Microsoft Defender for Office 365: Prompt injection protection for email
Microsoft Defender for Office 365 introduces prompt injection protection to detect and block malicious email content targeting AI assistants. High confidence threats are auto-quarantined. Available to Plan 2 and Microsoft 365 E5 users, enabled by default from early July 2026. No action required; review workflows and inform teams. What and Why We are introducing prompt injection protection for email in Microsoft Defender for Office 365. This capability detects and blocks malicious prompt injection content embedded in email messages that attempt to manipulate AI assistants and agents. It helps protect enterprise data by identifying attacks designed to exfiltrate information, discover tools, or expose system prompts. High confidence threats are automatically quarantined before they can be processed by AI powered workflows. This enhancement strengthens enterprise ready AI security and aligns with evolving threat patterns. Rollout Schedule Public Preview: Beginning early July 2026 and expected to complete by early September 2026 General Availability (Worldwide): Beginning early September 2026 and expected to complete by early September 2026 Impact on Your Organization Who is affected Organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5 Platforms and services Exchange Online, Microsoft Defender for Office 365, Microsoft Defender XDR services What will happen Emails identified as prompt injection will be classified as High Confidence Phish. A new Detection Technology value called Prompt Injection Protection will be applied. High confidence threats will be automatically quarantined. The feature is enabled by default for eligible tenants. Existing policies and workflows remain unchanged. These detections will appear within existing threat investigation and reporting experiences in Microsoft Defender. Action Required / Recommendations No action is required. Recommended actions: Review your submission and quarantine workflows. Use the Microsoft Defender submission process if false positives occur. Use Tenant Allow Block List if needed to manage exceptions. Inform your security and helpdesk teams about the new detection category. Learn more: Prompt injection protection in Microsoft Defender for Office 365 | Microsoft Defender for Office 365 | Microsoft Defender | Microsoft Learn Compliance considerations No compliance considerations identified, review as appropriate for your organization. Message ID: MC1422060
The post Microsoft Defender for Office 365: Prompt injection protection for email appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office 365: Prompt injection protection for email
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Change in sender email address for Copilot emails
Microsoft is updating the sender email for Copilot-related educational and enablement emails to [email protected] by mid-S...
Microsoft Purview: Information Protection – Auto-labeling simulation scale increase from 4 million to 20 million items
Microsoft Purview Information Protection increases auto-labeling simulation capacity from 4 million to 20 million items, expands SharePoint si...
Microsoft Exchange Online: Review and configure EWSAllowedAppIDs before Exchange Web Services access changes
Microsoft is updating how EWSAllowedAppIDs is applied in Exchange Online as part of EWS retirement starting October 1, 2026. Organizations usi...
IT resources to plan, prepare, and deploy Windows
New and updated resources are available whether you’re a seasoned IT pro or earlier in your career. Learn how to effectively roll out feature ...
[Whiteboard] Legacy Whiteboard migration to OneDrive
Microsoft Whiteboard is migrating from legacy Azure-based storage to OneDrive-backed storage. Migration must be completed by September 25, 202...
Microsoft Teams: Organize important resources in chats and channels
Microsoft Teams is introducing a new way to organize and access important resources in chats and channels. Users will be able to pin key conte...
Microsoft Teams: Analytics for desk utilization on Teams Pro Management portal
Teams admins can access utilization analytics for Teams bookable desks on Teams Pro Management portal, similar to analytics provided for meeti...
Outlook: Inline chat for email drafting
Instead of opening Copilot Chat every time you want to use Copilot to draft a message, this change introduces an inline chat component that st...
SharePoint: Changes to the FAQ web part authoring experience
The SharePoint FAQ web part will provide a standard, non-AI experience for manually creating, editing, and managing FAQs. The AI-assisted FAQ ...
Microsoft Teams: Multi-line call history tabs in the Calls app
Multi-line users get a redesigned call history experience that organizes activity by phone line. Call activity is organized into dedicated tab...