★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI● Microsoft partner since 2006◆ 1,100+ organizations under management

Mimecast or Proofpoint vs Defender for Office 365: Do You Still Need a Third-Party Email Security Gateway in 2026?

2026-09-27·IT Partner·Licensing and cost guidesNewEmail SecurityDefenderExchange OnlineMicrosoft 365

Most Microsoft 365 tenants we meet that run Mimecast or Proofpoint bought the gateway years ago, when Exchange Online Protection was the only filter Microsoft offered. Since then Microsoft 365 Business Premium has come to include Defender for Office 365 Plan 1, E5 includes Plan 2, and the gateway sits in front of a filter the organization already pays for. The question is not whether the gateway is good. It is what the gateway does that Defender does not, whether that is worth a second vendor, and what breaks when both filter the same mail. Here is the answer for a 20 to 500 seat organization, and the migration sequence for those who decide to move.

What Defender for Office 365 Plan 1 and Plan 2 cover, and who already has them

Microsoft's product page, opened for this article, describes Plan 1 as protection "against email and collaboration-based cyberattacks across email, Teams, SharePoint, and OneDrive", with "real-time protection for malicious links and QR codes" (Safe Links), "protection against zero-day malware and viruses in attachments" (Safe Attachments) and "language model-based sentiment analysis to protect against phishing campaigns". Plan 2 adds "advanced threat hunting", "cyberattack simulation training" and "automated investigation and response". In practice, Plan 1 is the filter and Plan 2 is the filter plus the security team's tools. Both sit on Exchange Online Protection, which every tenant has.

Who has what, at Microsoft list price, September 2026 price list:

  • Microsoft 365 Business Premium includes Plan 1 (as reported by Microsoft's Q&A forum and partner summaries; see Sources).
  • Microsoft 365 E5 and Office 365 E5 include Plan 2. Microsoft 365 E3 and Office 365 E3 gained Plan 1 in Microsoft's 2026 packaging update (rollout complete by August 1, 2026, per Microsoft's licensing news page, opened September 27, 2026); CISA's Security Suite baseline, written before that change, still describes Plan 1 and Plan 2 as "included with E5 and G5 and are available as add-ons for E3 and G3", so treat Plan 2 as an add-on for E3 and check your tenant's service plans for Plan 1.
  • Defender for Office 365 Plan 1 add-on: $24 per user per year on an annual commitment ($2 a month).
  • Defender for Office 365 Plan 2 add-on: $60 per user per year ($5 a month).

Microsoft's preset security policies do the configuration work. CISA's baseline describes "built-in protection, standard, and strict" presets that "allow administrators to enable the full feature set of Defender by adding users to the policies rather than manually configuring each setting". A Plan 1 tenant with everyone in Standard and executives in Strict is configured; one with nobody in a preset is running defaults, and defaults are why people think Defender is weak. Our SPF, DKIM, DMARC and Plan 1 vs Plan 2 article covers the DNS records every filter depends on.

What a gateway does that Defender does not

A secure email gateway is a separate mail hop: your MX record points at the vendor, mail is filtered there, and clean mail is handed to Exchange Online. On filtering itself, the gateways and Defender now overlap almost completely. What the gateways still add:

  • Email continuity. If Exchange Online is unavailable, users read and send recent mail from the vendor's portal or app. Mimecast markets this as Mailbox Continuity and Proofpoint Essentials lists continuity in its feature set (both as reported). Microsoft has no equivalent product.
  • Archiving with independent retention: a copy of every message held outside Microsoft, searchable, with legal hold and export, on a schedule that does not depend on a Microsoft license. Microsoft 365 has retention policies, archive mailboxes and eDiscovery in Purview, but inside the same tenant.
  • One console for mail on other platforms, such as a Google Workspace subsidiary or an on-premises Exchange server.
  • Bundled outbound features: large-file send, secure message portals, encryption, DLP.

Both vendors now offer an API-based deployment beside the MX-based gateway. Mimecast's API mode is reported to use the same detection engine without an MX change, and Proofpoint Essentials offers an "Integrated Deployment" with Microsoft 365 that onboards without MX changes (both as reported). API mode removes the double-filtering problems below but also removes continuity, because no vendor sits in the mail path when Microsoft is down. Check which mode your contract is on.

