LUCIDTextjet - Print logo

WithSecure Elements Collaboration Protection for Microsoft 365

Short Description

Open HTML

What are the core benefits of WithSecure Elements Collaboration Protection for Microsoft 365?
Central console – Managed in Elements Security Center, no endpoint agent needed.
Full coverage – Scans Exchange Online, SharePoint, OneDrive and Teams files.
Cloud sandboxing – Unknown attachments are detonated and analysed in isolation.
Breach alerts – Warns when company mailbox credentials appear in data breaches.
Rule monitoring – Flags malicious forwarding and auto-delete rules in mailboxes.
Important note – Endpoints, Microsoft 365 backup and user MFA need separate products.

Long Description

Open HTML

What is included in WithSecure Elements Collaboration Protection for Microsoft 365?

Mailbox content scanning – Attachments and URLs in emails, calendar items, tasks and contacts.
SharePoint, OneDrive, Teams scanning – Files stored or shared there are analysed for malware and phishing.
Advanced threat detection – Suspicious unknown files are detonated in an isolated cloud sandbox.
Compromised account detection – Notifies users and admins when mailbox credentials appear in breaches.
Inbox rule scanning – Detects forwarding and auto-delete rules that attackers set up.
Important – No endpoint protection, Microsoft 365 backup or user MFA included.

What are the main benefits of WithSecure Elements Collaboration Protection for Microsoft 365?

WithSecure Elements Collaboration Protection for Microsoft 365 is a cloud-to-cloud security module that adds malware, phishing and account-compromise detection on top of the protection built into Microsoft 365, managed centrally in the web-based WithSecure Elements Security Center. It was previously sold as WithSecure Cloud Protection for Microsoft Office 365 and is now marketed as the Email and Collaboration Protection capability of WithSecure Elements XDR.

No installation – Connects cloud-to-cloud, with no software, server or client changes.
Quarantine in tenant – Harmful items move to a hidden quarantine folder in your tenant.
Device-independent protection – Threats are detected whether users work in Outlook, browser or phone.
Scheduled reports – Periodic overviews of detections for management reviews and audits.
Granular admin roles – Separate admin, read-only and quarantine manager roles limit access.
Multi-tenant management – Service providers manage several customer tenants from one portal.

Which company size is WithSecure Elements Collaboration Protection for Microsoft 365 suitable for?

The product fits any organisation whose email and file sharing run on Microsoft 365, from a small business without IT staff to a service provider managing many tenants. For a small company, the main gain is that one administrator connects the tenant once and then only reacts to detections, with no agents to roll out. For medium-sized and large companies, it closes the gap between the filtering in standard Microsoft 365 plans and the sandboxing that Microsoft reserves for higher-tier plans, and it serves as one documented layer within a broader security setup.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland By sector By sector By sector
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Occasional Common Standard
Sandboxing for Microsoft 365 mail and files ✓ ✓ ✓
This product fits Good fit Good fit As one layer

Does WithSecure Elements Collaboration Protection for Microsoft 365 meet the requirements of Swiss cybersecurity legislation?

The revised Information Security Act obliges operators of critical infrastructure, such as energy suppliers, healthcare providers, financial institutions, telecommunications companies and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery; most other companies are not directly affected but may receive similar requirements through customer contracts. WithSecure Elements Collaboration Protection for Microsoft 365 supports the detection side of this obligation: it flags malicious attachments and URLs, manipulated inbox rules and breached mailbox credentials in Microsoft 365 as soon as they occur. Each detection records the affected mailbox, sender, recipients, subject and file name, which helps describe an incident accurately in a report. The product does not decide whether an incident is reportable, does not submit the report, does not detect attacks on endpoints, servers or the network, and does not provide round-the-clock monitoring on its own. This information is not legal advice; for a binding assessment of your obligations, consult a qualified legal professional.

Does WithSecure Elements Collaboration Protection for Microsoft 365 meet the requirements of European cybersecurity legislation?

No software product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk management measures, not a specific tool. Those measures include incident handling, business continuity and backup, supply chain security, basic cyber hygiene and training, access control, cryptography and multi-factor authentication. WithSecure Elements Collaboration Protection for Microsoft 365 contributes to incident handling by detecting and quarantining malicious content in Exchange Online, SharePoint, OneDrive and Teams, and to access control by alerting administrators when company credentials appear in data breaches. Its administration portal supports multi-factor authentication and role-based access, and portal audit logs are retained for up to two years. It does not back up Microsoft 365 data, encrypt email, train users, enforce multi-factor authentication for Microsoft 365 users, or protect devices, so these measures must be covered separately.

Does WithSecure Elements Collaboration Protection for Microsoft 365 help with security questionnaires from large customers?

Yes, for the email and file-sharing part of a questionnaire, but not beyond it. The product lets you answer yes to questions on malware and phishing scanning of inbound, outbound and internal email, sandbox analysis of unknown attachments, URL reputation checks, scanning of files in SharePoint, OneDrive and Teams, quarantine handling, detection of compromised accounts and malicious inbox rules, and role-separated administration with multi-factor authentication. It does not answer questions on endpoint and server protection, endpoint detection and response, patch management, backup and recovery of Microsoft 365 data, email encryption or data loss prevention, security awareness training, or multi-factor authentication for all employees. The most direct way to close the technical gaps is to add further modules of the same WithSecure Elements platform, such as Endpoint Protection, Endpoint Detection and Response or Identity Security, which are managed in the same Elements Security Center; backup, training and organisational policies still need separate solutions.

Which limitations should you know before buying?

The product protects only Microsoft 365 and Office 365 cloud services; on-premises Exchange servers, other mail platforms and endpoints are outside its scope, and it works on top of Microsoft's own filtering rather than replacing it. It is a standalone module that does not require other Elements products, but connecting a tenant requires Microsoft Global Administrator consent. For Teams, the documented protection covers files shared in channels and chats; scanning of chat message text is not documented. Compromised account detection is based on breach intelligence about leaked credentials, not on analysis of sign-in behaviour; detecting suspicious Entra ID sign-ins is the task of the separate WithSecure Elements Identity Security module, which is the most common follow-up purchase. New mailboxes, sites and channels can take up to two to three hours to be discovered, although they can be protected automatically once found; no region-specific feature restrictions were found.

Frequently asked questions about WithSecure Elements Collaboration Protection for Microsoft 365

Which Microsoft 365 plans are supported?

WithSecure lists Microsoft 365 Business Basic, Business Standard and Business Premium, Microsoft 365 E3, E5, F1 and F3, Office 365 E1, E3 and E5, as well as the Microsoft 365 and Office 365 education plans A1, A3 and A5.

Where are quarantined emails stored?

Harmful items are moved or copied to a hidden quarantine folder inside your own Microsoft 365 tenant, and only metadata such as mailbox, sender, subject and file name is kept in the quarantine database. Administrators can review and restore items from the Elements Security Center.

What access does the product need in Microsoft 365?

The application requests read and write access to mail, calendars and contacts in all mailboxes, directory read access and access to activity and service health data. This scope is required to scan and quarantine content and should be noted in your internal security review before connecting the tenant.

 

Meta Description

Scans Exchange Online, SharePoint, OneDrive and Teams for malware and phishing via cloud-to-cloud API. For companies already on Microsoft 365.

Keywords

WithSecure Elements Collaboration Protection for Microsoft 365, WithSecure, WithSecure Elements, WithSecure Cloud Protection for Microsoft Office 365, Microsoft 365 email security, collaboration security, attachment sandboxing, compromised account detection, inbox rule scanning

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree