Why Microsoft 365 and Google Workspace Aren’t Enough to Protect Your Utah Business Email

Network Optimization

Every Utah business owner running Microsoft 365 or Google Workspace has made the same assumption: email security is handled. It's baked into the subscription, so there's nothing more to add. That assumption is half right.

The built-in tools are real. Microsoft Defender for Office 365 and Gmail's spam and malware filters catch millions of messages every day, and most Utah SMBs never see the ones that get blocked. But there's a category of attack built specifically to get past those filters, and it's the category doing the most damage to Utah businesses right now: business email compromise, vendor impersonation through lookalike domains, AI-written phishing that references real names and projects, and outbound data leaks that never trigger a single alert.

This article breaks down what Microsoft 365 and Google Workspace actually include at each plan tier, what they're built to miss, and what a managed email security layer adds on top. Utah examples throughout, because the businesses getting hit aren't abstractions.

Score Your Network in 2 Minutes.

We built a free interactive scorecard that sizes up your WiFi situation across seven risk factors and tells you exactly what to do next.

Key Takeaways

  • Microsoft 365 Business Basic and Standard don't include Defender for Office 365 Plan 1. Safe Attachments (sandboxing) and full impersonation detection are still Business Premium-only, even after Microsoft's mid-2026 packaging update.
  • Google Workspace's Security Sandbox is included starting at Business Standard. Business Starter doesn't get it.
  • Neither platform scans outbound mail for PHI, PCI, or PII by default. That gap sits open on every plan tier from both vendors.
  • Business email compromise, AI-generated phishing, and internal account compromise are built to pass SPF, DKIM, and DMARC, the exact checks platform-native filters rely on.
  • A managed email security layer adds inbound gateway inspection, outbound data governance, and 24/7 behavioral monitoring, on top of Microsoft 365 or Google Workspace, without replacing either.
  • 1Wire is currently offering two months of Managed Email Security at no charge.
popular platforms

What Microsoft 365 and Google Workspace Actually Include

Start with what's true: Microsoft and Google both build real security into their platforms, and getting the tier right matters more than anything else in this article.

Every Microsoft 365 Business plan, Basic, Standard, and Premium, includes Exchange Online Protection: spam filtering, basic malware detection, and anti-phishing policies that catch known threats and mass campaigns. What most Utah SMBs don't have is Microsoft Defender for Office 365 Plan 1, which adds Safe Links (URL rewriting and inspection at the moment someone clicks, not just at delivery) and Safe Attachments (opening attachments in an isolated sandbox before they reach an inbox). Defender Plan 1 has always shipped with Business Premium. Basic and Standard have not included it.

That's changing, partially. Microsoft's July 2026 packaging update is rolling out URL time-of-click protection to Business Basic and Business Standard by August 1, closing part of the Safe Links gap, alongside a price increase on both plans. Safe Attachments and the rest of Defender Plan 1, including sandboxing and full impersonation policies, still require Business Premium. A business on Standard is getting better URL protection this summer. It is not getting attachment sandboxing.

Google Workspace follows a similar pattern. Gmail's built-in protections, spam filtering, phishing and malware detection, apply across every tier, including Business Starter. Security Sandbox, which detonates attachments in an isolated environment the same way Safe Attachments does, is included starting at Business Standard and up. Business Starter doesn't get it.

Email security features by platform and plan tier for Utah businesses. Feature availability changes as Microsoft and Google update their platforms.

Table 1: What’s Included in M365 and Google Workspace vs. What Requires More
Feature M365 Basic/Standard M365 Business Premium Google Workspace Starter Google Workspace Standard/Plus
Spam filtering Included Included Included Included
Basic malware scanning Included Included Included Included
Anti-phishing policies Basic (Exchange Online Protection) Defender for Office 365 Plan 1 Basic only Enhanced
Safe Links / URL click-time protection Not included (URL time-of-click protection rolling out by Aug. 1, 2026) Included (Safe Links) Not available Not available
Attachment sandbox / detonation Not included Included (Safe Attachments) Not included Included (Security Sandbox)
Domain similarity / impersonation detection Limited Included (Defender Plan 1) Limited Limited
Outbound data scanning (PII/PHI/PCI) Not included Requires DLP add-on Not included Requires DLP add-on
Behavioral anomaly detection Not included Partial (Defender Plan 2 add-on) Not included Not included
Encrypted outbound messaging Not included Requires add-on Not included Partial
24/7 managed monitoring and response Not included Not included Not included Not included

The pattern that matters: both platforms handle known threats and mass-market spam well at every price point. The tools that catch attacks engineered to look legitimate, sandboxing, click-time inspection, impersonation analysis, start at a specific tier and stop there. Neither platform, at any tier, scans outbound mail for sensitive data or watches for behavioral anomalies in an account that's already been compromised. That's not a gap between Basic and Premium. It's a gap in what platform-native email security is built to do at all.

