Threat Classification
Microsoft documents a threat classification system in Defender for Office 365 that uses large language models, small language models and machine learning models to automatically categorise email-based threats by intent and attack nature. The record covers classification only, not the separate protection mechanisms that act on a verdict.
Recorded characteristics
- Function
- Microsoft documents that the threat classification system automatically detects and classifies email-based threats. Documentation separates threat types (broad categories such as phishing, malware and spam), threat detections (technologies that identify indicators, such as spoof, impersonation and URL reputation) and threat classification itself, described as categorising a threat based on intent and the specific nature of the attack. Documented threat classes include advance fee scam, adware, business intelligence, contact establishment, downloader, gift cards, HackTool, invoice fraud, payroll fraud, PII gathering, ransom, remote access trojan, spyware and task fraud. Microsoft states that new classifications are added as attack methods evolve. Classification results are surfaced in Threat Explorer, Incidents and alerts, Advanced hunting, the Threat protection status report and the Mailflow status report.
- Data access
- Microsoft documents classification of email messages and communications. Detection technology documentation establishes analysis of message content by purpose-built large language models ("LLM content analysis"), machine learning models for phishing and spam, sender and domain information, domain and IP reputation, URL reputation, file and attachment reputation and detonation results, campaign and fingerprint signals, and mailbox intelligence sender maps. Microsoft's documentation for this capability does not establish access to tenant data beyond email and its associated security signals.
- Actions
- None
- External actions
- Unknown
- Human confirmation
- Not established
- Permission basis
- Not established
- Administrative control
- Microsoft documents anti-phishing policies as the configuration surface for phishing protection, including customisable phishing email thresholds to fine-tune detection and AI and machine learning-based detection, with a default anti-phishing policy applying to all recipients and optional custom policies. Microsoft also documents admin submissions to report incorrect verdicts to Microsoft for analysis, with Tenant Allow/Block List entries acting as a temporary override signal to the filters. Microsoft's classification documentation itself does not describe any setting that turns classification on or off or that selects classification models.
- Default state
- Not established
- Availability
- Microsoft states that threat classification applies to Microsoft Defender for Office 365 Plan 1 and Plan 2 and to Microsoft Defender XDR. Microsoft documents a wider protection ladder in which all organisations with cloud mailboxes have built-in security features, with Defender for Office 365 Plan 1 and Plan 2 adding further protection; the classification page's stated applicability is to the Defender plans and Defender XDR rather than to every Microsoft 365 customer.
- Licensing
- Documented as applying to Microsoft Defender for Office 365 Plan 1, Microsoft Defender for Office 365 Plan 2 and Microsoft Defender XDR.
- External model or provider
- Microsoft-operated classification technology. Microsoft names the technology categories used — large language models, small language models and machine learning models — and refers to purpose-built large language models for content analysis, but does not publicly identify the specific underlying models for this capability.
- Limitations and uncertainty
- The specific underlying models are not publicly identified. No runtime identity or permission mechanism is established for the classification operation itself. Classification and enforcement are separate concepts: Microsoft documents classification as producing a categorisation surfaced in reporting and hunting experiences, while blocking, quarantine, remediation and delivery decisions are documented as separate Defender mechanisms. The set of threat classes is stated to expand over time. Microsoft documents admin submission and Tenant Allow/Block List processes for incorrect verdicts, indicating that incorrect classifications can occur.
Evidence
- Threat classification in Microsoft Defender for Office 365
Supports: Function · General · External model · Actions · Data access · Availability · Licensing · Limitations · Human confirmation · Permission basis · Default state · Primary source
The threat classification system automatically detects and classifies email-based threats, categorising a threat based on intent and the specific nature of the attack.
Microsoft distinguishes threat types, threat detections and threat classification as separate concepts.
Microsoft states the system uses large language models, small language models and machine learning models.
The documented output is a classification surfaced in Threat Explorer, Incidents and alerts, Advanced hunting and reports; no state-changing operation is attributed to classification.
Classification is documented as applying to email messages and communications.
Applies to Microsoft Defender for Office 365 Plan 1 and Plan 2 and Microsoft Defender XDR.
Applicability is stated by Defender plan rather than to all Microsoft 365 customers.
New threat classifications are expected as attack methods emerge.
Classification is described as automatic; no confirmation step is documented for any action, because no action is documented.
No runtime identity or permission mechanism is described for the classification operation.
No operational default (enabled or disabled) is stated for the classification mechanism.
- Understand detection technology within the email entity page in Microsoft Defender for Office 365
Supports: Data access · External model · Actions · Limitations · Primary source
Detection technologies analyse message content, sender and domain information, URLs, attachments, IP and domain reputation, and campaign and fingerprint signals.
LLM content analysis is described as analysis by Microsoft's purpose-built large language models; the advanced filter uses machine learning models for phishing and spam.
Detection technologies are described as producing a threat verdict shown on the email entity page.
False positives are addressed through admin submission and a temporary Tenant Allow/Block List override signal.
- Anti-phishing policies in Microsoft 365
Supports: Admin controls · Default state · Primary source
Anti-phishing policies provide customisable phishing email thresholds to fine-tune detection, alongside AI and machine learning-based detection.
A default anti-phishing policy applies to all recipients, with optional custom policies; this concerns policy scope, not classification activation.
- Submit messages, URLs, and attachments for analysis in the Microsoft Defender portal
Supports: Limitations · Admin controls · Primary source
Microsoft documents submitting messages, URLs and attachments for analysis when a verdict appears incorrect.
Admin submissions are the documented route to have Microsoft review a verdict.
- Microsoft Defender for Office 365 overview
Supports: Availability · Licensing · Primary source
All cloud mailboxes include built-in security features; Defender for Office 365 Plan 1 and Plan 2 add further protection.
Defender for Office 365 is licensed in Plan 1 and Plan 2 tiers above built-in protection.