Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC696850

Microsoft Defender for Office 365 enable admins to provide intent while submitting

Informational

Message ID

MC696850
View in Admin Center

Roadmap ID

183907
View in Roadmap

Services

Exchange Online
Microsoft Defender XDR

Affected Platforms

Web

Summary

Microsoft Defender for Office 365 will allow admins to provide intent when submitting messages, attachments, or URLs. This will streamline Microsoft's analysis and result in more accurate analysis. The change will start rolling out in mid-February 2024 and should be complete by late March 2024. This feature will not impact any existing submissions, filtering, or grouping functionality in submissions. End user reporting and admin submission of Teams messages is available only in Microsoft Defender for Office plan 2.

Details

Updated February 25, 2024: We have updated the rollout timeline below. Thank you for your patience.

This applies to customers with Exchange Online Protection, Microsoft Defender for Office plan 1 or plan 2 service plans.

Soon, admins can provide intent when submitting messages (email and Microsoft Teams), email attachments, or URLs to Microsoft.

Admins can convey whether they are submitting for a second opinion from Microsoft or they are submitting because a true malicious message was missed by Microsoft. With this change, Microsoft analysis of admin submitted messages (email and Microsoft Teams), URLs, and email attachments will be further streamlined and will result in more accurate analysis.




This message is associated with Microsoft 365 Roadmap ID 183907

When this will happen:

This change will start rolling out in mid-February 2024 (previously mid-December) and should be complete by late March 2024 (previously late February).

How this will affect your organization:

You will see this experience when you start making new admin submissions from Submissions, Threat Explorer, or Quarantine.

What you need to do to prepare:

This new feature will not impact any existing submissions, filtering, or grouping functionality in submissions.

Note: Today, end user reporting and admin submission of Teams messages is available only in Microsoft Defender for Office plan 2.

Timeline

📅
Published
Dec 8, 2023
Message published to Message Center
✏️
Updated
Feb 26, 2024
Message content updated
🏁
End Date
May 6, 2024
Message timeline ends

Tags

#Updated message#New feature#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC889519

Microsoft Defender for Office 365: Tenant Allow/Block List will support IPv6 allow and block entries

Sep 13, 2024
MC794542

Microsoft Defender for Office 365: Tenant Allow/Block List will support blocking top-level domains and subdomains

May 20, 2024
MC765804

Microsoft Defender for Office 365: Adding last used dates to Tenant Allow/Block Lists

Apr 2, 2024
MC711335

Microsoft Defender for Office 365: Quarantine End User Allow and Block list management

Jan 30, 2024
MC1096885

Mail Bombing Detection technology in Microsoft Defender for Office 365

Jun 17, 2025