News · curated 13 Jul 2026
Prompt injection protection in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn
First reported microsoft.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
Microsoft Defender for Office 365's prompt injection detection addresses a real emerging attack surface where email is weaponized to hijack AI assistants that summarize or act on messages, giving defenders situational awareness of both the threat class and an available mitigation.
Microsoft documentation describes prompt injection protection built into Microsoft Defender for Office 365, which detects attacker-authored instructions embedded in inbound email (body, subject, quoted replies, attachments, or hidden markup) before that content reaches a user or an AI assistant such as Microsoft 365 Copilot. The feature explains indirect prompt injection techniques including direct instructions to the model and hidden/invisible text (white-on-white fonts, zero-size text, HTML/CSS tricks) and detects them as part of existing mail-flow inspection.