Source: Help Net Security
Author: Sinisa Markovic
URL: https://www.helpnetsecurity.com/2025/11/25/enhance-microsoft-calendar-threat-protection/
Microsoft cracks down on malicious meeting invites
ONE SENTENCE SUMMARY:
Microsoft enhances Defender for Office 365 by linking Hard Delete to calendar entry removal and strengthening domain blocking.
MAIN POINTS:
- Phishing attacks exploit calendar entries from auto-created Outlook invites.
- Microsoft updates Defender for Office 365 to remove calendar entries via Hard Delete.
- Security actions like Hard Delete now erase linked calendar items.
- Update applies across security surfaces like Explorer, Advanced Hunting, and API.
- Limitations include .ics files remaining untouched and reissued invites reappearing.
- Domain blocking update simplifies blocking for repeated URLs from the same domain.
- Changes streamline incident response for Security Operations Center (SOC) teams.
- Update aligns email and calendar cleaning processes.
- IT teams benefit from reduced follow-up tasks on calendar inquiries.
- Enhancements help reduce phishing risks and alert noise.
TAKEAWAYS:
- New update connects Hard Delete with calendar item removal.
- Domain-wide blocking reduces repetitive URL handling.
- Changes improve efficiency in phishing incident response.
- Email and calendar entries now follow a unified cleanup process.
- IT teams experience fewer follow-up inquiries about calendar discrepancies.