Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365
Microsoft Defender for Office 365 will enhance the Deep Analysis tab on the Email Entity page with a refreshed UI, improved detonation chains, expanded metadata, and detailed behavior insights. Rollout starts October 2025 (preview) and November 2025 (general availability). No user action or compliance impact expected.
We’re excited to share recent enhancements to the Deep Analysis tab on the Email Entity page in Microsoft Defender for Office 365. These updates are designed to provide deeper insights and a more intuitive experience when investigating threats.
When this will happen:
Public Preview: We will begin rolling out early Oct 2025 and expect to complete by late Oct 2025.
General Availability (Worldwide): We will begin rolling out early Nov 2025 and expect to complete by mid-Nov 2025.
How this will affect your organization:
There will not be any impact on the security investigation and hunting workflow. Post rollout, security teams will have deeper insights from the detonation outcomes to help them make more informed decisions. The enhancements will provide:
- A refreshed and streamlined user interface
- Improved detonation chain with nested entity details for better threat visibility
- Expanded URL and file metadata for better context
- More detailed and exportable behavior insights
These improvements are designed to empower your security teams with richer, more actionable data to accelerate investigations and response.
URL detonation details:
Screenshot URL 1:
Screenshot URL 2:
Screenshot URL 3:
File detonation details:
Screenshot File 1:
Screenshot File 2:
Screenshot File 3:
What you need to do to prepare:
No action items needed from users or admin.
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.
Message ID: MC1163754