Microsoft will provide Office 365 Advanced Threat Protection (ATP) users with more details about malware samples and malicious URLs that were discovered after the following detonation.

“We are working to uncover more of the details that led to malicious activity when URLs or files are ‘triggered’ in Office 365 ATP,” the Microsoft 365 roadmap entry for the new feature states.
“In addition to the detonation chain, we will also share a summary of the detonation, with details such as the time range of the detonation, the file or URL resolution, related entities, screenshots , and more.”
The «detonation service» detects malicious attachments and links
The «detonation service» is used by Office 365 ATP to scan attached files (via the ATP Safe Attachments feature) and embedded links (via ATP Safe Links) in real time in controlled environments to warn customers of unknown threats via email if it detects any malicious behavior.
It is designed to expose malicious signals “including behaviors such as removed and downloaded files, registry manipulation for persistent and stored stolen information, outbound network,” and more, as Microsoft explains.
“The volume of detonated threats translates into millions of signals that need to be inspected. To scale protection, we use machine learning to sort through this massive amount of information and determine a ‘verdict’ for the files analyzed.”
Global availability in June 2020
Microsoft plans to release this updated version of Office 365 in June 2020 and make it generally available across all Office 365 environments with an Advanced Threat Protection program.
You can get Office 365 ATP with Exchange and Microsoft 365 subscription plans, including Microsoft 365 E5, Office 365 E5, Office 365 A5, Microsoft 365 Business Premium, and more.
If your current subscription does not include Advanced Threat Protection, you can purchase ATP Plan 1 or ATP Plan 2 as an add‑on to certain subscriptions.
Part of the boost to enhance Office 365 security features
Safe Documents was previously released in private preview for Office 365 ProPlus customers with Microsoft 365 E5 and E5 Security subscriptions in February, a feature designed to automatically check Office documents for known risks and threat profiles before they are opened.
Office 364 ATP will be updated in June with attack flow insights for malware attacks to improve the campaign that was released in December in public preview with support for phishing campaigns.
Microsoft is also working to stop corporate data theft through email forwarding by disabling Office 365 email forwarding to external recipients by default, starting in the fourth quarter of 2020
During Q2, Redmond plans to add automated malicious content blocking to Office 365, regardless of custom administrator or user, unless manually overridden.
