Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
The provided context describes how Threat Explorer and remediation work, but does not state any licensing rules about which mailboxes (E3 vs E5/P2) an E5/P2‑licensed admin is allowed to act on. It only states that:
- Threat Explorer/Real‑time detections require Defender for Office 365 licensing and appropriate permissions for the user performing the actions.
- Email remediation (soft delete, hard delete, move to junk/deleted, etc.) is a Defender for Office 365 Plan 2 capability and requires the Search and Purge role or equivalent permissions.
From the context:
- “To use Threat Explorer or Real-time detections, you need to be assigned a license for Defender for Office 365… Threat Explorer or Real-time detections contains data for users with Defender for Office 365 licenses assigned to them.”
- “Microsoft Defender for Office 365 Plan 2 … enables security teams to remediate threats in email… through manual and automated investigation.”
- “Email remediation is an already existing feature that helps admins act on emails that are threats… What you need: 1. Microsoft Defender for Office 365 Plan 2… 2. Sufficient permissions (be sure to grant the account Search and Purge role).”
The context does not provide any explicit statement about:
- Whether an E5/P2‑licensed admin may or may not purge messages from mailboxes that are only licensed with E3.
- Any prohibition or restriction on using Threat Explorer or purge actions against E3‑licensed mailboxes in a mixed‑license tenant.
Because this specific licensing scenario is not covered in the supplied material, no definitive answer can be given from the context.
References:
- About Threat Explorer and Real-time detections in Microsoft Defender for Office 365
- Email security with Threat Explorer and Real-time detections in Microsoft Defender for Office 365
- Steps to use manual email remediation in Threat Explorer
- Remediate malicious email delivered in Office 365
- Threat hunting in Threat Explorer and Real-time detections in Microsoft Defender for Office 365
- Threat investigation and response