This article explains what to do after Defend completes a successful health check to complete your organization setup. This includes reviewing your results, tuning detection settings, configuring allow and deny lists, setting up notifications, and choosing initial deployment settings.
Recommended Next Steps
Complete the following steps in order to finish configuring Defend for your organization:
- Verify mail flow(post-delivery): Mail flow verification happens automatically as part of the health check. A passed health check confirms that inbound and outbound mail are routing through Defend correctly.
- Review and tune Company Impersonation Attacks and Linguistic Analysis: These detection settings are in the Settings page. For configuration steps, see the Defend - Configuring Company Impersonation Protection article and the Defend - Configuring Linguistic Analysis article.
-
Configure your Allow list, Deny list, and Productivity allow: Navigate to Allow / Deny lists in the main menu. Entries on the Allow list override Defend's classification for email, messaging, or both. For more details, see the Defend - Allow or Deny Lists article.
-
Set up admin notification preferences: Navigate to Event Notifications in the main menu to create and manage notification rules, including event type and severity. For more details, see the Defend - Event Notifications article.
Note: Confirm you can access the audit log. Most admin roles, including Global Administrator, already have access to the Audit Log in the main menu, so there's usually nothing to configure here. -
Create additional admin users, if needed: Navigate to User Management in the main menu and select the Add Admin button. For available roles and permissions, see the Defend - User Management article.
Initial Setup Tips
For new deployments, we recommend enabling Silent Mode or Monitoring Mode before turning on full enforcement.
What Silent Mode and Monitoring Mode Do
With either mode enabled, Defend processes email for all your users, but only named users receive Defend's teachable moments and auto-remediation. The rest of your organization has its email processed for learning only. Statistics and threat intelligence are available for all emails processed in Defend, regardless of mode.


