MICROSOFT’S latest quarterly email-security benchmark, covering May to July 2026, found that Defender missed 221 high-severity threats per 1,000 protected users. Microsoft said this was 55.4% fewer than the next-closest secure email gateway (SEG) vendor. The comparison measures missed threats rather than total catches, which Microsoft said provides a fairer comparison because vendors may face different threat volumes and levels of exposure.
It also noted that missed threats have risen across several reporting periods, including for Microsoft, as attackers use AI to gather public information, tailor messages and create more convincing impersonation attempts.
The benchmark found that integrated cloud email security (ICES) products provided their largest additional benefit in promotional and bulk-mail filtering. ICES malicious catch rose to 0.30%, from 0.13% in the previous quarter, while spam catch increased to 0.52%, from 0.28%. Defender caught 92% of post-delivery malicious messages on average during the period.
Microsoft said its system continuously reevaluates messages already in inboxes, using new threat intelligence, campaign information and other signals to identify and remediate risks that were not apparent when messages were delivered.
Microsoft linked the findings to product changes including Outlook’s Promotions folder, a redesigned machine-learning and AI model stack, and prompt-injection protection intended to isolate malicious instructions in emails before delivery.
It said research during a consecutive four-week period recorded roughly two-thirds fewer false negatives and nearly one-fifth fewer false positives for Defender customers, although these figures were presented as Microsoft research observations rather than independent benchmark results.