Microsoft says Defender missed 221 high-severity emails per thousand users and still won its own benchmark
The vendor's fifth quarterly scorecard shows missed-threat rates climbing across the industry as AI-written phishing gets harder to catch.

Key points
- Microsoft's May to July 2026 benchmark says Defender for Office 365 missed 221 high-severity emails for every 1,000 users protected, a figure the company publishes itself.
- That was 55.4% fewer misses than the next-best secure email gateway rival, according to Microsoft's own data.
- Missed threats have climbed across several reporting periods for every vendor Microsoft measured, Defender included.
- Third-party add-on filters, known as ICES tools, caught an additional 0.30% of malicious mail and 0.52% of spam on top of Defender.
- Microsoft credits an AI model rebuild for a roughly two-thirds drop in missed threats over a four-week test.
Microsoft has published its fifth quarterly email security scorecard, and the honest bit is buried under the victory lap: even the winner is letting a lot through.
The report, from the Microsoft Security Response Center's blog, covers May 2026 through July 2026. It measures high-severity phishing and malware emails that slipped past each vendor's filter, per 1,000 users protected. Microsoft says Defender missed 221. Rival secure email gateways, the specialist filters large companies buy to sit in front of their mail, missed more than double that.
What is Microsoft actually measuring?
Missed threats, not catches. Microsoft argues that counting blocked emails is misleading, because different customers face different volumes. Counting what reached the inbox is the fairer test.
High-severity means credential phishing, business email compromise (where criminals impersonate an executive to trigger a wire transfer), and malware attachments, not nuisance spam.
Are the numbers getting worse?
Yes, and Microsoft admits it. Miss rates have risen across multiple reporting periods for every vendor in the benchmark. Microsoft blames generative AI, which lets attackers scrape public information about a target and craft convincing impersonation attempts that fool both filters and staff.
That's the part worth sitting with. The vendor with the best score in its own league table is still letting hundreds of serious messages through per thousand mailboxes, and the trend points up. We've covered the product's reliability problems separately: our 2 September story found Defender incorrectly flagging normal Google URLs as malicious, and a 17 September report detailed a second proof-of-concept walking past Microsoft's patch for a known Defender flaw.
| Metric (May to July 2026) | Value |
|---|---|
| Defender high-severity misses per 1,000 users | 221 |
| Gap to next-best SEG rival | 55.4% fewer misses |
| ICES add-on malicious catch rate | 0.30% |
| ICES add-on spam catch rate | 0.52% |
| Defender post-delivery malicious catch | 92% average |
What about the add-on filters companies pay extra for?
Not much, on these numbers. Integrated cloud email security tools, or ICES, are third-party products that plug into Microsoft 365 to catch what Defender misses. Microsoft's benchmark says they added 0.30% on malicious mail and 0.52% on spam, both up on the previous quarter (0.13% and 0.28%) but still small.
Where ICES tools earn their keep is promotional and bulk filtering. Microsoft says that finding has now shaped its product roadmap: the new Promotions folder in Outlook is a direct response.
What changed under the hood?
Microsoft rebuilt Defender's machine learning stack to weigh message topic and language alongside technical signals. Over a four-week test, it recorded roughly a two-thirds reduction in false negatives (bad mail wrongly let through) and nearly a one-fifth reduction in false positives (good mail wrongly blocked).
Microsoft has also added prompt injection protection, which strips hidden instructions attackers plant in emails to hijack AI assistants like Copilot when they process a mailbox on a user's behalf. It's a genuinely new attack surface, and one worth watching as more firms let AI agents triage inboxes.
Should you worry?
One caveat runs through the whole exercise. This is Microsoft grading Microsoft against Microsoft's competitors, using Microsoft's telemetry. Independent benchmarks from organisations like AV-Comparatives or SE Labs would carry more weight. Until those land, treat the ranking as directional. The rising miss rate across every vendor is the more useful number, whoever's publishing it.



