Microsoft adds email prompt injection filter to protect Copilot
The vendor says its Defender email service now detects and isolates malicious AI instructions before messages reach inboxes that agents read.
By The Agentic Times ·

Microsoft said on 17 September 2026 that Microsoft Defender now includes prompt injection protection for email, designed to detect and isolate malicious AI instructions in messages before they are delivered. The company said the feature is intended to protect "not only people, but also Copilot, agents, and other AI systems that read and act on inbox content".
The disclosure came in Microsoft's fifth consecutive quarterly email security benchmarking blog post, which compares Defender's performance against other secure email gateway (SEG) and integrated cloud email security (ICES) vendors using Microsoft's own telemetry.
Prompt injection is an attack in which text hidden in ordinary content is written to look like an instruction to an AI system, so that a model reading the content follows the attacker's wishes rather than the user's. Email is an obvious delivery route, because assistants such as Copilot are routinely given access to a user's inbox and can summarise, draft or act on messages without a person reading the underlying text first. Microsoft described the filter as evidence of how it continues "evolving our defenses to address the latest cyberattack techniques". The company did not publish detection rates for the prompt injection feature, or describe how isolation works in practice.
The rest of the post covered conventional email threats. For the period from May 2026 to July 2026, Microsoft said Defender missed 221 high-severity threats per 1,000 protected users, which it described as 55.4% fewer than the next-closest SEG vendor. The benchmark counts missed threats rather than messages caught, the company said, because catch totals reflect differences in threat volume and exposure between vendor environments, and normalising per 1,000 users allows a more consistent comparison. The data source for all the published figures is Microsoft Defender itself.
Microsoft acknowledged that missed threats have risen across several reporting periods, including for its own product. It attributed this to a broader trend in which AI "makes it easier for cyberattackers to gather public information, tailor messages, and create more convincing impersonation attempts", and said this reinforces the need for protection that continuously adapts.
On the ICES side, Microsoft said third-party tools continue to add the most value in filtering promotional and bulk mail, with more modest contributions elsewhere. It reported ICES vendor malicious catch at 0.30%, up from 0.13% in the previous quarter, and spam catch at 0.52%, up from 0.28%. Defender itself caught 92% of post-delivery malicious messages on average during the period, according to the company. Microsoft said post-delivery remediation is not a one-off action, and that Defender continuously reevaluates delivered messages as new indicators and campaign intelligence emerge.
The company also said benchmarking has shaped other product work, including a new Promotions folder in Outlook and a redesigned machine learning and AI model stack that incorporates natural language processing signals such as message topic. Over a four-week period, Microsoft research observed roughly a two-thirds reduction in false negatives and nearly a one-fifth reduction in false positives for Defender customers, the company said.
Microsoft said its benchmarking programme began in July 2025 with the stated goal of bringing greater transparency to email security effectiveness. The figures have not been independently verified.
Sources
- microsoft.comhttps://microsoft.com/en-us/security/blog/2026/09/17/improving-email-security-outcomes-with-real-world-microsoft-defender-insights
