Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1046168

Microsoft Defender for Office: "Threat classification" in Mail flow status summary and Threat protection status reports

Informational

Message ID

MC1046168
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Office is introducing "Threat classification" into the Mail flow status summary and Threat protection status reports to better understand email attack intent. The rollout began in mid-March 2025 and will complete by late May 2025. No admin action is required, but reviewing current configurations and notifying users is recommended.

Details

Following MC973503 (Updated) Microsoft Defender for Office: Introducing "Threat classification" for email (published January 2025, updated March 2025), we will introduce Threat classification into the Mail flow status summary report and the Threat protection status report to enhance understanding of the intent behind an email attack.

When this will happen

General Availability (Worldwide): We began rolling out mid-March 2025 and expect to complete by late May 2025.

How this will affect your organization

Mail flow status report:

admin controls

Threat classification breakdown in the Mail flow status report:

admin controls

Threat classification breakdown in the Threat protection status report:

admin controls

As a result of this change, we will introduce Threat classification as a new column in the output of the Get-MailTrafficATPReport Microsoft PowerShell cmdlet:

admin controls

These changes will be available by default.

What you need to do to prepare

This rollout will happen automatically by the specified dates with no admin action required before the rollout. Review your current configuration to determine the impact for your organization. You may want to notify your users about this change and update any relevant documentation.

Learn more

  • View email security reports - Microsoft Defender for Office 365 | Microsoft Learn
    • Mail flow status report
    • Threat protection status report
  • Microsoft Ignite: Redefining email security with LLMs to tackle a new era of social engineering | Microsoft Community Hub

Timeline

Published
Apr 2, 2025
Message published to Message Center
Updated
Apr 2, 2025
Message content updated
End Date
Jul 25, 2025
Message timeline ends

Tags

#Feature update#Admin impact

Category

Stay Informed

Related Messages

Similar updates

MC1042925

Microsoft Defender for Office 365: Enhancing page load performance

Mar 28, 2025
MC1069558

Microsoft Defender: Updates to Export Quarantine Message cmdlet

May 7, 2025
MC1030003

Microsoft Outlook: Disable add-in user reporting buttons now that built-in Report button is GA for all platforms

Mar 12, 2025
MC1042926

Microsoft Defender for Office 365: Platform migration for enhanced data storage and performance

Mar 28, 2025
MC1036568

Updates to App Governance Pre-Defined Policies in Defender for Cloud Apps

Mar 19, 2025