{"id":59142,"date":"2025-08-07T16:00:00","date_gmt":"2025-08-07T16:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=141655"},"modified":"2025-08-07T16:00:00","modified_gmt":"2025-08-07T16:00:00","slug":"announcing-public-preview-phishing-triage-agent-in-microsoft-defender","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/","title":{"rendered":"Announcing public preview: Phishing triage agent in Microsoft Defender"},"content":{"rendered":"<p><span data-contrast=\"auto\">At Microsoft Secure 2025, we <\/span><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftthreatprotectionblog\/what%E2%80%99s-new-in-microsoft-defender-xdr-at-secure-2025\/4390817\" target=\"_blank\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">introduced<\/span><\/span><\/a><span data-contrast=\"auto\"> a new wave of innovations across Microsoft Defender aimed at redefining what AI can do for security operations. At the center of these announcements was the&nbsp;<\/span><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/SecurityCopilotBlog\/automate-cybersecurity-at-scale-with-microsoft-security-copilot-agents\/4394675\/\" target=\"_blank\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">launch<\/span><span data-ccp-charstyle=\"Hyperlink\">&nbsp;of 11 Security Copilot agents<\/span><\/span><\/a><span data-contrast=\"auto\">, each purpose-built to reduce manual workload and accelerate response through autonomous, adaptive automation. Integrated into existing Microsoft Security infrastructure, they continuously learn and adapt to your unique environment, while keeping your team in control for proactive, end-to-end protection.&nbsp;<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Among these is the Phishing Triage Agent in Microsoft Defender, now available in Public Preview. It tackles one of the most repetitive tasks in the SOC: handling reports of user-submitted phish. Instead of manually combing through endless submission, security teams can now rely on an agent that triages thousands of alerts each day, typically within 15 minutes of detection. Early adopters are already seeing accelerated threat response and significant time savings.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Phishing continues to be one of the most pervasive entry points for threat actors, with over 90% of breaches starting from email-based deception. In just twelve months,&nbsp;<\/span><a href=\"https:\/\/www.microsoft.com\/security\/security-insider\/intelligence-reports\/microsoft-digital-defense-report-2024\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Microsoft Defender for Office 365 detected more than 775 million malware-laced emails<\/span><\/span><\/a><span data-contrast=\"auto\">, underscoring the relentless, large-scale nature of the threat.&nbsp;<\/span><span data-contrast=\"auto\">While today\u2019s security tools are highly effective at blocking most of these attempts, attackers aren\u2019t standing still. They continuously adapt\u2014tweaking content, spoofing identities, changing tactics, and exploiting new channels to slip past defenses. Increasingly, they\u2019re also using generative AI to craft phishing messages that appear more legitimate and personalized, making detection even harder. As a result, a small but dangerous number of phishing emails still manage to slip through and reach users\u2019 inboxes.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">When users report these suspicious messages, they land in SOC queues for further review, creating a&nbsp;significant operational burden for&nbsp;security teams. Most submissions are false alarms, yet&nbsp;analysts must still&nbsp;manually&nbsp;review&nbsp;each one&nbsp;to&nbsp;catch&nbsp;the&nbsp;rare&nbsp;threats buried in the noise.&nbsp;This delays response, drains focus, and raises the risk of a dangerous miss.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The Phishing Triage Agent marks a meaningful step forward in autonomous security operations. Powered by large language models (LLMs), it performs sophisticated assessments\u2014including semantic evaluation of email content, URL and file inspection, and intent detection\u2014to determine whether a submission is a true phishing threat or a false alarm. Unlike traditional systems based on static rules or pre-coded logic, the agent dynamically interprets the context and artifacts of each email to reach an independent verdict. It is autonomous defense working behind the scenes, cutting through the noise and elevating what truly matters.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Equally transformative is the agent\u2019s ability to learn. Rather than relying on fixed conclusions, the Phishing Triage Agent continuously evolves. Analysts can reclassify incidents and provide natural language feedback explaining why a particular verdict was correct or not. The agent incorporates this input, refining its reasoning and adapting to the organization\u2019s specific needs, patterns, and nuances. With every interaction, it becomes more accurate and better attuned to its environment, creating a feedback loop that drives ongoing improvement.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">One of the most&nbsp;defining features&nbsp;of the Phishing Triage Agent<\/span><span data-contrast=\"auto\">&nbsp;<\/span><span data-contrast=\"auto\">is how clearly it communicates its decisions. For every verdict, the agent provides a natural language explanation that outlines why a message was or wasn\u2019t classified as phishing. The rationale is clear and accessible, allowing analysts to quickly comprehend what led to the outcome.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">For those seeking deeper understanding, the agent also produces a visual map of its decision logic: a step-by-step breakdown of how it evaluated the submission. Each phase is presented as an expandable card within a structured diagram, detailing the signals analyzed, evidence collected, and logic applied. Teams can drill into any step to view the agent\u2019s reasoning in context, making the entire process traceable and reviewable from start to finish. This level of transparency isn\u2019t just helpful, it\u2019s essential for building trust in autonomous security systems.