New Defender XDR permission for viewing and downloading quarantined emails
A new Defender XDR RBAC permission gives administrators read and download access to quarantined emails without granting broader access to email content.
A new Defender XDR RBAC permission gives administrators read and download access to quarantined emails without granting broader access to email content.
Defender XDR is adding a new permission that allows security teams to preview and download only the emails users have reported as malware or phishing, without requiring broader access to all email content in the organization.
Microsoft published an FAQ including timelines for when Microsoft 365 E3 and E5 customers can expect the additional Intune Suite capabilities, and when Microsoft 365 E3 customers will receive Defender for Office 365 Plan 1.
Microsoft is enabling Unified RBAC for new tenants with Defender for Office 365 Plan 2 starting at the end of May 2026.
Defender for Office 365 URL click alerts are expanding to Microsoft Teams. When users click malicious links in Teams messages, alerts now appear in the Defender portal for faster detection and investigation.
Microsoft has enhanced the Defender Tenant Allow/Block List to support blocking external Teams users and domains, centralizing external access controls across Microsoft 365.
Microsoft is expanding Teams message reporting to Defender for Office 365 Plan 1, allowing users to report suspicious and false-positive messages starting February 2026.
Microsoft will enable new messaging safety protections in Teams for tenants using the default configuration starting January 2026.
Microsoft will enable ZAP in Teams for organizations with Defender for Office 365 Plan 1 starting in January 2026, with an opt-out option available for security admins.