Hello!
I would configure Defender in 1 of 2 ways.
EOP (No Defender licenses)
MS defaults and let Check Point do all the security.
Defender P1 or P2
Configure the policies as you want, with the security levels you want, and create a custom Quarantine Digest in MS365 that does not send the digest emails. Then go into CP and configure CP to send the Quarantine and to integrate with MS365 Quarantine.
So, your MS365 Quarantine emails will show up on your CP digest.
Unified Quarantine - Admin and End User View of All Emails Quarantined by Microsoft and Avanan
Whether this is best practice, I am not sure, but this is how I have it set up and it works me and my clients.