M365 Change Tracker

← All changes · defender

Update

The Phishing Triage Agent and Security Alert Triage Agent now use the more limited Email & collaboration content: Emails associated with alerts (read) permission instead of the broader Email & Collaboration content: All Emails (read) permission.

The Phishing Triage Agent and Security Alert Triage Agent now use the more limited Email & collaboration content: Emails associated with alerts (read) permission instead of the broader Email & Collaboration content: All Emails (read) permission. This least-privilege permission restricts agent access to only email content associated with alerts, improving the security posture of your agent configuration.

Source last updated 2026-06-01

Affected: Microsoft Defender XDR

Related changes

View at Microsoft →