Microsoft Defender for Office: Introducing “Threat classification” for email
Microsoft Defender for Office is introducing a “Threat classification” feature for emails, utilizing advanced techniques for accurate threat intent analysis. It will integrate across various experiences, aiding in better detection and response. The rollout begins early January 2025 and completes by late January 2025. Users should prepare by familiarizing with the new feature and updating workflows. Coming soon to Microsoft Defender for Office: We will introduce Threat classification details to enhance your ability to understand the intent behind email attacks. This update will allow you to integrate Threat classification information across key experiences, enabling better detection, analysis, and response. The Threat classification system utilizes large language models (LLMs), machine learning (ML) models, and other advanced techniques to understand the intent behind threats, providing a more accurate classification. As the system evolves, you can expect new Threat classifications to be added to keep pace with emerging attack methods. When this will happen: General Availability (Worldwide): We will begin rolling out early January 2025 and expect to complete by late January 2025. How this will affect your organization: Threat Explorer: You will be able to filter emails by Threat classification, view the classification in the results, analyze trends using charts, and export data with the classification details included: View image in new tab Advanced Hunting: The ThreatClassification column will be available in the EmailEvents table, allowing you to create custom detection rules based on classification details: View image in new tab Email summary panel: Threat classification will be integrated across multiple areas, including Alerts, Incidents, Reports, AIR, Submission, Explorer, and Advanced Hunting, providing a comprehensive view of threat classifications: Email entity page: A new Threat classification field will be added in the threat detection details, helping you understand the context and intent of the detected threat: What you need to do to prepare: View image in new tab View image in new tab These changes will be available by default for admins to configure. Familiarize your team with the new Threat classification details available in the Threat Explorer, Advanced Hunting, email summary panel, and email entity page. Leverage Threat classification to enhance […]
The post Microsoft Defender for Office: Introducing “Threat classification” for email appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office: Introducing “Threat classification” for email
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Copilot (Microsoft 365): Local inferencing
Local inferencing expands Microsoft Copilot’s sovereign controls by enabling AI inferencing for supported Copilot interactions to occur within...
Dynamics 365 Customer Service: Quality evaluation supports knowledge source in criteria
Criteria questions can now use knowledge sources to help evaluate customer interactions. This allows organizations to ground evaluation criter...
Microsoft Viva: Ability for leaders to publish Power BI reports
Microsoft Viva Insights is extending its report publishing capabilities from analysts to leader personas such as Chief Officers, Managers and ...
Dynamics 365 Customer Service: Detailed quality evaluation score breakdown
Evaluation details now include a scoring breakdown at the overall, section, and question level. Users can see how the final evaluation score w...
Dynamics 365 Customer Service: Support Not Applicable answer option for quality evaluation criteria
Criteria questions now support a Not Applicable answer option. When a question is marked as not applicable, it is excluded from scoring instea...
Dynamics 365 Customer Service: Inactivate quality evaluation records
Quality managers can now inactivate evaluation records that should no longer contribute to scoring or reporting. Inactive evaluations are pres...
Microsoft Teams: Granular Conditional Access for Teams meetings
Granular Conditional Access for Teams meetings gives organizations greater control over access to sensitive meetings. Administrators can apply...
Customized PowerBI reports behavior after major report updates
Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...
Microsoft SharePoint: Changes to the FAQ web part authoring experience
The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...
Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...