For detecting and blocking malicious files stored in SharePoint, Microsoft Defender for Office 365 Safe Attachments is the closer fit. Defender for Cloud Apps serves a different role: it helps identify risky activity and sharing, investigate cloud threats, and apply governance actions. The products can complement each other, but Defender for Cloud Apps file policies are scheduled to retire on January 6, 2027, so they are not a sound long-term foundation for file-based data protection.
How the products differ for SharePoint
| Decision area | Defender for Office 365 | Defender for Cloud Apps |
|---|---|---|
| Primary role | Safe Attachments analyzes potentially malicious files in SharePoint, OneDrive, and Teams; identified files are locked and reported. | Monitors cloud activity and sharing patterns, supports investigation of account and insider risks, and provides governance controls for cloud files. |
| Examples of detection | Microsoft 365 virus scanning followed by file detonation, with asynchronous analysis informed by sharing and guest activity, heuristics, and threat signals. | Anomaly and activity detections can include suspicious IPs, unusual file deletion, sharing or download activity, risky-IP logons, malware, and ransomware. |
| Examples of response | Locks a file identified as malicious and reports it in Defender reports and Explorer; administrators can access detections in quarantine. | SharePoint governance actions can make a file or folder private, place it in quarantine, or remove external collaborators. |
| Key qualification | Does not scan every stored file, and analysis is asynchronous. By default, users may still download a detected malicious file unless the tenant blocks downloads. | File policies are scheduled to retire January 6, 2027. Microsoft directs customers to Microsoft Purview DLP or auto-labeling for continuing file-based data protection. |
Microsoft’s descriptions of these functions are in its Safe Attachments documentation and Defender for Cloud Apps documentation.
What Defender for Office 365 does with SharePoint files
Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is the more direct control for harmful-file detection. Microsoft says files first pass through the common Microsoft 365 virus-detection engine; Safe Attachments can then open selected files in a virtual environment for detonation. When a file is identified as malicious, the service locks it through integration with the file stores. Detections are available in Defender reports and Explorer, and administrators can find the file in quarantine. These details are described in Microsoft’s Safe Attachments for SharePoint, OneDrive, and Microsoft Teams guidance, last updated May 8, 2026.
This is not a continuous scan of every file already in every library. Microsoft describes asynchronous analysis that uses sharing and guest-activity events, heuristics, and threat signals to identify files for analysis. That distinction matters when setting expectations: Safe Attachments is a protective detection layer, not evidence that every stored file has already been inspected.
#1 Best Overall
What Defender for Cloud Apps adds
Defender for Cloud Apps focuses on cloud threat activity and governance rather than serving as a substitute for Safe Attachments’ file detection. Its Microsoft 365-related capabilities can help identify compromised-account or malicious-insider behavior, data leakage, and exposed sharing, and support audit-based investigation. Examples of activity include unusual deletion, sharing, or multiple downloads; templates also cover malware, ransomware, suspicious IPs, and risky-IP logons.
For SharePoint, documented governance actions include making a file or folder private, quarantining it for an administrator or user, and removing external collaborators. File-policy templates also cover cases such as sharing to unauthorized or personal email domains and files containing PII, PCI, or PHI. However, Microsoft says Defender for Cloud Apps file policies retire January 6, 2027, and directs customers to Microsoft Purview DLP or auto-labeling for ongoing file-based data protection. See Microsoft’s Defender for Cloud Apps overview.
Rank #2
Which one should you use?
- Choose Defender for Office 365 Safe Attachments when the priority is identifying and locking malicious files in SharePoint, OneDrive, or Teams.
- Use Defender for Cloud Apps as a complementary control when you need to investigate unusual downloads, sharing, account-risk signals, or apply cloud-file governance actions.
- Plan file-based data protection around Purview rather than relying on Defender for Cloud Apps file policies past their stated retirement date.
In short, the choice is not a like-for-like product comparison: Safe Attachments addresses malicious files, while Defender for Cloud Apps adds activity and governance visibility.
Configuration details that change the protection outcome
Enable Safe Attachments for SharePoint, OneDrive, and Teams
Microsoft documents enabling the feature in the Defender portal’s global settings or through Exchange Online PowerShell. The PowerShell command is:
Rank #3
Set-AtpPolicyForO365 -EnableATPForSPOTeamsODB $true
Required administrative permissions apply, and Microsoft says a change can take up to 30 minutes to take effect. Consult Microsoft’s configuration guidance for the current portal path and role requirements.
Rank #4
Decide whether detected files may be downloaded
A detected malicious file is blocked from opening, moving, copying, or sharing, but the default behavior still permits deletion and downloading. Administrators can block downloads tenant-wide with SharePoint Online PowerShell:
Set-SPOTenant -DisallowInfectedFileDownload $true
Microsoft says this setting applies to both users and administrators; deletion remains possible. Microsoft also recommends creating an alert policy for detected files. For the visual blocked-file indicator, sites should use the Modern SharePoint experience. See the Safe Attachments configuration documentation.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteBest Value
Meet Defender for Cloud Apps prerequisites
Connecting Microsoft 365 to Defender for Cloud Apps requires at least one assigned Microsoft 365 license. File monitoring requires an appropriate Entra administrator role, such as Application Administrator or Cloud Application Administrator. Microsoft 365 activity monitoring requires Purview auditing to be enabled. Microsoft lists the service’s setup and capabilities in its product overview.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Safe Links is separate from SharePoint file scanning
Safe Links checks URLs when users click them in supported Office apps; it is not the same control as Safe Attachments’ analysis and locking of files stored in SharePoint. Links to downloadable files are checked only when the applicable Safe Links policy enables real-time URL scanning for suspicious links and links to files. See Microsoft’s Safe Links documentation.
Licensing: verify the tenant’s actual entitlement
Microsoft’s 2026 Defender for Office 365 service description lists SharePoint, OneDrive, and Teams protection under both Plan 1 and Plan 2. It states that Plan 1 is included with Office 365 E3 and Microsoft 365 E3 effective July 1, 2026. Plan 2 adds capabilities including advanced threat hunting, automation, and investigation; the feature table lists Explorer and automated investigation and response for Plan 2, while Plan 1 has real-time detections. Check the exact tenant subscription and service-plan assignment before assuming a capability is enabled. See Microsoft’s Defender for Office 365 service description.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →

