top of page

Microsoft's Own Numbers: 221 Missed Threats per 1,000 Users, and a Triage Agent Most Small Businesses Cannot Use

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
15 hours ago
7 min read

On September 17, 2026, Microsoft published its latest email security benchmark. By Microsoft's own count, Microsoft Defender for Office 365 missed 221 high-severity threats per 1,000 protected users between May and July 2026, up from 171 in the November 2025 to January 2026 period two benchmarks earlier; Microsoft says misses have risen across multiple reporting periods, including its own. Microsoft's yardstick is a threat not detected before delivery, and in its 2025 methodology post it said it held Defender to a stricter version of that standard, counting a threat as missed even if Defender removed it afterward. Microsoft also says that is about 55% fewer misses than the next closest secure email gateway vendor, and we take Microsoft at its word. Best of the group still means 221. Microsoft also reports that Defender removed 92% of malicious mail found in the inbox during the period, which is why its stricter counting rule matters when you read 221. For an organization of 50 people, that is roughly 11 high-severity emails in a quarter that were delivered before detection, whether or not a later cleanup pulled them back, before anyone talks about the ordinary phishing that does not rate "high severity."

This post is about what Microsoft is doing about that number, what it costs, who can use it, and why we think a small business is better served by a different approach. Where we state a fact, it comes from the sources linked at the end, most of them Microsoft's own pages. Where we give an opinion, we label it.

The dial that does not fix it

If you run Microsoft 365, the setting Microsoft's own tuning guidance points you to is the phishing email threshold in the anti-phishing policy. It has four levels, from Standard to Most aggressive, and Microsoft's documentation describes the tradeoff in one sentence: "The chance of false positives (good messages marked as bad) increases as you increase this setting." The same documentation, on the page about tuning anti-phishing protection, says that "some phishing messages can still be delivered to mailboxes in your organization," and asks you to have users report them with the Outlook button so the reports can help train Microsoft's detection.

That tradeoff went wrong publicly twice this year. Between February 5 and 12, 2026, Microsoft's incident EX1227432 quarantined legitimate email and pulled Teams messages across Exchange Online and Teams; Microsoft's own explanation, as reported by BleepingComputer, was "a logic error in a heuristic detection aimed at novel credential phishing campaigns." In early September 2026, incident MO1465962 had Safe Links blocking legitimate Google search URLs as malicious. Those two were Microsoft-side errors, not customer settings, and Microsoft fixed both; detection engineering is hard. But they show what the false-positive side of the tradeoff looks like: quarantined invoices and blocked links from your own vendors. Turning the dial up moves you toward that side, and the 221 figure, drawn from Microsoft's real-world telemetry rather than a lab test, does not go to zero.

The agent, and who can actually use it

One of Microsoft's answers to the mail that gets through is the Phishing Triage Agent, one of the Security Copilot agents in Microsoft Defender, in public preview since July 2025 and now listed by Microsoft as generally available for the phishing alert type, while the same agent's extension to identity and cloud alerts is still in preview. Here is what it does, in Microsoft's words: it "helps security teams scale the triage and classification of user-reported phishing emails." For phishing, it works on one alert type, "Email reported by user as malware or phish," and it uses a large language model to classify each report as a real threat or a false positive, resolving the false positives on its own.

Read that again from a small business owner's chair. The agent starts after the email reached the inbox, after a person noticed something was wrong, and after that person clicked Report. It does not stop the message. It sorts the pile of reports. And Microsoft's own research on the agent, posted in November 2025, says why the pile needs sorting: in a random sample from live operations, only 11.88% of user-reported submissions were malicious. Most of what the agent triages is not malicious; it is the noise that comes with asking people to report anything that looks off.

Then there is the question of who gets it. Per Microsoft Learn, the agent requires Microsoft Defender for Office 365 Plan 2 and Security Copilot with provisioned capacity in Security Compute Units, and "the agent automatically starts consuming SCUs provisioned for the workspace when the trial period ends." Since November 18, 2025, Microsoft has been rolling Security Copilot into Microsoft 365 E5 and E7: 400 SCUs a month for each 1,000 paid user licenses, capped at 10,000, at no added cost. Other customers provision SCUs on their own, at a list price of $4 per provisioned SCU per hour, billed monthly, with overage at $6 per SCU. Microsoft 365 Business Premium, one of the plans Microsoft says is aimed at small and medium businesses, includes Defender for Office 365 Plan 1, not Plan 2. So for the typical 10 to 100 person company, the agent is not included; getting it means adding Defender for Office 365 Plan 2 licenses and buying Security Copilot capacity on top, for a product built for a security operations center.

Our opinion, labeled as such: we would rather see that engineering effort go into catching the message before delivery, where a miss becomes a wire transfer, than into an agent that processes the reports afterward. The agent is built for a security operations team with analysts to relieve. The small and medium businesses we talk to do not have one analyst. They have an office manager who is also the Microsoft 365 admin.

