Loading...

Microsoft Defender for Office 365: Prompt injection protection for email

Microsoft Defender for Office 365: Prompt injection protection for email

Microsoft Defender for Office 365 introduces prompt injection protection to detect and block malicious email content targeting AI assistants. High confidence threats are auto-quarantined. Available to Plan 2 and Microsoft 365 E5 users, enabled by default from early July 2026. No action required; review workflows and inform teams. What and Why We are introducing prompt injection protection for email in Microsoft Defender for Office 365. This capability detects and blocks malicious prompt injection content embedded in email messages that attempt to manipulate AI assistants and agents. It helps protect enterprise data by identifying attacks designed to exfiltrate information, discover tools, or expose system prompts. High confidence threats are automatically quarantined before they can be processed by AI powered workflows. This enhancement strengthens enterprise ready AI security and aligns with evolving threat patterns. Rollout Schedule Public Preview: Beginning early July 2026 and expected to complete by early September 2026 General Availability (Worldwide): Beginning early September 2026 and expected to complete by early September 2026 Impact on Your Organization Who is affected Organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5 Platforms and services  Exchange Online, Microsoft Defender for Office 365, Microsoft Defender XDR services What will happen Emails identified as prompt injection will be classified as High Confidence Phish. A new Detection Technology value called Prompt Injection Protection will be applied. High confidence threats will be automatically quarantined. The feature is enabled by default for eligible tenants. Existing policies and workflows remain unchanged. These detections will appear within existing threat investigation and reporting experiences in Microsoft Defender. Action Required / Recommendations No action is required. Recommended actions: Review your submission and quarantine workflows. Use the Microsoft Defender submission process if false positives occur. Use Tenant Allow Block List if needed to manage exceptions. Inform your security and helpdesk teams about the new detection category. Learn more: Prompt injection protection in Microsoft Defender for Office 365 | Microsoft Defender for Office 365 | Microsoft Defender | Microsoft Learn Compliance considerations No compliance considerations identified, review as appropriate for your organization. Message ID: MC1422060

The post Microsoft Defender for Office 365: Prompt injection protection for email appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Office 365: Prompt injection protection for email

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.