Can a malicious email manipulate Copilot? Microsoft’s new prompt injection protection explained

Yes. An email can contain instructions aimed at an AI assistant rather than the person reading it. Microsoft calls this prompt injection. Attackers can hide instructions in the message body, quoted replies, attachments, metadata, invisible text or encoded content. If an AI assistant processes the email, those instructions may try to influence its summary, classification or response.

Microsoft now documents Prompt injection protection in Microsoft Defender for Office 365 as available for Defender for Office 365 Plan 2. It inspects inbound email before delivery through the existing mail-flow protection pipeline, and Microsoft says no additional configuration is required.

What prompt injection looks like

Traditional phishing tries to persuade a person to click or reply. Prompt injection targets the model. Microsoft lists techniques including white-on-white or zero-size text, off-screen HTML, malicious instructions in quoted threads, attachments and obfuscated Unicode or Base64 content.

Security researchers at Permiso demonstrated cross-prompt injection against Outlook email-summary experiences and Copilot in Teams in early 2026. EchoLeak, CVE-2025-32711, was a separate Microsoft 365 Copilot vulnerability identified in 2025 and subsequently addressed. The wider risk is covered in our guide to zero click phishing and advice on Copilot security controls before an IT rollout.

Microsoft 365 Copilot can ground responses in emails, chats, documents and other Microsoft Graph content that the signed-in user has permission to access. Overshared SharePoint or OneDrive content can therefore increase what Copilot can surface.

What Microsoft has added

Microsoft says Defender combines LLM classification with existing sender and message signals. It analyses message bodies, subjects, hidden markup, quoted content and normalised encoded text. Detected messages receive the existing High confidence phishing verdict and a Prompt injection protection detection technology value.

LayerWhere it actsMain role
Defender for Office 365 prompt injection detectionMail flow, before deliveryDetects malicious instructions in inbound email
Microsoft 365 Copilot safety systemsModel runtimeHelps block injected instructions from grounded content
Microsoft Defender XDR correlationAcross the incidentCorrelates email, identity, endpoint and data signals

The Microsoft Defender for Office 365 team has explained the reasoning behind this defence-in-depth approach.

What it does not solve

Email filtering cannot remove prompt-injection risk from every source. Copilot can also use authorised files, chats and connected data. Microsoft Purview and AI data protection can help manage sensitive information, while organisations should control shadow AI tools quietly sharing company data.

Staff training still matters. Treat Copilot output as generated content, not a security verdict. Reinforce anti phishing for Microsoft 365 and make sure employees understand how your team spots a phishing email. Businesses planning adoption can start with the key features of Microsoft 365 Copilot for business.

FAQs

Do I need to turn prompt injection protection on?

No additional policy is required for the feature itself. Microsoft currently lists it for Defender for Office 365 Plan 2, so confirm that your tenant has the required licensing.

Can Copilot be tricked into exposing company data?

Prompt injection can attempt to influence an assistant, but Microsoft 365 Copilot is designed to surface organisational data only where the user already has permission. Oversharing therefore remains an important risk to review.

Is this only a Microsoft 365 problem?

No. Indirect prompt injection is a wider generative-AI security risk whenever an assistant processes untrusted content.

Where to start

Northern Star can review your deployment through Microsoft Copilot consulting in London, strengthen inbound protection with email security services in London and assess exposure through network penetration testing. IT consulting services in London can support governance, while global IT support for international projects helps multi-site organisations apply consistent controls.

Call Northern Star on +44 (0) 800 319 6032 or book a callback with our London team. You can also see how we work as a managed service provider in London.