In short: For a lot of businesses on Microsoft 365 Business Premium or E5, Defender for Office 365 covers enough that a separate gateway is hard to justify on filtering alone. Where a gateway still earns its place is rarely the filtering: it is continuity when Exchange Online is unavailable, independent archiving with retention you control, and the assurance position of not having your mail security and your mail platform be the same vendor. Decide on those three, not on detection-rate marketing from either side.
- You are paying for Mimecast and Microsoft 365 and wondering whether you need both
- A renewal is coming up and you want a view that is not from either vendor
- You have Business Premium or E5 and suspect you are not using what you already own
- You have a retention, continuity or vendor-separation obligation to satisfy
Two outcomes, both expensive. Paying twice for overlapping protection year after year because nobody wanted to be the one who removed a security control. Or dropping the gateway to save money and discovering afterwards that it was carrying your archive and your continuity, neither of which Microsoft replaces by default.
Why nobody gives you a straight answer on this
Because almost everyone writing about it sells one of the two. Microsoft's material explains that Defender covers what you need. Mimecast's material explains that a native-only approach leaves gaps. Both are arguing their own book, and both make reasonable points, which is exactly what makes the question hard to resolve from public sources.
Systech resells Mimecast and is a Microsoft partner. We make money either way, and we would rather tell you not to buy something than sell you a licence you do not need and have the conversation about value at renewal instead.
Where Defender genuinely is enough
If you are on Business Premium or E5, your mail is entirely in Exchange Online, you have no regulatory archiving obligation, and nobody has asked you to demonstrate vendor separation in your security stack, then Defender for Office 365 configured properly is a reasonable place to stop.
The word doing the work there is configured. A very large share of the gaps we find in Microsoft 365 estates are not gaps in what the licence covers, they are features included in a licence the business already pays for and has never turned on. Safe Links and Safe Attachments policies left at defaults, no anti-phishing policy with impersonation protection, no Conditional Access. Buying a second product to sit in front of an unconfigured first one is an expensive way to avoid a configuration exercise.
That is genuinely the most common honest answer to this question: before adding a gateway, find out whether what you already own is switched on.
Where a gateway still earns its place
Continuity. If Exchange Online is unavailable, a gateway with continuity keeps mail flowing and gives users somewhere to read and send from. Whether that matters depends entirely on what an hour without email costs you, and for some businesses the answer is genuinely not much.
Independent archiving. If you have a retention obligation, or you may need to produce mail for a dispute or a regulator, an archive held separately from the platform that generates the mail is a stronger position than retention policies inside the same tenant. This is the one that most often decides it for regulated firms.
Vendor separation. If your mail platform and your mail security are the same vendor, a compromise or a misconfiguration in that vendor's stack affects both at once. Some sectors and some insurers now ask about this directly. Whether it is a real risk or a procurement preference varies, but it is increasingly a question you have to have an answer to.
Notably, none of those three is about catching more phishing. If a vendor is selling you a gateway primarily on detection rates, ask them to explain the continuity and archiving position instead.
If you decide to move off Mimecast
We will help you do that, and it is worth saying so explicitly on a page that could be read as a sales pitch for keeping it.
The part that catches people out is not mail flow, which is a straightforward connector and MX change. It is the archive. Mail already in a Mimecast archive does not automatically appear in Exchange Online, and archive extraction is slow, occasionally expensive, and much easier to plan before you give notice than after.
The other piece is policy parity. A gateway typically accumulates years of rules, allow lists and exceptions. Migrating those without review reproduces every historical mistake in a new system; not migrating them at all breaks things nobody remembers configuring. It needs a proper review either way.
What we do with Mimecast
- Review what your existing Microsoft 365 licence already covers and whether it is switched on
- Give a straight recommendation on whether a gateway is justified for your estate
- Manage Mimecast where it is: policy, continuity and archiving
- Migrate off Mimecast where it is not, including the archive extraction most people forget
- Harden Defender for Office 365 properly: anti-phishing, Safe Links, Safe Attachments, Conditional Access
Related
Frequently asked
Do I still need Mimecast if I have Microsoft Defender for Office 365?
For many businesses on Business Premium or E5, not on filtering alone. Defender configured properly covers a great deal. Where a gateway still earns its place is continuity when Exchange Online is unavailable, independent archiving with retention you control, and not having your mail platform and mail security be the same vendor. Decide on those three rather than on detection-rate claims, which both sides publish and neither side publishes neutrally.
Is Defender for Office 365 as good as Mimecast at catching phishing?
Both are capable, and any comparison of detection rates you find will have been produced by one of the two vendors or funded by one of them. In practice the difference we see in real estates is far less about the engine than about configuration: a well-configured Defender tenant outperforms a poorly configured gateway, and the reverse is equally true. If detection is your only concern, the higher-value exercise is almost always auditing what your current tooling is actually set to do.
What do we lose if we drop the gateway and rely on Microsoft alone?
Three things, in order of how often they matter. Continuity, so if Exchange Online is unavailable there is no independent path for mail. Independent archiving, so your retention and any legal or regulatory production relies on policies inside the same tenant that holds the mail. And vendor separation, so a compromise or misconfiguration in Microsoft's stack affects platform and security together. Whether any of those matters depends on your obligations and what an hour without email costs you.
We are paying for Mimecast but not sure we use it. How do we tell?
Look at three things. Is continuity actually configured and has it ever been tested. Is the archive being used for anything, meaning real retention or search requests rather than simply accumulating. And are the gateway's policies doing work that Defender is not already doing, which usually means comparing the two policy sets side by side. If the answer to all three is no, you are paying for a product doing nothing your Microsoft licence is not, and we would tell you that.
Can you help us migrate off Mimecast?
Yes. Mail flow is the straightforward part: connectors and an MX change. The archive is what catches people out, because mail held in a Mimecast archive does not automatically appear in Exchange Online, and extraction is slow and much easier to plan before notice is given than after. The other piece is policy parity: gateways accumulate years of rules and exceptions, and migrating them unreviewed reproduces old mistakes while dropping them entirely breaks things nobody remembers setting up.
Other vendors we support
- Progress Kemp LoadMaster support, licensing and lifecycle
- SonicWall firewall support, and what End of Support means for your model
- WatchGuard Firebox support and lifecycle: when you actually need to move
- Altaro is now Hornetsecurity: VM Backup and 365 Total Backup
- Nakivo Backup & Replication: what it covers and how it is licensed
- Exclaimer or native Microsoft 365 signatures: which one you actually need
Not sure where you stand with Mimecast?
Tell us what you are running and we will tell you plainly whether it needs action, including when the answer is that it does not.
