Microsoft Defender for Office: Introducing “Threat classification” for email
Microsoft Defender for Office is introducing a “Threat classification” feature for emails, utilizing advanced techniques for accurate threat intent analysis. It will integrate across various experiences, aiding in better detection and response. The rollout begins early January 2025 and completes by late January 2025. Users should prepare by familiarizing with the new feature and updating workflows. Coming soon to Microsoft Defender for Office: We will introduce Threat classification details to enhance your ability to understand the intent behind email attacks. This update will allow you to integrate Threat classification information across key experiences, enabling better detection, analysis, and response. The Threat classification system utilizes large language models (LLMs), machine learning (ML) models, and other advanced techniques to understand the intent behind threats, providing a more accurate classification. As the system evolves, you can expect new Threat classifications to be added to keep pace with emerging attack methods. When this will happen: General Availability (Worldwide): We will begin rolling out early January 2025 and expect to complete by late January 2025. How this will affect your organization: Threat Explorer: You will be able to filter emails by Threat classification, view the classification in the results, analyze trends using charts, and export data with the classification details included: View image in new tab Advanced Hunting: The ThreatClassification column will be available in the EmailEvents table, allowing you to create custom detection rules based on classification details: View image in new tab Email summary panel: Threat classification will be integrated across multiple areas, including Alerts, Incidents, Reports, AIR, Submission, Explorer, and Advanced Hunting, providing a comprehensive view of threat classifications: Email entity page: A new Threat classification field will be added in the threat detection details, helping you understand the context and intent of the detected threat: What you need to do to prepare: View image in new tab View image in new tab These changes will be available by default for admins to configure. Familiarize your team with the new Threat classification details available in the Threat Explorer, Advanced Hunting, email summary panel, and email entity page. Leverage Threat classification to enhance […]
The post Microsoft Defender for Office: Introducing “Threat classification” for email appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office: Introducing “Threat classification” for email
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Teams: Updated header and dashboard for chats and channels on mobile
Microsoft Teams mobile will feature a redesigned header and lightweight dashboard for chats and channels, improving navigation and access to k...
Deprecation for Manifest V2 (MV2) browser extensions support in Microsoft Edge
Microsoft Edge will retire Manifest V2 (MV2) extensions by early 2027, fully switching to Manifest V3 (MV3) for improved security and performa...
Power BI subscriptions: Changes to notification delivery and sender experience
Power BI is updating subscription notification delivery to improve reliability and sender reputation, changing sender identity, email formatti...
Cross-post SharePoint News to Engage
SharePoint News can now be cross-posted to Viva Engage communities with full fidelity and synchronized conversations across platforms. Rolling...
Call Quality Dashboard Custom Detailed Reports
Call Quality Dashboard will get a refreshed interface with enhanced accessibility and features like dark mode. Public preview starts mid-Augus...
Microsoft Copilot Pages: Access existing Pages from the “/” menu in chat
Starting late August 2026, users can access existing Pages via the “/” menu in Copilot chat, while the “Edit in Pages”...
Microsoft Teams: Collect information with List Form in Workflows
Microsoft Teams Workflows will add a new trigger, “A form is submitted,” for automating actions based on SharePoint list–backed fo...
Microsoft Viva Engage: Reducing reply notification volume in email
Microsoft Viva Engage will reduce email reply notifications by only sending alerts for direct replies, @mentions, and new posts, cutting down ...
Microsoft Teams: Lobby visibility will align with the “Who can admit from lobby” meeting option
Microsoft Teams will align lobby visibility with the “Who can admit from lobby” setting, so only users allowed to admit participan...
Microsoft Word: Similarity Checker retirement
Microsoft Word’s Similarity Checker will be retired on October 3, 2026, and removed from Microsoft Editor. Other writing and editing fea...