Double filtering: what breaks when both are in the path

With the MX pointed at the gateway, Exchange Online sees every message arriving from the gateway's addresses. Unless Enhanced Filtering for Connectors is configured on the inbound connector, Defender evaluates SPF, DKIM alignment, spoof intelligence and IP reputation against the gateway rather than the true sender; Microsoft's migration documentation describes Enhanced Filtering as required for Defender to see where internet messages actually came from (as reported). Without it, administrators turn Defender's checks down to stop false positives, or both products quarantine, with two notifications.

The rest of the list, from our migrations:

  • Safe Links and the gateway both rewrite URLs, so users see a vendor-wrapped link inside a Microsoft-wrapped link and click reports disagree.
  • Two allow lists and two block lists, maintained by different people, that drift apart.
  • DMARC aggregate reports go to whichever platform the MX points at; move the MX and the reporting changes.
  • Attackers who find the tenant's direct Microsoft endpoint bypass the gateway unless inbound mail is restricted to the gateway's addresses, and many tenants never did that.

Most of these are configuration debt rather than product faults, but each is a reason "keep both for defense in depth" usually delivers two half-tuned filters instead.

The decision: keep the gateway or move

Keep the gateway, for now, if:

  • A regulator, a contract or your litigation posture requires an archive outside Microsoft and you have not designed a Purview replacement.
  • Continuity during a Microsoft outage is a documented business requirement.
  • Mail on other platforms has to be filtered by the same policy.
  • The contract has more than a year to run and the exit cost is real.

Move to Defender if:

  • You are on Business Premium or E5 and are paying for a filter twice.
  • The tenant has Plan 1 but nobody is in a preset policy; fix that first, then compare detection on real traffic.
  • The gateway was bought for a reason nobody can name anymore.

Two things are not reasons. "Defender misses phishing" is usually a tenant on defaults. "The gateway blocks more" is often true in raw counts because gateways score aggressively; what matters is what reaches inboxes and what gets released, measurable only with both running on the same mail for a few weeks. A gateway is not identity protection either: the attack paths in our MFA article start after delivery, and the SCuBA baselines accept a third-party filter but still require identity and sharing controls.

The migration sequence

Microsoft's migration guide has three phases, prepare, set up and onboard, and our service follows it.

  1. Prepare. Inventory the gateway's rules, allow and block lists, outbound and DLP policies and archive scope. Confirm which Defender plan you hold and where DMARC reports go. Decide the archive's fate: export, migrate, or keep the vendor's archive-only product.
  2. Set up. Put a pilot ring in the Standard preset and priority accounts in Strict. Configure Enhanced Filtering for Connectors so Defender sees true source addresses while the gateway stays in front. Set quarantine notifications and user guidance, and recreate the allow and block entries that still make sense in the Tenant Allow/Block List.
  3. Onboard. Widen the presets to everyone. Switch the MX per domain to Microsoft (propagation can take up to 48 hours, as Microsoft notes) and restrict inbound mail to Microsoft's path. Watch the reports for two weeks and tune. Keep the gateway account open until the last domain has moved and the archive is settled; cancelling early loses data.

For a single-domain, 100-mailbox tenant this is two weeks of calendar time, most of it pilot and MX propagation. Archive export or migration is its own project, and it is what most often extends the gateway contract by a quarter.

Frequently asked questions

Do I still need Mimecast if I have Microsoft 365 Business Premium?

For filtering, no: Business Premium includes Defender for Office 365 Plan 1, which covers Safe Links, Safe Attachments and impersonation protection once users are in a preset policy. You still need Mimecast if you rely on its continuity or archive, or if it filters mail outside Microsoft 365.

Can I run Mimecast and Defender for Office 365 together?

Yes, and many do during a migration: configure Enhanced Filtering for Connectors, restrict inbound mail to the gateway's addresses, and decide which product owns quarantine. Permanently, it usually means two half-tuned filters.

What happens to my Mimecast archive if I cancel?

Access ends with the contract. Export or migrate the archive before the cancellation date, with a documented chain of custody if it is held for legal reasons.

Does Microsoft 365 E3 include Defender for Office 365?

Plan 1, yes, since the 2026 packaging update: Microsoft's licensing news page lists Defender for Office 365 Plan 1 among the additions to Microsoft 365 E3 and Office 365 E3, with rollout complete by August 1, 2026. Plan 2 is still an add-on for E3. At Microsoft's September 2026 list, Plan 1 is $24 per user per year for the plans that do not include it, and Plan 2 is $60.

