New Defender XDR permission scopes access to user-reported malware and phishing emails

Microsoft is introducing a new permission in Defender for Office 365 that gives security teams more targeted access when investigating emails that users have reported as malware or phishing.


Timeline

The rollout should be completed in May 2026.

What is changing?

Reviewing email content linked to security alerts previously required broad access to all emails in the organization.
Security admins could select two permissions under email & collaboration.

  • Email & collaboration metadata (read)
  • Email & collaboration content: All Emails (read)
The previous email permissions in Defender XDR
The previous email permissions in Defender XDR

The new permission “Emails associated with alerts (read)”, found under Security operations, allows defined user accounts to preview and download only the specific emails associated with the alert “Email reported by user as malware or phish“.

New Defender XDR permission for user-reported malware and phishing emails
New Defender XDR permission for user-reported malware and phishing emails

As described in the updated unified RBAC documentation, the new permission is scoped to investigate flagged messages without requiring broader access to all email content in the organization.

New Defender XDR permission
New Defender XDR permission

Administrators who already hold the broader email and collaboration content read permission will see no change to their access or workflows. The new permission is an addition, not a replacement, and existing role assignments remain unaffected.

Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *