Microsoft · Microsoft Defender for Office 365

Threat Classification

Microsoft documents a threat classification system in Defender for Office 365 that uses large language models, small language models and machine learning models to automatically categorise email-based threats by intent and attack nature. The record covers classification only, not the separate protection mechanisms that act on a verdict.

Recorded characteristics

Function
Microsoft documents that the threat classification system automatically detects and classifies email-based threats. Documentation separates threat types (broad categories such as phishing, malware and spam), threat detections (technologies that identify indicators, such as spoof, impersonation and URL reputation) and threat classification itself, described as categorising a threat based on intent and the specific nature of the attack. Documented threat classes include advance fee scam, adware, business intelligence, contact establishment, downloader, gift cards, HackTool, invoice fraud, payroll fraud, PII gathering, ransom, remote access trojan, spyware and task fraud. Microsoft states that new classifications are added as attack methods evolve. Classification results are surfaced in Threat Explorer, Incidents and alerts, Advanced hunting, the Threat protection status report and the Mailflow status report.
Data access
Microsoft documents classification of email messages and communications. Detection technology documentation establishes analysis of message content by purpose-built large language models ("LLM content analysis"), machine learning models for phishing and spam, sender and domain information, domain and IP reputation, URL reputation, file and attachment reputation and detonation results, campaign and fingerprint signals, and mailbox intelligence sender maps. Microsoft's documentation for this capability does not establish access to tenant data beyond email and its associated security signals.
Actions
None
External actions
Unknown
Human confirmation
Not established
Permission basis
Not established
Administrative control
Microsoft documents anti-phishing policies as the configuration surface for phishing protection, including customisable phishing email thresholds to fine-tune detection and AI and machine learning-based detection, with a default anti-phishing policy applying to all recipients and optional custom policies. Microsoft also documents admin submissions to report incorrect verdicts to Microsoft for analysis, with Tenant Allow/Block List entries acting as a temporary override signal to the filters. Microsoft's classification documentation itself does not describe any setting that turns classification on or off or that selects classification models.
Default state
Not established
Availability
Microsoft states that threat classification applies to Microsoft Defender for Office 365 Plan 1 and Plan 2 and to Microsoft Defender XDR. Microsoft documents a wider protection ladder in which all organisations with cloud mailboxes have built-in security features, with Defender for Office 365 Plan 1 and Plan 2 adding further protection; the classification page's stated applicability is to the Defender plans and Defender XDR rather than to every Microsoft 365 customer.
Licensing
Documented as applying to Microsoft Defender for Office 365 Plan 1, Microsoft Defender for Office 365 Plan 2 and Microsoft Defender XDR.
External model or provider
Microsoft-operated classification technology. Microsoft names the technology categories used — large language models, small language models and machine learning models — and refers to purpose-built large language models for content analysis, but does not publicly identify the specific underlying models for this capability.
Limitations and uncertainty
The specific underlying models are not publicly identified. No runtime identity or permission mechanism is established for the classification operation itself. Classification and enforcement are separate concepts: Microsoft documents classification as producing a categorisation surfaced in reporting and hunting experiences, while blocking, quarantine, remediation and delivery decisions are documented as separate Defender mechanisms. The set of threat classes is stated to expand over time. Microsoft documents admin submission and Tenant Allow/Block List processes for incorrect verdicts, indicating that incorrect classifications can occur.

Evidence