ExplainerInformationCybersecurity

Do not treat Threat Explorer's latest delivery location as the user's current folder

What does an unknown or stale latest delivery location establish during an email investigation?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseExplainer · 2 min read
Executive summary

What you need to know

What does an unknown or stale latest delivery location establish during an email investigation?

Potentially affected

Investigators interpreting original and latest delivery locations in Microsoft Defender for Office 365 Threat Explorer.

DSE recommendation

Separate recorded delivery and security actions from any claim about the message's present user-managed location.

Source facts

Threat Explorer’s Latest delivery location does not include end-user actions such as deletion or movement into an archive or PST file. Microsoft documents Unknown locations even when Delivery action says Delivered, for example when an Inbox rule moves mail into another default folder. Unknown can also occur when ZAP cannot find a message after delivery because it was moved or deleted. Microsoft Learn.

Applicability

Use this interpretation when an investigation relies on Threat Explorer’s original or latest location fields. The relevant question is what those fields establish, not whether an unfamiliar value should automatically be escalated as a delivery failure.

DSE recommendation

Separate recorded delivery and security actions from any claim about the message’s present user-managed location. Preserve the displayed location, delivery action and observation time together. If the response decision requires confirmation that a particular copy still exists, request appropriately authorized evidence for that specific question rather than treating the dashboard label as a live folder inventory. Avoid describing an unknown location as successful removal.

Verification

In a controlled mailbox, compare the fields before and after a safe sample is moved by an end user. Inspect whether the investigation notes distinguish the observed security record from the independently established mailbox state. For a real case, keep uncertainty explicit until the necessary evidence is obtained. Record what was actually checked and do not infer that the recipient opened the message, retained a copy, or was protected merely from a location value.

Official references

Microsoft Learn: Threat Explorer field definitions. Source reviewed September 9, 2026.

Primary reference

Review the official source

About Threat Explorer and Real-time detections in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE