Microsoft published the results of its latest quarterly email security comparison, saying that Microsoft Defender missed the fewest high-severity threats among the solutions evaluated during the period from May to July 2026. According to the company’s figures, the number of missed threats was 221 per 1,000 protected users, which was 55.4% lower than that of the nearest competitor among secure email gateway (SEG) providers.
The comparison is based on measuring threats that were not detected, rather than counting the total number of malicious messages intercepted. Microsoft justifies this approach by saying that the number of messages captured can be affected by differences in threat volume and exposure levels across each provider’s environments. Standardizing the measurement per 1,000 users is intended to provide a more consistent comparison between solutions, according to the company.
What Do the Results Actually Measure?
The material is not limited to preventing a message before it reaches the inbox. Microsoft’s comparison also includes integrated cloud email security (ICES) solutions, which combine pre-delivery filtering with post-delivery detection and remediation. The company says Defender detected an average of 92% of malicious messages after delivery during the measurement period.
ICES results indicate that the greatest added value of multilayered protection appeared in filtering promotional messages and bulk-sent messages. The malicious-message capture rate among ICES providers also rose to 0.30%, compared with 0.13% in the previous quarter, while the spam capture rate rose to 0.52%, compared with 0.28%.
Microsoft explains that post-delivery remediation is not a one-time action performed after a message reaches the user. According to the company’s description, Defender reevaluates messages in mailboxes when new threat intelligence, risk indicators, or information related to an attack campaign emerges, and then remediates messages whose risk becomes clear later.
Why Does This News Matter?
The importance of these figures lies in shifting email security evaluation from the question “How many messages were blocked?” to a more precise question: “How many high-severity threats reached the user or remained undetected?” However, the comparison remains tied to the scope of the solutions selected by Microsoft and the measurement methodology presented in the material, so the figures alone are not sufficient to judge every organization’s experience or every type of message.
Microsoft says missed threats increased across multiple measurement periods, including for Defender. The company believes this is consistent with attackers’ use of artificial intelligence to gather public information, customize messages, and craft more convincing impersonation attempts. This observation does not mean that artificial intelligence explains every failure, but it highlights the need for defenses that adapt to new signals rather than relying solely on fixed rules.
How Did the Results Affect Defender?
Microsoft links the measurement results to some of its recent investments in Defender. It added the Promotions folder in Outlook based on the observation that ICES solutions deliver substantial benefits in filtering promotional and bulk messages, while keeping legitimate marketing messages available to users instead of mixing them with malicious or unwanted messages.
The company also redesigned its machine-learning and artificial-intelligence model stack, incorporating natural-language-processing signals, including the subject line, alongside other detection signals. Microsoft says a measurement conducted by its research teams over four consecutive weeks showed an approximately two-thirds reduction in missed-threat detection failures and an approximately one-fifth reduction in false positives among Defender customers. These percentages are presented as the result of monitoring conducted by Microsoft, and the material provided no independent details about the test group or comparison design.
Protecting Users and Systems That Read Email
The latest addition goes beyond human users. Microsoft says it developed protection against prompt injection to detect and isolate malicious instructions directed at artificial-intelligence systems before delivery. The company links this protection to the spread of Copilot, agents, and other systems that may read inbox content and take action based on it.
In practice, this expands the scope of email security from preventing phishing or malware to examining instructions that could exploit an intelligent system handling messages. However, the material provides no technical details about the isolation mechanism or prompt-injection attack detection rates, leaving open questions about how this protection would be evaluated outside Microsoft’s tests.
Editorial Conclusion
The comparison provides an important indication that email security is no longer merely a pre-delivery prevention layer. The results presented by Microsoft place continuous post-delivery remediation, multilayered filtering, and model improvements among the essential elements of protection. At the same time, the figures should be read as benchmark results published by the company itself, not as a comprehensive independent certification of Defender’s performance in all environments. The clearest value for organizations lies in the methodology: monitoring messages after delivery, measuring missed threats per user, and reviewing the system’s ability to adapt to rapidly changing impersonation campaigns.