What the Built-In Tools Are Designed to Miss

Managed Email Security from daily email threats

Built-in filters work by pattern matching: known bad senders, known malware signatures, authentication failures. That's exactly why the attacks causing the most financial damage to Utah businesses are built to avoid every pattern the filters check for.

Business email compromise is the clearest example. An attacker registers a domain like acmesupplies-billing.com, close enough to a real vendor's name that nobody double-checks it, and sends an invoice that passes SPF, DKIM, and DMARC because it's genuinely coming from that domain, just not the vendor's real one. The sender name reads “John from Acme Supplies.” The invoice amount looks normal. Microsoft and Google's filters have nothing to flag, because nothing about the message is technically fraudulent. Domain similarity analysis, which flags lookalike domains before a human has to spot them, isn't included in Business Basic, Standard, or Google Workspace Starter.

AI-generated spear phishing is harder still, because there's no pattern to match. Each message is written around a recipient's actual job title, current projects, and manager's name, and no two look alike. How AI is making phishing attacks more dangerous covers why that shift breaks pattern-based detection entirely. A Murray accounting employee getting a message that references their manager by name and asks for an urgent wire transfer isn't looking at a mass campaign. They're looking at a message written for them specifically. Behavioral analysis, which flags unusual requests regardless of how the message is worded, does catch it. Pattern matching doesn't.

Outbound leakage is the gap most owners don't think about at all. Neither Microsoft 365 nor Google Workspace scans outbound mail for PHI, PCI, or PII by default. A Salt Lake City medical practice receptionist emailing a spreadsheet of patient names and appointment times to the wrong address isn't stopped by anything in a standard M365 or Workspace license. That's not a malicious act slipping past a filter. It's a filter that was never scanning outbound mail in the first place.

The hardest case is internal account compromise. Once an attacker has a valid credential, and credential theft doesn't require breaking anything technical, every email sent from that account is fully authenticated. An Ogden law firm partner's account sending wire instructions at 11pm on a Friday passes SPF, DKIM, and DMARC because it really is that account. Only a behavioral baseline, flagging unusual timing, volume, or request type, catches it. Neither platform builds that in.

One more gap worth naming before the table: QR codes in email bodies are images, not links, so Safe Links and Gmail's URL scanners don't inspect them by default. How phishing scams work breaks down how attackers exploit that blind spot with quishing, the row at the bottom of the table below.

The email attacks most likely to reach a Utah business inbox despite active Microsoft 365 or Google Workspace protection, and what stops them.

Table 2: Attack Types That Slip Through Built-In Filters
Attack Type Why Built-In Filters Miss It Utah Business Example What Catches It
Business email compromise (BEC) Sent from a legitimate lookalike domain that passes SPF, DKIM, and DMARC A Draper construction firm receives a fake invoice from “acmesupplies-billing.com,” built to match their real vendor’s name Domain similarity analysis in a dedicated email security gateway, not included in M365 Basic/Standard or Google Workspace Starter
AI-generated spear phishing Unique per recipient, references real personal details, passes every pattern-based filter A Murray accounting employee gets a message referencing their manager by name, requesting an urgent wire transfer Behavioral analysis that flags unusual sender patterns and request types, not part of platform-native filtering
Internal account compromise Attacker uses a stolen valid credential; outbound mail is fully authenticated An Ogden law firm partner’s M365 account sends wire transfer instructions at 11pm on a Friday Behavioral baselines that flag unusual sending time, volume, or content, a managed monitoring capability
Vendor impersonation via display name spoofing Display name shows a trusted contact; the sending address is unrelated and often passes basic filters A Provo dental group gets an email appearing to be from its X-ray equipment supplier, requesting updated payment details Header analysis and sender verification in an inbound email gateway
Outbound PHI/PCI/PII leakage Neither platform scans outbound mail for sensitive data patterns without a paid DLP add-on A Salt Lake City medical practice receptionist emails a spreadsheet of patient names, DOBs, and appointment times to the wrong address Outbound data governance scanning with PHI/PCI/PII rules
QR code phishing (quishing) QR codes in email bodies are images, not URLs, so Safe Links and URL scanners don’t analyze them by default Orem retail staff receive a fake Microsoft account verification email with a QR code linking to a credential-harvesting page Image-based threat detection and QR code URL analysis

None of this replaces the case for training employees to spot the obvious attempts before they reach this level of sophistication. Cybersecurity employee training for Utah businesses and this article's technical layer are complementary, not substitutes for each other.

What a Managed Email Security Layer Actually Adds

email security gateway

1Wire's Managed Email Security service is built around the specific gaps above, not a general upgrade to spam filtering.

The inbound gateway inspects messages before they reach Microsoft or Google's own filters, running domain similarity and impersonation analysis on every sender, catching the lookalike-domain and display-name spoofing attacks that pass SPF, DKIM, and DMARC. Malware and ransomware scanning quarantines dangerous attachments regardless of plan tier. Allow and block list management is handled by 1Wire directly, so a Utah office manager isn't maintaining sender policies by hand.

