-sized businesses.
Microsoft 365 E3 now includes Microsoft Defender for Office 365 Plan 1
, a change that rolled out as part of
the 2026 packaging update which completed by 1 August 2026
. For Kent SMEs running E3 subscriptions, this represents a substantial increase in protection—but only if you enable and configure the new features.

The timing is critical.
The government’s Cyber Security Breaches Survey found that 85% of businesses that experienced a breach identified phishing as the attack method
, and
generative AI tools now allow attackers to craft perfectly written, grammatically flawless emails in any language, eliminating the telltale spelling mistakes that once gave phishing emails away
. Against this backdrop, the additional protection Microsoft has just added to your existing licences could not arrive at a more opportune moment.

What Microsoft Defender for Office 365 Plan 1 Adds to Your E3 Licence

If your organisation subscribes to Microsoft 365 E3, Office 365 E3, or certain Business plans, you now have access to a suite of advanced email protection tools that were previously a separate purchase.
Microsoft Defender for Office 365 Plan 1 includes protection against advanced phishing and malware, URL time-of-click protection that scans URLs at time of click to prevent access to malicious websites
, plus enhanced reporting and threat investigation capabilities.

The additions are particularly important for organisations facing the current threat environment.
Akamai observed a 137% increase in API attack traffic
, whilst
AI is now being used to scrape an individual’s publicly available data—their employer, job title, recent LinkedIn posts, even conference appearances—and generate highly personalised spear phishing attack tactics emails that reference real events and real colleagues
.

URL Time-of-Click Protection: Why It Matters Now

URL time-of-click protection scans links in Outlook and Office apps at the moment a user clicks, blunting phishing links that were clean when the message arrived
. This addresses a fundamental weakness in traditional email filtering: attackers often compromise legitimate websites hours or days after an email is delivered, turning a previously safe link into a credential harvesting page.

This “time-of-click” capability is now available in Microsoft 365 Business Basic, Business Standard, and all E3 plans, giving UK SMEs a layer of defence that adapts to evolving threats in real time. For businesses that have already experienced phishing incidents—or are concerned about security alert fatigue—this represents a meaningful improvement in automated protection.

Prompt Injection Protection Against AI Threats

One of the most significant new capabilities addresses an emerging threat category.
Prompt injection protection in Defender for Office 365 now detects prompt injection attacks hidden in inbound email
. These attacks attempt to manipulate AI systems—including Microsoft Copilot and other generative AI tools—by embedding malicious instructions within seemingly innocuous email content.

Given the NCSC’s recent warnings about AI security risks, this feature offers timely protection for organisations beginning to deploy AI-enabled productivity tools across their workforce.

What UK SMEs Must Do This Month

The licensing change does not automatically enable all features. Microsoft 365 administrators need to review and activate the new capabilities to ensure their organisations benefit from the enhanced protection. Here is what to prioritise:

1. Verify Your Licensing Entitlement

Check whether your organisation holds Microsoft 365 E3, Office 365 E3, or eligible Business licences.
Rollout began in June 2026 and completes by 1 August 2026, with tenants receiving at least 30 days’ notice in the Microsoft 365 Message Center before the features become available
. Review your Message Center for confirmation that Defender for Office 365 Plan 1 is now active in your tenant.

2. Enable Safe Links and Safe Attachments Policies

Navigate to the Microsoft Defender portal and configure Safe Links policies to scan URLs at the point of click. Similarly, ensure Safe Attachments policies are active to detonate suspicious files in a sandbox environment before they reach end users. Both features are now included in your subscription but require policy configuration to function.

3. Review Intra-Organisation Protection Settings

Microsoft is introducing intra-org protection data into core customer facing reports: the Mailflow status report, Threat protection status report, and Top senders and recipient report, giving admins and security operators insight into how built-in security features and Defender for Office 365 protect users from malicious email traffic inside the organisation
. This addresses a frequently overlooked attack vector: compromised accounts sending phishing emails to colleagues.

4. Configure Unified RBAC Permissions

For organisations with Defender for Office 365 Plan 2 (available in E5 licences),
new Defender for Office 365 Plan 2 organisations now use the Microsoft Defender unified role-based access control (Unified RBAC) model by default as of July 2026
. Review your permission structure to ensure security operations staff have appropriate access to the expanded reporting and investigation tools.

Why This Matters for Kent SMEs in August 2026

The updated licensing arrives as UK cyber security pressures intensify.
The National Cyber Security Centre reports that nationally significant incidents represented 48% (204) of all incidents between September 2024 and August 2025, a dramatic increase from 89 incidents the previous year
. Meanwhile,
what has changed is how attacks look, how they arrive, and why email filters alone no longer catch them
.

For SMEs, the challenge is resource allocation. Most small IT teams cannot dedicate staff to continuously monitor emerging threats or manually review every suspicious email. The automated protections now included in E3 licences help bridge that gap, but they require deliberate configuration and periodic review to remain effective.

This update also complements other recent Microsoft security enhancements, including the Edge security update alerts launched earlier this month and the forthcoming Windows 11 Patch Tuesday changes on 13 August. Together, these updates form a strengthened security posture—provided organisations take the time to enable and maintain them.

Common Pitfalls to Avoid

Several configuration mistakes can undermine the effectiveness of Defender for Office 365, even when the licensing is correctly assigned:

Looking Ahead: The Cyber Security and Resilience Bill

The licensing update also arrives as the UK’s legislative environment evolves. As previously covered in our analysis of the UK Cyber Resilience Pledge,
the pending Cyber Security and Resilience Bill is expected to mandate supplier assurance, ransomware-payment reporting, and stricter incident notifications
. Organisations that establish robust email security controls now will find compliance considerably easier when those requirements take effect.

What to Do Next

For Kent SMEs running Microsoft 365 E3 or eligible Business licences, the priority this month is straightforward: verify the new Defender for Office 365 Plan 1 features are active in your tenant, enable Safe Links and Safe Attachments policies, and schedule time to review the enhanced reporting capabilities. If your organisation lacks internal expertise to configure these features correctly, now is the time to seek assistance before the next wave of AI-powered phishing attacks arrives.

Meridian Micro helps Kent and South East businesses configure and maintain Microsoft 365 security features, including Defender for Office 365 deployment, policy tuning, and ongoing security monitoring. If you need support enabling the new E3 capabilities or reviewing your existing email security posture, call our team on 01303 883111 or visit our offices in Saltwood, Hythe. We provide practical, jargon-free advice tailored to the realities of running a small business in 2026.