Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1098943

Microsoft Defender for Office 365: AI-powered submissions response for improved result explainability

Informational

Message ID

MC1098943
View in Admin Center

Roadmap ID

488098
View in Roadmap

Services

Microsoft Defender XDR

Affected Platforms

Web

Summary

Microsoft Defender for Office 365 is introducing AI-powered explanations for email submission results, enhancing clarity on why messages are classified as spam, phishing, or clean. This feature will roll out globally from late June to mid-July 2025 and is available by default. No admin action is required.

Details

We’re introducing a new AI-powered capability in Microsoft Defender for Office 365 that enhances the explainability of email submission results. This feature uses large language models (LLMs) to generate clear, human-readable rationales for why a submitted message was classified as spam, phishing, or clean.

This message is associated with Microsoft 365 Roadmap ID 488098.

When this will happen:

General Availability (Worldwide): We will begin rolling out late June 2025 and expect to complete by mid-July 2025.

How this will affect your organization:

This feature applies only to email submissions in the Microsoft Defender portal and does not include files, Teams messages, URLs, or user-submitted content at this time. This feature is available by default.

To view the new explanations:

  1. Go to https://security.microsoft.com
  2. Navigate to Actions & Submissions > Submissions or directly to https://security.microsoft.com/reportsubmission
  3. Select the Emails tab and open a submission
  4. In the Result Details section, you’ll see an AI-generated explanation (when available)

These AI-generated explanations may include:

  • The reasoning behind the classification
  • Key indicators used in the decision
  • Optional behavioral insights

If the AI explanation is unavailable, the system will revert to the standard explanation.

Table: Supported result types with LLM explanations:

Result Type Description
Unknown Microsoft could not reach a decision. May be due to inaccessible content or analyst disagreement.
Bulk Sender classified as bulk. Future similar items may be blocked based on BCL.
Spam Classified as spam. Future similar items may be blocked based on SCL.
No threats found Item found clean. Filters may be updated.
Threats found Item found malicious. Filters may be updated.

Screenshot: AI-generated explanation for email submission results in Microsoft Defender portal:

admin controls

What you need to do to prepare:

This rollout will happen automatically by the specified dates with no admin action required before the rollout. Review submission workflows to take advantage of the new explanations. You may want to notify your admins and/or users about this change and update internal documentation.

Learn more: Submission result definitions - Microsoft Defender for Office 365 | Microsoft Learn

Timeline

📅
Published
Jun 19, 2025
Message published to Message Center
✏️
Updated
Jun 19, 2025
Message content updated
🏁
End Date
Sep 15, 2025
Message timeline ends

Tags

#New feature#User impact#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC1091443

Microsoft Defender XDR: Scoped access for Defender for Identity (preview)

Jun 10, 2025
MC1088729

Microsoft Defender for Office 365: Two new data tables in Advanced hunting (preview)

Jun 5, 2025
MC1133508

Microsoft Teams Integration with Microsoft Defender for Office Tenant Allow/Block List for blocking domains

Aug 11, 2025
MC1147984

Microsoft Teams: User reporting for incorrectly identified security concerns

Sep 4, 2025
MC1223828

Microsoft Teams: Report a suspicious call

Jan 29, 2026