Defender blocks hostile email prompts before Copilot sees them

Microsoft’s updated Defender for Office 365 guidance says Plan 2 can detect prompt-injection content in inbound email before it reaches a mailbox or an AI assistant. Detections use the existing high-confidence-phishing verdict and appear as Prompt injection protection in Defender investigation and reporting tools.
For Copilot adoption leads, the useful distinction is where this control operates. It protects the inbound email path before Copilot or another assistant reads a message; it does not make every file, Teams message or web page safe to ground automatically. That boundary makes adoption guidance more concrete. Teams can let users trial email summarising and triage with a known mail-layer control, while still teaching them to treat prompts, shared content and generated replies as work that needs review.
Analysis
Ask the security owner whether the tenant has Defender for Office 365 Plan 2 and how prompt-injection detections surface in its existing phishing process. Add that answer to the Copilot email-use guidance rather than promising blanket protection.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Copilot adoption needs an email prompt-injection check", Collab365 Spaces.