Defender for Office 365 – Prompt injection
Phishing still tries to trick humans. A newer class of email threat tries to trick the AI that reads mail on their behalf. Microsoft calls this prompt injection in email: instructions embedded in a message so that when someone – or an automated workflow – asks an assistant such as Microsoft Copilot to summarize, triage, or act on that mail, the model may follow the attacker’s instructions instead of the user’s intent.
As Mid-Michigan shops use assistants to summarize inboxes, the model becomes a target. Microsoft Defender for Office 365 is adding mail-flow detection aimed at that class of message. This is inbound quarantine, not a cleanup of SharePoint permissions. Confirm what your tenant actually has before you assume every mailbox is covered.
Prompt injection targets your AI – not just your people. Mail-flow quarantine is an earlier layer. It does not replace Copilot’s own safeguards.
How this differs from “click this link”
Traditional phishing mainly targets a person. Prompt injection targets the AI model. The payload is directive text, not only a lure. Microsoft’s documentation describes instructions hidden in the body, subject, quoted replies, attachments, or markup, written to override the model’s instructions or the user’s intent.
Common techniques Microsoft lists include direct instructions; hidden or invisible text (white-on-white, zero-size, off-screen, or HTML and CSS tricks); injection through quoted or forwarded content; attachments and metadata; and encoding or obfuscation. A person skimming the message may see an ordinary email. The assistant that “reads” the whole thread may see a command.
Microsoft’s Defender for Office 365 blog frames the chain this way: hidden instructions arrive, a user or agent asks Copilot to summarize, and the model may follow what was embedded. Successful injection, Microsoft Learn notes, can leak mailbox content, misclassify mail as safe, generate misleading summaries, or drive unwanted automated actions.
What Microsoft says the payloads try to do
Defender for Office 365 prompt injection protection focuses on credible threats that attempt to:
- Exfiltrate data through a URL – send or encode sensitive information to an attacker-controlled address.
- Reveal the assistant’s system prompt, alignment settings, or hidden policies.
- Discover available tools – especially tools that can read or write data.
Not every instruction-like sentence in business email is treated as an attack. Microsoft says basic test injections from known senders may not trigger, as a balance against false positives. Do not read a quiet Threat Explorer as proof that nothing is trying. Read it as a filter aimed at higher-confidence objectives.
What is rolling out
Microsoft Defender for Office 365 Plan 2 – and, per Message Center MC1422060, Microsoft 365 E5 tenants – can detect prompt injection content in inbound email as part of the same mail-flow inspection used for phishing and malware. Eligible tenants do not need a separate policy to benefit. This pack does not claim Plan 1 coverage.
Per Microsoft Learn and MC1422060:
- Detections use the existing High Confidence Phish verdict.
- A new Detection Technology value appears: Prompt Injection Protection, filterable in Threat Explorer, real-time detections, and Advanced Hunting.
- High-confidence threats are automatically quarantined before AI-powered workflows can process them.
- The feature is enabled by default for eligible tenants. Existing policies stay in place.
Rollout, from MC1422060 as updated September 2, 2026: public preview began early July 2026 and was expected to complete early September 2026. General availability worldwide begins early October 2026 (the earlier target had been early September). Do not assume every mailbox is covered on a given day. Confirm status in your Message Center and tenant. Platforms named in the message are Exchange Online, Defender for Office 365, and Defender XDR.
What quarantine means for helpdesk
Microsoft’s quarantine documentation is the right companion here. High confidence phishing is among the detections that are always quarantined. Recipients generally cannot release those messages themselves. Depending on policy, they may only request release. The default action for high-confidence phish is quarantine.
Analysts review hits in Email Quarantine and on Explorer and email entity pages. MC1422060 says no tenant action is required to turn the feature on, and still recommends reviewing submission and quarantine workflows, using Defender submissions for false positives, and using the Tenant Allow/Block List only for a real exception.
Defense in depth, not a silver bullet
Microsoft describes three layers: mail-flow detection, Copilot safety systems at model runtime, and Defender XDR correlation. Quarantine keeps high-confidence mail away from Copilot and other AI grounded in Exchange Online. It is not a reason to ignore permissions, grounding, or what an agent is allowed to do.
What to do
For people using Copilot on mail
- Treat odd summaries or unexpected actions as something to report, not only a glitch
- If a message is missing, check with IT before assuming it was deleted – it may be quarantined
- Do not expect to self-release high-confidence phishing; request a review if policy allows
- Keep using normal phishing reporting for mail that still reaches the inbox
For organizations
- Confirm Defender for Office 365 Plan 2 or Microsoft 365 E5 for mailboxes that feed Copilot or other AI workflows
- Filter Threat Explorer and real-time detections by Prompt Injection Protection
- Review quarantine release rules and brief helpdesk: high-confidence phish is not a user self-release
- Send false positives through Microsoft Defender submissions; use Tenant Allow/Block List only when needed
- Keep Copilot runtime safeguards. Mail-flow is one layer
Practical admin checklist
Confirm Defender for Office 365 Plan 2 or Microsoft 365 E5 coverage for mailboxes that feed Copilot or other AI workflows.
In Microsoft Defender, filter Threat Explorer and real-time detections by Detection Technology = Prompt Injection Protection.
Review Email Quarantine for High Confidence Phish. Users generally cannot self-release; they may only request release, depending on policy.
Walk helpdesk through false positives: submit via Microsoft Defender submissions, and use Tenant Allow/Block List only when needed.
Treat this as defense in depth. Copilot and other Microsoft AI products still have runtime safeguards. Check Message Center MC1422060 before assuming general availability is complete in your tenant.
Bottom line for Mid-Michigan teams
Prompt injection hides instructions where an assistant will read them. Defender for Office 365 Plan 2 can classify high-confidence hits as High Confidence Phish, tag them Prompt Injection Protection, and quarantine them before AI workflows process the message. The feature is on by default for eligible tenants, with worldwide general availability beginning early October 2026. Confirm licensing, watch the new detection, and rehearse quarantine with helpdesk. Then keep the runtime safeguards. One layer is not a program.
KW Corporation is part of your team. Our Managed IT practice helps Mid-Michigan and statewide clients tighten mailbox security and AI-adjacent guardrails – quarantine hygiene, Defender for Office 365 readiness, and admin playbooks – so new Microsoft protections actually get used.
Aligning mailbox security with AI?
KW’s Managed IT team can help Mid-Michigan organizations with Defender readiness, quarantine playbooks, and practical AI guardrails.
Microsoft documentation used for educational commentary. See original pages for full guidance:
Microsoft Learn – Prompt injection protection –
MC1422060 (Message Center archive) –
Defender for Office 365 blog – Defending the inbox –
Quarantine overview
Technology @ Your Service
KW Corporation – 307 W. Grand River Ave, Fowlerville, MI 48836 – 517-223-3610 – support@kw-corp.com



