SecOps SignalMicrosoft Security Operations Intelligence

High - Microsoft Defender for Office 365 Plan 1, Microsoft Defender for Office 365 Plan 2, Microsoft 365 E3, Microsoft Teams - Microsoft primary source

Microsoft Defender for Office 365 latest feature updates including prompt injection protection and RBAC enhancements

Microsoft Defender for Office 365 introduced several impactful features including detection of prompt injection attacks in inbound emails, default use of unified RBAC for new Plan 2 organizations from July 2026, and inclusion of Plan 1 within Microsoft 365 E3. Other notable updates are enhanced user reporting in Teams, near real-time URL protection in Teams messages, mail bombing attack detection, and expanded AI-powered submission response capabilities. These updates improve security posture, access control, and user reporting functionality.

What changed

- Prompt injection attacks detection in emails - Unified RBAC as default for new Plan 2 organizations starting July 2026 - Microsoft Defender for Office 365 Plan 1 now included in Microsoft 365 E3 - Enhanced Teams message and call reporting (including calls and contextual messages) - Near real-time URL protection in Teams messages - Mail bombing attack detection added - AI-powered generative explanations for admin submissions - New RBAC permissions for email content associated with alerts - Expanded zero-hour auto purge (ZAP) and admin quarantine to Plan 1 - Email actions in Advanced Hunting for easier investigation and response - Ability to block malicious domains and sender emails in Teams portal - Localized default notification emails based on user language settings

Why it matters operationally

Security teams gain improved tools for detection and response including new attack detections (prompt injection, mail bombing), enhanced reporting and quarantine capabilities in Teams, better role-based access control, and streamlined investigation workflows. The inclusion of Defender Plan 1 in Microsoft 365 E3 may affect licensing and deployment strategies. Blocking malicious senders and domains more quickly and with real-time effects improves operational protection.

What the SOC should check

Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.

Recommended actions

  • Review and understand prompt injection attack detection capabilities for incident response
  • Prepare for unified RBAC becoming default for new Defender for Office 365 Plan 2 tenants starting July 2026
  • Leverage new RBAC permissions to enable email content preview related to alerts for analysts
  • Enable and configure user reporting features for Teams messages and calls to improve threat visibility
  • Use advanced hunting with new email actions to streamline investigations
  • Utilize mail bombing detection to monitor and mitigate volumetric email attacks
  • Consider impacts of Defender Plan 1 inclusion in Microsoft 365 E3 for licensing and product planning
  • Implement blocking of malicious Teams senders and domains via Defender portal for near real-time protection
  • Configure notification templates to support localized emails based on user language settings

KQL hunting context

New advanced hunting email actions and detection method values support hunting and automated response.

Source links

https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new