Knowbe4 iconKnowbe4Sep 25, 2026 ~6 min source read

Microsoft’s email benchmark shows layered defenses still matter — and which add-on led the pack

Microsoft’s May–July 2026 telemetry benchmark compares real-world results from Microsoft Defender plus seven Integrated Cloud Email Security add-ons. The data clarifies what baseline cloud filtering handles, where it leaves gaps, and which add-on delivered the largest incremental protection in live tenants.

What Microsoft’s Latest Email Benchmark Proves About Defense-in-Depth

Share this story

Send the public story page.

Useful takeaways from this story.

Microsoft Defender blocks the bulk of commodity spam, mass phishing and known malware, but evasive, payload-free attacks often bypass baseline filters.

KnowBe4 Defend led all seven measured ICES add-ons across Microsoft’s uplift metrics, catching substantially more dangerous mail that Defender missed and performing the largest post-delivery clean-up.

Low overlap with Defender is an important metric: it shows an add-on is finding net-new threats rather than duplicating existing detections.

The useful part

Blog / Email Security / What Microsoft's Latest Email Benchmark Proves About Defense-in-Depth. Reiner, MBA | Sep 25, 2026 Tweet Let's face it: inertia is often the most common yet most dangerous adversary when it comes to acquiring new technology, especially in cybersecurity. There is still a persistent assumption across many organizations that email security architecture that worked three years ago is still good enough for today's threat landscape.

How it works

  • Baseline perimeter filtering inevitably leaves an attack surface exposed to executive impersonation and Business Email Compromise (BEC).
  • Hyper-personalized GenAI spear phishing and adversarial prompt injections have also become widespread, targeting users wherever they collaborate, whether in Outlook or Microsoft Teams.
  • To understand how the market solves this challenge, Microsoft measured seven leading Integrated Cloud Email Security (ICES) add-on solutions running directly on top of Microsoft Defender.
  • --> When combined with our position as a member of the Microsoft Defender ICES Vendor Ecosystem, this data gives security leaders the clear, verifiable foundation they need to make confident architectural...
  • When measuring how much incremental malicious mail add-ons were caught after Microsoft Defender delivered the message, the figures were unmistakable: #1 in Dangerous Email Caught That Microsoft Defender...

What to take from it

Even when security teams suspect gaps, the friction of evaluating, procuring and operationalizing new technology creates a massive organizational bottleneck. Because these attacks contain no malicious attachments or known-bad links, static inspection has nothing to detonate. KnowBe4 Defend caught 3.7 times more dangerous emails that slipped past Microsoft Defender than the average add-on.

Example or evidence

  • Vendor claims are notoriously reliant on synthetic lab simulations or cherry-picked sample sizes that rarely survive in an organization's live environment.
  • That reality is why Microsoft's latest benchmark release is an inflection point for organizations looking to evaluate the effectiveness of their tech stack.
  • Microsoft Defender stops the overwhelming volume of commodity spam, mass phishing and known malware before it reaches an inbox.
  • Routing email via a legacy Secure Email Gateway (SEG) into Microsoft Defender introduces unnecessary cost, latency, technical complexity and operational friction.

Details worth keeping

This report strips away marketing hyperbole and measures what security tools actually catch inside live production tenants. Native cloud defense has matured significantly. Evasive, payload-free attacks demand specialized behavioral AI.

Related coverage

  • Ninjaone: Windows systems are the backbone of most IT environments, running critical applications and enabling distributed workforces worldwide.
  • Cofense: Lee Martin explores why security awareness programs need to move beyond measuring activity and risk to focus on whether employees are actually getting better at recognizing and responding to phishing.
  • Thehackernews: Introduction Security teams have gotten pretty good at testing against what can hurt them.
  • Microsoft: Once a Marine, always a Marine.

More context around this story.

Ninjaone iconNinjaoneSep 18, 2026

How to Build a Sustainable Windows Security Posture

Windows systems are the backbone of most IT environments, running critical applications and enabling distributed workforces worldwide. Yet many organizations still rely on reactive security: patching after breaches occur and investigating threats only after alerts fire, adding cost and regulatory exposure. As an IT man

Beyond Human Risk: A Better Way to Build Secure Behavior
Cofense iconCofenseSep 23, 2026

Beyond Human Risk: A Better Way to Build Secure Behavior

Lee Martin explores why security awareness programs need to move beyond measuring activity and risk to focus on whether employees are actually getting better at recognizing and responding to phishing. Cofense’s approach to Secure Behavior Management connects measurable employee competency with real-world phishing and r

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app