On the outbound side, data governance rules scan for PII, PHI, PCI, and NPI before a message leaves the building, the exact gap that leaves a medical practice's patient list or a law firm's settlement documents one misdirected email from a compliance problem. Encrypted message delivery covers the communications that need it, sent using a private key so only the intended recipient can read them, and it works across Microsoft 365, Google Workspace, desktop clients, and mobile apps.

1Wire is currently offering two months of Managed Email Security at no charge for businesses that complete an assessment and deploy the service. It's worth knowing about now, not just at the point of deciding whether to book.

The monitoring is the part that's easy to undersell. 1Wire watches the email environment 24/7, so a suspected account compromise or a sudden flood of outbound suspicious mail gets flagged before damage is done, not after an employee notices something's wrong and opens a ticket. Email security benefits for businesses covers a California lawyer who lost $59,517 to a monitoring bot planted inside his own firm's server, the kind of internal compromise a behavioral baseline is built to catch before the wire goes out.

None of this requires replacing Microsoft 365 or Google Workspace. The gateway sits in front of both, and setup is handled by 1Wire start to finish. Most Utah businesses are live within one business day. Email security is one layer in 1Wire's broader Managed IT Solutions, alongside Managed Firewall protection for the rest of the network.

Why This Matters for Utah Businesses Specifically

Utah isn't a generic market for this kind of crime. The Utah Cyber Threat Outlook documented 6,877 cybercrime complaints and $129.4 million in reported losses in 2024, figures drawn from the FBI's IC3 report for Utah victims specifically.

The industries most represented in Utah's business base, healthcare, legal, financial services, and technology, are exactly the industries where business email compromise and data leakage cause the most damage. A Provo medical practice sending appointment reminders through an unprotected outbound channel is one misrouted email from a HIPAA violation. A Salt Lake City law firm running an attorney's account on M365 Business Standard, without Safe Attachments or sandboxing, is one stolen credential from exposing client files.

Silicon Slopes companies mostly have IT teams built for this. The businesses this matters most for don't: the twenty-person accounting firm in Murray, the dental group with three locations in Ogden, the commercial real estate office in Draper. They're running the platform they were sold and trusting it to cover what it was never built to cover. The platform isn't failing them. It was never designed to do the job they're assuming it's doing.

Get a Free Email Security Assessment

If you're running Microsoft 365 or Google Workspace and haven't added a dedicated email security layer, a free assessment will show you exactly what's getting through. 1Wire reviews your current email environment, identifies the specific gaps for your plan tier, and can have protection deployed within a day.

Book your free consultation →

 

Want the full feature set first? Review the Managed Email Security service page before booking, or see best practices for email security for the full hygiene checklist alongside a managed solution.

Questions Utah Business Owners Ask Before Adding Email Security

If I upgrade to Business Premium, do I still need this?

Premium adds Defender Plan 1, Safe Links and Safe Attachments, which closes real gaps. It doesn't add outbound data governance, behavioral monitoring, or managed allow and block list maintenance. For a healthcare or legal practice, those remaining gaps are the ones that cost money.

How does 1Wire's service work with Microsoft 365 or Google Workspace?

It sits in front of both as an inbound gateway and behind them as an outbound scanner. Setup doesn't require switching platforms. Mail routes through the 1Wire layer first, then continues to your existing inbox.

How long does deployment take?

1Wire handles setup. Most Utah businesses are live within one business day.

What's the two-month free offer?

1Wire is currently offering two months of Managed Email Security at no charge. Book a consultation to confirm eligibility.

What about the employee side, not just the technology?

7 crucial tips to spot a phishing email covers the training angle. A managed email security layer and a trained team catch different things, and Utah businesses that do best have both.

Latest Posts

Managed Firewall vs. Consumer Router for Utah Businesses

Managed Firewall vs. Consumer Router for Utah Businesses

Most Utah business owners believe two things about their network. The router has a firewall, and that means the business is protected. Both are technically true. Together they create a false sense of coverage. We hear the same sentence in security conversations across...

How to Switch to Managed WiFi Without Disrupting Your Business

How to Switch to Managed WiFi Without Disrupting Your Business

You have read the comparisons. You know managed WiFi costs less over five years than buying and babysitting your own hardware, and you know what it does for coverage, security, and the support burden your staff currently carry. The decision is mostly made. What is...

What to Expect From Business WiFi Support

What to Expect From Business WiFi Support

You know the sequence. The WiFi goes down in the middle of a workday. You call support and spend twenty minutes explaining your setup to someone who has never heard of your business. The issue gets escalated. A technician shows up two days later with no more context...

Run your business with 1Wire

Save money, be more productive and future proof your business communications.

1wire helps

1Wire’s Personalized Technology Process

Expert guidance, custom solutions, seamless setup.

Book Your Free Consultation

Discuss your Business needs for phones, internet, networking, cybersecurity, and cabling.

Get a Custom Solution & Save

Receive a tailored package—1Wire clients save 20–35% compared to standard service providers.

Enjoy Expert Setup & Support

We handle installation and provide ongoing support for peace of mind.