SHD / MC Checker

MC1422060 | (Updated) Microsoft Defender for Office 365: Prompt injection protection for email



MC1422060 | (Updated) Microsoft Defender for Office 365: Prompt injection protection for email

Classification planForChange
Last Updated 09/02/2026 17:03:17
Start Time 07/09/2026 21:50:12
End Time 11/16/2026 07:00:00
Message Content

Updated September 2, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why]

We are introducing prompt injection protection for email in Microsoft Defender for Office 365. This capability detects and blocks malicious prompt injection content embedded in email messages that attempt to manipulate AI assistants and agents. It helps protect enterprise data by identifying attacks designed to exfiltrate information, discover tools, or expose system prompts. High confidence threats are automatically quarantined before they can be processed by AI powered workflows. This enhancement strengthens enterprise ready AI security and aligns with evolving threat patterns.

[Rollout Schedule]

  • Public Preview: Beginning early July 2026 and expected to complete by early September 2026
  • General Availability (Worldwide): Beginning early October 2026 (previously early September) and expected to complete by early October 2026 (previously early September)

[Impact on Your Organization]

Who is affected

  • Organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5

Platforms and services

  •  Exchange Online, Microsoft Defender for Office 365, Microsoft Defender XDR services

What will happen

  • Emails identified as prompt injection will be classified as High Confidence Phish.
  • A new Detection Technology value called Prompt Injection Protection will be applied.
  • High confidence threats will be automatically quarantined.
  • The feature is enabled by default for eligible tenants.
  • Existing policies and workflows remain unchanged.
  • These detections will appear within existing threat investigation and reporting experiences in Microsoft Defender.

[Action Required / Recommendations]

No action is required.

Recommended actions:

  • Review your submission and quarantine workflows.
  • Use the Microsoft Defender submission process if false positives occur.
  • Use Tenant Allow Block List if needed to manage exceptions.
  • Inform your security and helpdesk teams about the new detection category.

Learn more: Prompt injection protection in Microsoft Defender for Office 365 | Microsoft Defender for Office 365 | Microsoft Defender | Microsoft Learn

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Machine Translation

2026年9月2日更新:タイムラインを更新しました。ご辛抱いただきありがとうございます。 

【何となぜ】

Microsoft Defender for Office 365でメール用のプロンプトインジェクション保護を導入します。この機能は、AIアシスタントやエージェントを操作しようとするメールメッセージに埋め込まれた悪意のあるプロンプトインジェクションコンテンツを検出・ブロックします。情報の流出、ツールの発見、システムプロンプトの露出を目的とした攻撃を特定し、企業データを保護します。高い信頼度の脅威は、AI搭載のワークフローで処理される前に自動的に隔離されます。この強化は企業向けのAIセキュリティを強化し、進化する脅威パターンに沿います。

[展開スケジュール]

  • パブリックプレビュー:2026年7月初旬から2026年9月初旬までに完了予定です
  • 一般公開(世界展開):2026年10月初旬(以前 は 9月初旬)から2026年10月初旬(以前 は9月初旬)までに完了予定です。

[組織への影響]

影響を受ける人物

  • Microsoft Defender for Office 365 Plan 2 または Microsoft 365 E5 を使用している組織

ホームとサービス

  •  Exchange Online、Microsoft Defender for Office 365、Microsoft Defender XDR services

何が起こるのか

  • プロンプトインジェクションと認定されたメールは、 高信頼フィッシュに分類されます。
  • 新しい検出技術の値である プロンプトインジェクション 保護が適用されます。
  • 高い信頼度の脅威は自動的に隔離されます。
  • この機能は、対象となるテナントに対して デフォルトで有効化 されています。
  • 既存のポリシーやワークフローは変更されていません。
  • これらの検出は 、Microsoft Defenderの既存の脅威調査および報告体験内に反映されます。

[行動が必要/勧告]

何の対応も必要ありません。

推奨される行動:

  • 提出書類を見直し、隔離作業を行ってください。
  • 誤検知が発生した場合はMicrosoft Defenderの提出プロセスをご利用ください。
  • 例外管理に必要な場合はテナント許可ブロックリストを使いましょう。
  • 新しい検出カテゴリについて、セキュリティおよびヘルプデスクチームに知らせてください。

詳しくはこちら: Microsoft Defender for Office 365におけるプロンプトインジェクション保護 |Microsoft Defender for Office 365 |Microsoft Defender |Microsoft Learn

[コンプライアンスの考慮事項]

コンプライアンス上の懸念事項は特定されず、組織に応じてレビューしてください。