MC1422060: Microsoft Defender for Office 365 Adds Prompt Injection Protection for Email

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
33
0 25 50 75 100
MODERATE IMPACT • ASSESS BUSINESS IMPACT
Recommended Action:
Take a look and decide whether this affects your tenant, users or support teams.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Security TeamsMicrosoft 365 AdminsTenant AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
Timeline for general availability has shifted from early September to early October, reducing immediacy. Feature is enabled by default and improves security posture, so admin effort is mainly reviewing detection, quarantine and exception processes, and informing relevant teams. End users will not see workflow changes, so user impact is minimal.
40
🛡️ Admin Impact
15
👥 User Impact
35
Urgency
30
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Defender for Office 365 adds prompt injection protection for email, automatically quarantining high-confidence threats targeting AI workflows.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review submission and quarantine workflows and inform security teams about the new detection category.
📅

ROLLOUT TIMELINE

Upcoming:
Early October 2026

📢 Official Microsoft Message Center Announcement


(Updated) Microsoft Defender for Office 365: Prompt injection protection for email
Message ID: MC1422060

Updated September 2, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why]

We are introducing prompt injection protection for email in Microsoft Defender for Office 365. This capability detects and blocks malicious prompt injection content embedded in email messages that attempt to manipulate AI assistants and agents. It helps protect enterprise data by identifying attacks designed to exfiltrate information, discover tools, or expose system prompts. High confidence threats are automatically quarantined before they can be processed by AI powered workflows. This enhancement strengthens enterprise ready AI security and aligns with evolving threat patterns.

[Rollout Schedule]

  • Public Preview: Beginning early July 2026 and expected to complete by early September 2026
  • General Availability (Worldwide): Beginning early October 2026 (previously early September) and expected to complete by early October 2026 (previously early September)

[Impact on Your Organization]

Who is affected

  • Organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5

Platforms and services

  •  Exchange Online, Microsoft Defender for Office 365, Microsoft Defender XDR services

What will happen

  • Emails identified as prompt injection will be classified as High Confidence Phish.
  • A new Detection Technology value called Prompt Injection Protection will be applied.
  • High confidence threats will be automatically quarantined.
  • The feature is enabled by default for eligible tenants.
  • Existing policies and workflows remain unchanged.
  • These detections will appear within existing threat investigation and reporting experiences in Microsoft Defender.

[Action Required / Recommendations]

No action is required.

Recommended actions:

  • Review your submission and quarantine workflows.
  • Use the Microsoft Defender submission process if false positives occur.
  • Use Tenant Allow Block List if needed to manage exceptions.
  • Inform your security and helpdesk teams about the new detection category.

Learn more: Prompt injection protection in Microsoft Defender for Office 365 | Microsoft Defender for Office 365 | Microsoft Defender | Microsoft Learn

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update