Sources

  • Microsoft Licensing Resources, "Microsoft 365 Pricing and Packaging Updates" (2026), opened September 27, 2026: Defender for Office 365 Plan 1 added to Office 365 E3 and Microsoft 365 E3, rollout complete by August 1, 2026
  • Microsoft, "Microsoft Defender for Office 365" product page (microsoft.com/security), opened 2026-09-27 (Plan 1 and Plan 2 capability wording)
  • CISA, "M365 Secure Configuration Security Suite Baseline" in cisagov/ScubaGear on GitHub, opened 2026-09-27 (license inclusion wording; preset security policy description)
  • Microsoft Learn, "Migrate from a non-Microsoft protection service to Microsoft Defender for Office 365" and "Enhanced filtering for connectors in Exchange Online", as reported by search excerpts opened 2026-09-27; verify on Microsoft Learn
  • Microsoft Q&A, "MS 365 Business premium license include MS Defender Plan1 or Plan2?", and CIAOPS, "Microsoft Defender for Office 365 Plan 1 vs Plan 2" (May 20, 2025), as reported by search excerpts opened 2026-09-27
  • Mimecast product and support pages ("Advanced Email Security"; "Choosing Email Security Deployment Option"), Help Net Security, "Mimecast brings gateway-grade email security to API deployment" (March 10, 2026), and Proofpoint Essentials documentation ("Now Available: Integrated Deployment with Microsoft 365"), all as reported by search excerpts opened 2026-09-27; vendor pages were not reachable from our environment
  • Microsoft Commercial price list, September 2026 (all list prices above)
  • IT Partner service pages: content/services/ITPWW700MIGOT and ITPWW260SECOT; IT Partner blog articles linked above
  • IT Partner engineering notes, September 2026
Capability Exchange Online Protection (every tenant) Defender for Office 365 Plan 1 Defender for Office 365 Plan 2 Typical gateway (Mimecast, Proofpoint)
Anti-spam and anti-malware Yes Yes Yes Yes
Time-of-click URL protection No Safe Links Safe Links Yes
Attachment sandboxing No Safe Attachments Safe Attachments Yes
Impersonation and spoof protection Basic Yes, in preset policies Yes, in preset policies Yes
Threat hunting and automated investigation No No Yes Partly, in the vendor console
Email continuity during a Microsoft outage No No No Yes
Archive held outside Microsoft No No No Yes, with the archive product
Covers non-Microsoft mail platforms No No No Yes
Add-on list price, September 2026 n/a $24 per user per year $60 per user per year Vendor quote

Key takeaways

  • Business Premium, Microsoft 365 E3 and Office 365 E3 include Defender for Office 365 Plan 1 (E3 since the 2026 packaging update) and E5 includes Plan 2; the add-ons list at $24 and $60 per user per year on the September 2026 price list.
  • On inbound filtering Defender and the gateways overlap almost completely once users are in the Standard or Strict preset policies; a tenant on defaults is not a fair comparison.
  • What a gateway still adds is continuity during a Microsoft outage, an archive held outside Microsoft and coverage for other mail platforms; API-based vendor modes drop the continuity benefit.
  • Two filters in the mail path without Enhanced Filtering for Connectors give you broken sender checks, double URL rewriting, two quarantines and a bypass around the gateway, not defense in depth.
  • Migrate in Microsoft's three phases with a pilot ring, Enhanced Filtering, a staged MX cutover and inbound restriction, and settle the archive before the gateway contract ends.

If you have decided to move, Mimecast or Proofpoint to Defender for Office 365 Migration ($2,950 per project, two weeks) follows Microsoft's three-phase path: presets for a pilot ring while the gateway stays in front, Enhanced Filtering for Connectors, quarantine notifications and user communications, a staged MX cutover per domain with a documented rollback, and tuning on live traffic; archive migration is scoped separately so you do not lose access by cancelling too early. If the tenant has Defender licensed but never configured, Microsoft Defender for Office 365 Implementation ($2,900 per project, five days) sets up the policies, testing, alerts and reporting. Licenses are at Microsoft's list price; contact us with your gateway renewal date and we will work back from it.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.