Microsoft Defender for Office 365
Email and collaboration

Zero Hour Auto Purge

In brief

Updated Microsoft Defender documentation in defender-office-365/zero-hour-auto-purge.md.

What Defender admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Zero-day malware that was undetectable during mail flow.
  • Content weaponized after delivery to users.

ZAP addresses these issues by continually monitoring spam and malware signature updates in the service, and is seamless for users. ZAP finds and takes automated action on messages that are already in a user's mailbox. ZAP's search is limited acts on delivered mail through two paths:

  • Per-message reevaluation rescans individual messages within 48 hours of delivery.
  • Campaign-based remediation retroactively acts on messages later identified as part of a malicious campaign, including messages older than 48 hours — typically within a few hours to the last 48 hours of delivered email. a few days after delivery.

Users aren't notified ifwhen ZAP detects and moves a message.

Watch this short video to learn how ZAP in Microsoft Defender for Office 365 automatically detects and neutralizes threats in email.