The MDO stuff nobody documents (Tyler did)
Table of Contents
Three MDO write-ups, five to eight(ish) minutes of reading, one pattern through all of them.
It's been a while since I published a blog. I like a streak as much as anyone, but not enough to turn down a chance to stand on somebody else's hard work.
So here we are. Tyler Swinehart, (LinkedIn: /tyler-swinehart) an IT practitioner who writes up the parts of Microsoft Defender for Office the official docs leave out, has put out three pieces over the past few weeks. I read all three back to back (I need a hobby), and each one is rock solid, really.
What I like so much about them is that they highlight stuff that isn't obvious in MDO unless you are really looking for it. More importantly, Tyler spends more characters on solutions than problems, providing tips, tricks, and step-by-step guidance...stuff practitioners can actually use to help them get the most out of MDO.
Let's touch on each one a bit!
Explorer caps you, and you find out at the worst possible time
Explorer is the search interface most MDO admins live in, and for "find me this one email" it's fine. On a real investigation, it starts fighting you. The filtering does equals and contains, and that's the whole menu. No starts-with, no regex, no OR logic. So tracking a phishing campaign across rotating domains becomes ten separate searches you stitch together by hand. Then there's the 30-day retention limit, which you'll meet the afternoon someone asks for an email from 45 days ago (nobody ever asks for one from 15).
None of that puts up a warning. Explorer looks perfectly capable until the moment it isn't. Tyler's piece lays out the way around it, KQL for the queries Explorer can't express and log forwarding for the retention you'll eventually need, and the real lesson underneath: build both before the incident, because you won't have time during one.
Read it: Microsoft Defender for Office Explorer (the stuff nobody tells you until it's too late)
Quarantine passes your test and does nothing in production
This one has the sharpest silent failure of the three. Microsoft's preset security policies outrank any custom quarantine policy you build. If your custom settings and a preset disagree, the preset wins. Silently. Your carefully tuned policy just doesn't apply, and nothing in the UI says so. The write-up describes admins losing whole afternoons to quarantine behavior that "should work," right up until they find a preset quietly overruling all of it.
That's not the only trapdoor. Miss the right permission and MDO hides the quarantine completely instead of graying it out, so your new analyst decides it doesn't exist. Get "Advanced Filter" as the verdict reason and you get nothing you can validate. And with no delegation, the quarantined mail of anyone out on leave stacks up and expires unseen. Same pattern every time: it looks right, it tests right, and it's ignoring you in production.
Your detections report healthy while catching nothing
Turn a KQL query into a scheduled detection and you've got lightweight automated response running around the clock. You've also got two quiet ways to get burned.
First, entity mapping. When you build a detection, Microsoft suggests the entity mappings and then accepts whatever you confirm without checking that any of it makes sense. Point a column of URLs at a user entity and it saves clean, runs, fires alerts, and correlates exactly none of them. One campaign scatters across twenty disconnected alerts and nothing tells you why. Second, staleness. A detection keeps running and reporting healthy long after the threat it watched for moved on. Leadership sees "47 active detections" on a slide and assumes coverage. The slide is lying to them.
Both land on the same discipline: build the detection, then build the audit loop around it, because Microsoft won't tell you when either one goes dark.
The thread running through all three
None of this is in the quick-start guide. MDO ships, it works well enough on day one, and then the real operating knowledge (the retention limits, the policy precedence, the entity-mapping gotchas) gets learned the hard way, usually around 6pm on a Friday. If you've ever lost an afternoon to a quarantine policy that "should work," you already know the feeling.
What makes Tyler's write-ups worth your time is that he doesn't stop at the complaint. Each one hands you the workaround (with screenshots!), the setting to flip, the query to run. That's the difference between venting about MDO and getting more out of it.
So that's my freeloading done for the week. These three are worth the nineteen minutes. Forward them to whoever owns your tenant, ideally before they find out the hard way.
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.