Microsoft Defender for Office 365: Email and associated entities hunting capabilities available through Microsoft Graph Security API

Microsoft has introduced email and related entity hunting capabilities to the Microsoft Graph Security API. This enables the hunt for email metadata, such as subject, sender, and domain, as well as MDO detections and related entities via the API. This new feature is available to users of Microsoft Defender for Office 365. The release date of the feature is set to be in October CY2023, with a preview available in June CY2023. The platform for this feature is web cloud instance, available worldwide for standard multi-tenant users.
To learn more about this new capability, visit the Microsoft 365 roadmap using the provided link.
This update was featured on M365 Admin, your go-to source for all things Microsoft 365 administration.
Published on:
Learn moreRelated posts
Microsoft Defender for Office 365 Permissions Update | Advanced Hunting
Microsoft Defender for Office 365 is updating the permissions mechanism for accessing Email & collaboration schema in Advanced Hunting to ...
Microsoft Defender for Office 365: False positive email release from Quarantine through threat explorer, email summary panel, and email entity page take action
The Microsoft Defender for Office 365 now enables SecOps to manage false positives and release quarantined messages to the inbox via the Threa...
Microsoft Defender for Office 365: Updates to Precedence of User and Organizational Email Allows and Blocks
If you are a customer with Exchange Online Protection and Microsoft Defender for Office 365 plan 1 and plan 2 service plans, you need to know ...
Microsoft Defender for Office 365: 100 Admin Submission at once
Microsoft Defender for Office 365 admins can now submit up to 100 emails for analysis at once from advanced hunting, threat explorer, and user...
Microsoft Defender for Office 365: Tenant Allow/Block List domain & addresses block to send inbound emails to admin quarantine
The latest update to Microsoft Defender for Office 365 addresses an important issue concerning the Tenant Allow/Block List. Previously, when a...
Microsoft Defender for Office 365: Built-in Protection Time of Click URL Email Protection
Microsoft Defender for Office 365 customers will soon be able to benefit from enhanced security features as the final remaining aspect of the ...
Microsoft Defender for Office 365: DMARC aggregate reports for enterprise
Microsoft Defender for Office 365 has introduced an update that allows the owner of a domain to access reports on how their emails were receiv...
Microsoft Defender for Office 365: Limitless Tenant Allow/Block List
Microsoft is updating its Defender for Office 365 security platform to allow customers with MDO P2 or E5 security to create unlimited block an...
Microsoft Defender for Office 365: Tenant blocks via admin submission
Microsoft Defender for Office 365 users can now ensure higher security by blocking senders, email addresses, domains, URLs and email attachmen...