{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
        "slug": "dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/"
        },
        "title": "Do not treat Threat Explorer's latest delivery location as the user's current folder",
        "summary": "What does an unknown or stale latest delivery location establish during an email investigation?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:09+00:00",
        "modified_at": "2026-09-10T00:52:38+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 254,
        "potentially_affected": "Investigators interpreting original and latest delivery locations in Microsoft Defender for Office 365 Threat Explorer.",
        "dse_recommendation": "Separate recorded delivery and security actions from any claim about the message's present user-managed location.",
        "primary_source": {
            "name": "About Threat Explorer and Real-time detections in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Threat Explorer&#8217;s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this interpretation when an investigation relies on Threat Explorer&#8217;s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.</p>\n<h2>DSE recommendation</h2>\n<p>Separate recorded delivery and security actions from any claim about the message&#8217;s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.</p>\n<h2>Verification</h2>\n<p>In a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Threat Explorer field definitions</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nThreat Explorer’s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. Microsoft Learn.\nApplicability\nUse this interpretation when an investigation relies on Threat Explorer’s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.\nDSE recommendation\nSeparate recorded delivery and security actions from any claim about the message’s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.\nVerification\nIn a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.\nOfficial references\nMicrosoft Learn: Threat Explorer field definitions. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nThreat Explorer’s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about).\n\n## Applicability\n\nUse this interpretation when an investigation relies on Threat Explorer’s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.\n\n## DSE recommendation\n\nSeparate recorded delivery and security actions from any claim about the message’s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.\n\n## Verification\n\nIn a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.\n\n## Official references\n\n[Microsoft Learn: Threat Explorer field definitions](https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not treat Threat Explorer's latest delivery location as the user's current folder",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/",
                "headline": "Do not treat Threat Explorer's latest delivery location as the user's current folder",
                "description": "What does an unknown or stale latest delivery location establish during an email investigation?",
                "abstract": "What does an unknown or stale latest delivery location establish during an email investigation?",
                "articleBody": "Source facts\nThreat Explorer’s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. Microsoft Learn.\nApplicability\nUse this interpretation when an investigation relies on Threat Explorer’s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.\nDSE recommendation\nSeparate recorded delivery and security actions from any claim about the message’s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.\nVerification\nIn a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.\nOfficial references\nMicrosoft Learn: Threat Explorer field definitions. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:09+00:00",
                "dateModified": "2026-09-10T00:52:38+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-107-do-not-treat-threat-explorer-s-latest-delivery-location-as-the-user-s-current/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not treat Threat Explorer's latest delivery location as the user's current folder"
                },
                "articleSection": [
                    "Cybersecurity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 254,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "About Threat Explorer and Real-time detections in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about"
                }
            }
        ]
    }
}