What we do instead: prevention first

Our Managed Email Security runs on Check Point Email Security, connected to Microsoft 365 or Google Workspace through the API, with no change to your MX records. Two things matter about how it sits in your mail flow.

First, it runs after Microsoft's filter, not instead of it. Microsoft says this itself in its 2025 transparency post: integrated cloud email security products "execute after Microsoft Defender for Office 365 and act as a secondary filter." Check Point's documentation describes the same sequence from its side: Microsoft finds an email clean and intends to deliver it, Check Point scans it, finds it malicious, and quarantines it. You keep what Microsoft catches. We work on what it did not.

Second, we run it in the mode Check Point calls Prevent (Inline), which per Check Point "scans the emails prior to delivery to the user." Before delivery, not after a report. That is the whole point. Where a specific mail flow needs it, we use Detect and Remediate, which scans after delivery and pulls the message out, but the default is to stop it first.

And then a person does the work the platform cannot. We tune the policy for your organization instead of turning a global dial; we run the quarantine, restore the false positives, and adjust the block and allow lists as your vendors change; we investigate what staff report; and when Check Point ships a new protection, we test it and turn it on. That is what "fully managed" means on our services page, and it is the part a license tier does not include.

The number Microsoft would point you to, and why we still say measure

The same Microsoft benchmark reports that adding an integrated cloud email security layer improves malicious catch by an average of 0.30% (up from 0.13% the prior quarter), with the bigger gains in promotional and bulk filtering, and Microsoft's benchmarking page breaks that out for seven named vendors. Check Point is on the list: 0.07% added malicious catch, 3.08% added promotional filtering, and 0.09% non-malicious detections, which is the closest thing on the page to a false-positive figure, and low is what you want there. We are not going to pretend that page does not exist. We will say what it is: a Microsoft-run analysis of Microsoft's telemetry, and it does not say what those percentages are a share of, how they map to the 221 missed threats per 1,000 users, or anything about your tenant. We do not ask you to trust that page, or any vendor's marketing numbers, ours included.

Measure it. Our free two-week email security assessment connects the platform in Monitor only mode, which per Check Point "provides visibility" without inline enforcement; your current filter keeps doing its job and the platform reports what it sees. We quarantine nothing during the assessment. Each business day we go through what it flagged against what Microsoft delivered, separate the real threats from the false positives, and at the end you get a written report and a walkthrough with your own examples. If nothing got through, you will see that too, and you will have lost two weeks of our time, not yours.

Why it is worth two weeks

The FBI's Internet Crime Complaint Center counted 24,768 business email compromise complaints in 2025 with $3.05 billion in reported losses, and 191,561 phishing and spoofing complaints. Those are the messages that got through somebody's filter. The question for your organization is not whether Microsoft is good at this; by its own benchmark it is the best of the group it measured. The question is what the 221 looks like in your inboxes, and whether you want a person and a second layer working on it before delivery or an agent sorting reports after.

The year-end offer

Managed Email Security is $8 per user per month, license plus fully managed service. Through December 31, 2026, new customers who sign a 12-month agreement get 20% off, which is $6.40 per user per month; registered 501(c)(3) nonprofits get 30% instead, $5.60. New customers only, no onboarding fee, and a written SaaS security posture report on your tenant within your first 90 days at no charge. Full terms are in the year-end offer post, and the service is described on our services page.

We work with small and medium businesses and nonprofits nationwide, including Washington DC, Northern Virginia, and Maryland. Run the assessment first, look at your own numbers, and then decide whether the offer is worth taking. To start, book a free 15-minute call.

Sources: Microsoft Security blog, "Improving email security outcomes with real-world Microsoft Defender insights" (Sept 17, 2026) and "Transparency on Microsoft Defender for Office 365 email security effectiveness" (Jul 17, 2025); Microsoft Defender for Office 365 performance benchmarking page (Sept 2026); Microsoft Learn: Anti-phishing policies in Microsoft 365 (Aug 2026), Tune anti-phishing protection (Jul 2026), Phishing Triage Agent and Security Alert Triage Agent in Microsoft Defender (Jul 2026), Microsoft Security Copilot inclusion model (Jun 2026), Defender for Office 365 service description (Jul 2026); Microsoft Security Copilot pricing page; James Bono (Microsoft), "Randomized Controlled Trials for Phishing Triage Agent" (arXiv 2511.13860, Nov 2025); BleepingComputer reporting on Microsoft incidents EX1227432 (Feb 2026) and MO1465962 (Sept 2026); Check Point Email Security administration guide (Email Protection modes, Microsoft Defender visibility and enforcement flow) and solution brief; FBI IC3 2025 Internet Crime Report (Apr 2026).

Comments


bottom of page