Microsoft adds email prompt injection protection to Defender

Microsoft says a preview feature in Defender identifies and isolates emails containing malicious instructions intended for AI systems before delivery. The July 30 security update positions it as protection against prompt-injection content reaching the inbox.
Email has long been treated as a phishing and malware channel, while AI assistants add a new failure mode: untrusted text can be framed as an instruction for a system that is summarising or acting on mail. Controls designed only around links and attachments do not address that distinction. This preview puts a guardrail earlier in the path, before the message reaches a user or an AI workflow. Administrators still need to validate its coverage and false-positive behaviour, but it makes prompt injection a practical mail-security category rather than an abstract AI concern.
Analysis
Add “prompt injection in email” to your next Defender review and identify one mailbox workflow where Copilot or another AI tool processes external messages.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Microsoft adds email prompt injection protection to Defender", Collab365 Spaces.