&nbsp;<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;335551550&quot;:2,&quot;335551620&quot;:2}\">&nbsp;<\/span><\/p>\n<p><span data-ccp-props=\"{}\">&nbsp;<\/span><span>&nbsp;<\/span><\/p>\n<p> <span class=\"lia-media-object lia-media-is-center\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUlSTVRNSg?image-dimensions=744x434&amp;revision=8\" width=\"744\" height=\"434\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">Getting started is simple. The onboarding experience provides a clear overview of the agent\u2019s capabilities and how it functions in your environment. It can be configured with a dedicated identity and role-based access controls that follow least privilege principles, ensuring it operates strictly within its assigned scope.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Administrators&nbsp;retain&nbsp;full control. They can view, manage, and restrict the agent\u2019s actions,&nbsp;keeping&nbsp;its behavior&nbsp;aligned&nbsp;with the organization\u2019s security policies and standards.&nbsp;<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p> <span class=\"lia-media-object lia-media-is-center lia-media-size-default\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUZpTW5DQQ?image-dimensions=853x480&amp;revision=8\" width=\"853\" height=\"480\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">Once deployed, the agent operates in the background, automatically triggering whenever a user reports a suspicious email. As new submissions come in, it analyzes each one and assigns a classification. In most organizations, more than 90% of reported emails turn out to be false positives. The agent resolves these automatically, tagging them so analysts don\u2019t have to sort through each one manually.<\/span><span data-contrast=\"auto\">&nbsp;<\/span><span data-contrast=\"auto\">This allows teams to focus on the handful of incidents that truly require their attention. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">When the agent is enabled,&nbsp;Microsoft Defender for Office&nbsp;365\u2019s built-in&nbsp;<\/span><a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/air-about\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Automat<\/span><span data-ccp-charstyle=\"Hyperlink\">ed Investigation and Response (AIR)<\/span><\/span><\/a><span data-contrast=\"auto\">&nbsp;feature consumes the agent\u2019s output. AIR then builds on that analysis,&nbsp;detecting similar threats and surfacing remediation actions for SOC analysts to review and approve.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p> <span class=\"lia-media-object lia-media-is-center\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLWh5c0pORQ?image-dimensions=745x472&amp;revision=8\" width=\"745\" height=\"472\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">For each incident, the agent provides a natural language summary of its verdict. When it classifies a submission as malicious or benign, it clearly explains why\u2014citing factors such as sender reputation, message content, attachment behavior, and more. <\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span class=\"lia-media-object lia-media-is-center\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLU5SSW9QUg?image-dimensions=744x418&amp;revision=8\" width=\"744\" height=\"418\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">The Activity tab displays a flow diagram that shows how the agent arrived at its decision, including all intermediate steps and outcomes. This behind-the-scenes process covers everything from text and URL analysis to sandbox evaluation of attachments. And it all happens autonomously, without human intervention or scripting.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p> <span class=\"lia-media-object lia-media-is-center lia-media-size-default\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUtaTXloMw?image-dimensions=999x562&amp;revision=8\" width=\"999\" height=\"562\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">If an analyst disagrees with the agent\u2019s verdict, they can simply reclassify the submission and leave feedback in natural language. No special syntax or training is required. The agent learns from this input and uses it to refine future decisions, continuously improving its accuracy and alignment. Over time, the agent becomes a true extension of the team. It not only reduces manual effort but also adapts to the organization\u2019s unique environment and the evolving threat landscape it defends against.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p> <span class=\"lia-media-object lia-media-is-center lia-media-size-default\" data-image-alt><button class=\"lia-media-unstyled-btn\" type=\"button\" aria-haspopup=\"true\" aria-label=\"Enlarge Image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUZudVlDTQ?image-dimensions=999x562&amp;revision=8\" width=\"999\" height=\"562\" alt><\/button><\/span><\/p>\n<p><span data-contrast=\"auto\">The agent\u2019s performance is tracked in a dedicated dashboard that gives analysts real-time visibility into its impact. It displays the number of incidents handled, mean time to triage (MTTT), and a breakdown of false positives versus true positives over time. This always-on view helps security teams quantify efficiency gains, monitor accuracy, and build confidence in the agent\u2019s ongoing performance.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The Phishing Triage Agent, like all Microsoft Security Copilot&nbsp;agents, adheres to Microsoft\u2019s&nbsp;<\/span><a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/rai-faqs-security-copilot-agents\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Responsible AI<\/span><\/span><\/a><span data-contrast=\"auto\">&nbsp;principles. This includes built-in guardrails for fairness, transparency, security, privacy, and accountability.