Microsoft Defender for Office 365: ZAP expands cleanup to Deleted Items
Zero-hour Auto Purge (ZAP) in Microsoft Defender for Office 365 will now scan and remediate malicious emails in users’ Deleted Items folders, enhancing post-delivery protection without new policies. Rollout starts June 2026, affecting all tenants with ZAP enabled, with no user experience changes or required actions. What and Why: We are extending Zero-hour Auto Purge (ZAP) in Microsoft Defender for Office 365 to scan and remediate malicious messages located in users’ Deleted Items folders. This enhancement strengthens post-delivery protection by ensuring phishing, spam, and malware messages are removed even after a user deletes or reports them, improving overall tenant security without introducing new policies or configuration. Rollout Schedule: General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out in early June 2026 and expect to complete by late July 2026. Impact on Your Organization: Who is affected: All tenants using Exchange Online Protection or Microsoft Defender for Office 365 Plan 1 or Plan 2 with ZAP enabled Platforms/Services: Exchange Online Microsoft Defender for Office 365 Outlook (desktop, web, mobile) What will happen: ZAP will retroactively scan and take action on malicious messages found in the Deleted Items folder within the ZAP detection window. This includes messages that were: Reported by users as phishing Automatically moved after accepting calendar invitations Manually deleted by users Messages identified as malicious will follow existing policy actions (for example, move to Junk, quarantine). No new policies, actions, or configuration settings are introduced. Admins will see additional ZAP activity in existing reports and alerts. A new SourceLocation column will be added to the EmailPostDeliveryEvents table in Advanced Hunting to indicate the originating folder (for example, DeletedItems). User experience remains unchanged. Action Required / Recommendations: No action is required. This change is enabled by default and respects your existing anti‑spam, anti‑phishing, and anti‑malware policies. Recommended actions for admins: Review existing ZAP-related reporting in Mail flow status and Threat Explorer to help your Security Operations Center (SOC) become familiar with the additional activity. Update internal security documentation or helpdesk guidance to note that Deleted Items are now included in ZAP remediation. Learn more: Zero-hour auto purge […]
The post Microsoft Defender for Office 365: ZAP expands cleanup to Deleted Items appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office 365: ZAP expands cleanup to Deleted Items
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Teams: Enhanced real-time alerting rule management in the Teams admin center
Microsoft Teams will enhance Real-Time Alerting rule management in the Teams admin center by enabling rule duplication, bulk user uploads, and...
Copilot Studio – Use MCP-compliant tools in agent workflows
We are announcing the ability to use MCP (model context protocol) – compliant tools in agent workflows in Microsoft Copilot Studio. This...
Microsoft Teams: Personal message reminders for chat and channels
Microsoft Teams will introduce personal message reminders for chat and channel messages in October 2026. Users can set, manage, and receive no...
M365 Copilot: Tell Copilot what you need directly from the Copilot button in Word, Excel, and PowerPoint
Microsoft 365 Copilot adds a new prompt input directly on the Copilot button in Word, Excel, and PowerPoint for faster, contextual content cre...
Microsoft Outlook for iPad: Minimize email drafts and return to them later
Outlook for iPad will allow users to compose emails in a separate window and minimize drafts to return later, enhancing multitasking. This fea...
Microsoft Purview eDiscovery: Select user-owned SharePoint Embedded containers as a data source
Microsoft Purview eDiscovery will support selecting user-owned SharePoint Embedded containers as data sources for cases, searches, and holds s...
Microsoft Purview: Removing pay-as-you-go requirements for Edge for Business DLP unmanaged app protections
Starting mid-October 2026, Microsoft Purview will remove the pay-as-you-go billing requirement for inline collection and DLP policies protecti...
Data Privacy: Microsoft Online Services Subprocessor Disclosure
This notice provides an update to the Microsoft Online Services Subprocessors List. Microsoft may engage non-Microsoft organizations to help p...
Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a securit...
30-Day Reminder: Windows Server 2022 will reach end of mainstream support on October 13, 2026
On October 13, 2026, Windows Server 2022 will reach end of mainstream support. The October 2026 security update will be the last mainstream su...