Skip to main content
Shield Coverage

Shield Email Protection

Email is where most intrusions start. Shield Email Protection watches the mailbox - and it's priced per mailbox, so you can see exactly what you're paying for.

3
Regional officesBaltimore, Charlotte and Knoxville
1,400+
Detection rulesShipped via peer-reviewed CI/CD pipeline
100%
U.S.-based analystsZero offshore escalation paths

What it is

Microsoft 365 mail flow, authentication events and mailbox configuration are monitored by the SOClogix SOC. Phishing and business email compromise rarely announce themselves at the gateway - the signal is mailbox-level:

  • A mail rule created at 2am.
  • A forward to an external address.
  • An OAuth grant nobody requested.
  • A sign-in from an impossible location, followed by a quiet change to payment instructions.

Those are the events this service is built to catch.

What you receive

Detections triaged and investigated by an analyst, not forwarded. When a mailbox is compromised, you get the account, the timeline, what the attacker touched, and guided remediation - not an alert telling you something looked unusual.

The unit - per licensed user mailbox

  • Counted: any licensed Microsoft 365 user mailbox.
  • Not counted: shared, resource and room mailboxes. These are monitored at no additional charge. That exclusion is in your quotation and it is not a promotion - a shared mailbox is often exactly where an attacker hides, and charging for it would create an incentive to leave it uncovered.
  • Counted on the last calendar day of the month, billed in arrears.

All three tiers. The tier sets the rate and the depth of coverage behind it.

How it pairs

Email Protection and Shield ITDR are the two halves of the same attack. The phishing email lands in the mailbox; the credential it steals is used against the identity. Running both at Professional or Enterprise means one SOC correlates the message and the sign-in as a single incident rather than two unrelated alerts.

See the full Shield Coverage catalog.

More on the Microsoft 365 attack surface

Microsoft 365 Security

The full M365 attack surface, tenant hardening and what we monitor across email, SharePoint, Teams and Entra ID.

M365 Attack Surface Guide

Where attackers actually target your tenant, and the controls that close each path.

M365 Direct Send Phishing

How attackers spoof internal email through Direct Send, and how to detect it.

Ready for a SOC behind your business?

Contact SOClogix for a scoped Shield quotation. Every quotation is built from a scoped count of your real environment.

(443) 409-5426

We will get back to you within one business day.