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Administrators configure the agent\u2019s identity and permissions based on&nbsp;least privilege&nbsp;access,&nbsp;maintaining&nbsp;strict control over what data it can access, how much&nbsp;capacity&nbsp;it consumes, and which actions it&nbsp;is authorized to&nbsp;take. Operating within a&nbsp;<\/span><a href=\"https:\/\/www.microsoft.com\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Z<\/span><span data-ccp-charstyle=\"Hyperlink\">ero<\/span><span data-ccp-charstyle=\"Hyperlink\">&nbsp;<\/span><span data-ccp-charstyle=\"Hyperlink\">T<\/span><span data-ccp-charstyle=\"Hyperlink\">rust<\/span><\/span><\/a><span data-contrast=\"auto\"> framework, the agent\u2019s every action is evaluated against organizational policies before execution. This approach ensures that AI-powered capabilities enhance the SOC without compromising enterprise trust, compliance, or control.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The Phishing Triage Agent is the first in a new generation of agents designed to bring autonomous intelligence to security operations. By eliminating repetitive, reactive tasks and continuously learning from feedback, it allows teams to focus on what matters most\u2014investigating real threats and strengthening their overall security posture. This marks a leap forward into a more efficient, adaptive era for the SOC.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Organizations that meet the&nbsp;<\/span><a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/phishing-triage-agent#prerequisites\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">prerequisites<\/span><\/span><\/a><span data-contrast=\"auto\">&nbsp;can now&nbsp;get started&nbsp;by&nbsp;joining&nbsp;the&nbsp;Phishing Triage Agent&nbsp;Public Preview,&nbsp;available&nbsp;through a trial&nbsp;directly in&nbsp;the&nbsp;Microsoft Defender&nbsp;portal.&nbsp;To learn more,&nbsp;visit&nbsp;the&nbsp;<\/span><a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/phishing-triage-agent\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">product page<\/span><\/span><\/a><span data-contrast=\"auto\">&nbsp;for&nbsp;details on how it works, and&nbsp;the&nbsp;<\/span><a href=\"https:\/\/adoption.microsoft.com\/security-copilot\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span data-contrast=\"none\"><span data-ccp-charstyle=\"Hyperlink\">Adoption Hub<\/span><\/span><\/a><span data-contrast=\"auto\">&nbsp;for&nbsp;broader&nbsp;guidance&nbsp;on&nbsp;Security Copilot agents.<\/span><span data-ccp-props=\"{}\">&nbsp;<\/span><\/p>\n<p><span data-ccp-props=\"{}\">Looking to improve response times and support your team more effectively? <a class=\"lia-external-url\" href=\"https:\/\/info.microsoft.com\/ww-landing-what-generative-ai-can-do-for-your-soc.html\" target=\"_blank\" rel=\"noopener noreferrer\">Sign up to access \u201cWhat generative AI can do for your SOC\u201d today<\/a> or read more about <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\/ai-powered-unified-secops-defender\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft AI-powered unified security operations<\/a>.<\/span><\/p>\n<p>READ MORE <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/microsoftthreatprotectionblog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/4438301\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Phishing Triage Agent in Microsoft Defender is now available in Public Preview. It tackles one of the most repetitive tasks in the SOC: handling reports of user-submitted phish.<br \/>\nThe post Announcing public preview: Phishing triage agent in Microsoft Defender appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":59143,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[],"class_list":["post-59142","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-07T16:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUlSTVRNSg?image-dimensions=744x434&amp;revision=8\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Announcing public preview: Phishing triage agent in Microsoft Defender\",\"datePublished\":\"2025-08-07T16:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/\"},\"wordCount\":1416,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png\",\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/\",\"name\":\"Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png\",\"datePublished\":\"2025-08-07T16:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png\",\"width\":744,\"height\":434},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Announcing public preview: Phishing triage agent in Microsoft Defender\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/","og_locale":"en_US","og_type":"article","og_title":"Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-08-07T16:00:00+00:00","og_image":[{"url":"https:\/\/techcommunity.microsoft.com\/t5\/s\/gxcuf89792\/images\/bS00NDM4MzAxLUlSTVRNSg?image-dimensions=744x434&amp;revision=8","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Announcing public preview: Phishing triage agent in Microsoft Defender","datePublished":"2025-08-07T16:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/"},"wordCount":1416,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png","articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/","url":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/","name":"Announcing public preview: Phishing triage agent in Microsoft Defender 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png","datePublished":"2025-08-07T16:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender.png","width":744,"height":434},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/announcing-public-preview-phishing-triage-agent-in-microsoft-defender\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Announcing public preview: Phishing triage agent in Microsoft Defender"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=59142"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59142\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/59143"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=59142"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=59142"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=59142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}