TL;DR: 70% of its customers have fully moved away from secure email gateways, as legacy SEG controls continue to miss attack types that are increasing and Microsoft 365 expands native security capabilities, according to Abnormal AI. The shift shows email defence is now a control-design problem, not just a filtering problem.
At a glance
What this is: Abnormal AI argues that secure email gateways are losing relevance as customers move to other controls, newer attack types bypass legacy filtering, and Microsoft 365’s native protections reshape the email security baseline.
Why it matters: IAM and security teams need to treat email as an identity-adjacent control plane, because mailbox compromise, phishing, and token theft now require governance across authentication, access, and detection rather than reliance on a single perimeter layer.
Context
Secure email gateways were built to filter malicious messages at the email perimeter, but that model weakens when attacks shift into identity abuse, link-based payloads, and platform-native email controls. In this webinar, Abnormal AI frames the issue as a migration away from a legacy control category rather than a simple product preference.
The governance question for practitioners is not whether email threats still exist. It is whether the current control stack can absorb the overlap between email security, identity protection, and platform-native defences when the mailbox is already a primary attack surface.
Key questions
Q: What breaks when secure email gateways are the main email security control?
A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error. The gateway may still block commodity spam, but it cannot fully govern user action, recipient context, or account compromise. That leaves a gap between message delivery and actual risk reduction.
Q: When should organisations prioritise native platform controls over a SEG?
A: Prioritise the native platform when it already provides the baseline inspection, policy enforcement, and threat detection that the SEG was added to supply. The decision should turn on overlap and residual risk, not on habit. If the gateway only duplicates controls already present in Microsoft 365, it may add complexity rather than coverage.
Q: What are the signs that legacy email filtering is no longer sufficient?
A: The clearest signs are recurring attacks that bypass content-based detection, growing reliance on identity abuse instead of malicious attachments, and heavy dependence on follow-on controls to contain mailbox compromise. When the mailbox becomes the entry point for account takeover rather than the endpoint of the attack, filtering is no longer the main control.
Q: How should security teams share accountability for email-to-identity attacks?
A: Email security and IAM teams should treat mailbox abuse, phishing recovery, and token theft as one operational chain. If each team only owns its own tool set, attackers can move from mail delivery to identity compromise without a clear response owner. Joint ownership should cover prevention, detection, and recovery across the same path.
Background and context
Why legacy secure email gateways miss modern attack paths
Secure email gateways are primarily content and reputation filters. They look for known malicious indicators, malicious attachments, suspicious URLs, and sender anomalies, but they were not designed to govern the full range of identity-driven email abuse such as token theft, consent phishing, or attacks that begin outside the message body. As adversaries shift toward behaviour that is harder to classify statically, SEG value declines because the control sees the message, not the downstream identity consequence. Practical implication: teams should evaluate email defence by the attack paths it blocks, not by the volume of mail it filters.
Practical implication: Measure email protection against identity-driven attack paths, not only message filtering performance.
How Microsoft 365 native security changes the email control baseline
When a major platform expands its own security capabilities, the decision is no longer between a SEG and nothing. Microsoft 365’s native controls can absorb some of the inspection and enforcement work that used to sit at the gateway, which shifts the architecture question toward overlap, redundancy, and blind spots. That does not eliminate the need for additional controls, but it changes where those controls add value. Practical implication: reassess whether the SEG is still doing unique work or merely duplicating controls already present in the platform.
Practical implication: Map what the native platform already enforces before deciding whether a SEG still earns its place.
Email defense as an identity and access problem
Email is not only a content channel. It is also an access channel for resets, approvals, shared documents, OAuth grants, and token capture, which is why modern email compromise often becomes identity compromise. That is the architectural shift this migration reflects: the control problem spans mail hygiene, session trust, and account takeover resistance. In practice, email security has to connect with identity governance rather than sit apart from it. Practical implication: align phishing defence, conditional access, and account recovery controls as one operational chain.
Practical implication: Treat email security and identity governance as linked controls across the same attack surface.
NHI Mgmt Group analysis
Email defence has moved from perimeter filtering to identity-adjacent control design. The article’s central signal is not that one product class is fading, but that the attack surface has changed faster than gateway-era assumptions. When threats land in authentication flows, mailbox trust, or platform-native collaboration, the control question shifts to where identity enforcement actually happens. Practitioners should treat email security as part of the access stack, not a separate inbox problem.
Legacy SEG dependence creates a governance blind spot when the platform itself now supplies baseline protections. If Microsoft 365 already covers part of the inspection and enforcement layer, then the remaining value of a SEG has to be proven against specific attack paths. That forces teams to separate inherited architecture from current control need. Practitioners should re-baseline email security architecture against what the platform now enforces natively.
Email compromise is increasingly an identity event, not just a message event. Phishing, token theft, and malicious consent flows all turn email into a path toward account control. That means email defence must be evaluated alongside authentication, session trust, and recovery workflows. Practitioners should stop measuring success only by blocked mail and start measuring whether mailbox abuse can still become account abuse.
Control migration exposes the broader problem of overlapping security ownership. Email teams, IAM teams, and cloud security teams often treat the mailbox as their own domain, but attackers do not respect those boundaries. The practical result is fragmented accountability for the same compromise path. Practitioners should build shared ownership for email-to-identity attack chains rather than isolate them inside a single team charter.
Native platform security is changing the market signal, but it does not remove the need for governance. The lesson from the migration is not simply to remove tools. It is to identify where the security architecture now depends on policy consistency, identity assurance, and detection coverage instead of gateway duplication. Practitioners should use the shift to simplify control stacks only where governance remains intact.
What this signals
Control overlap is now the real SEG question. If a platform such as Microsoft 365 already enforces part of the email security baseline, the practical issue becomes whether the legacy gateway adds unique protection or only more administration. That is a governance decision, not a feature comparison.
Email security now behaves like an identity control surface. The attack path increasingly runs from message delivery to authentication abuse, which means teams need a shared view of email, access, and recovery controls. A mailbox that can still become an account takeover path is an IAM problem as much as a mail problem.
For practitioners
- Reassess SEG coverage by attack path Map which attacks still require a gateway layer and which are already handled by Microsoft 365 native controls, then compare that to the mailbox abuse patterns you actually see.
- Tie email defense to identity controls Connect phishing defence, conditional access, and account recovery so mailbox compromise cannot easily become identity takeover.
- Audit which detections are content-only Separate static message filtering from behavioural or identity-aware detections, then identify where your current stack still depends on signature-style inspection.
- Define who owns email-to-identity compromise Assign shared accountability across email security and IAM for token theft, malicious consent, and account recovery abuse.
Key takeaways
- Legacy secure email gateways are losing influence because modern email attacks increasingly bypass content-centric inspection and move into identity abuse paths.
- The migration signal is architectural, not cosmetic: native platform controls and identity-linked defences now matter more than a single perimeter filter.
- Practitioners should decide SEG value by residual risk, control overlap, and mailbox-to-identity compromise potential, not by legacy deployment patterns.
Key terms
- Inbox-to-identity attack chain: A chain in which email delivery leads directly to identity compromise and then to additional targeting from the compromised inbox. It matters because messaging security, authentication, and session governance become one threat surface rather than separate control domains.
- Control Overlap: Control overlap is the condition where one identity holds multiple permissions that should be separated across different roles or stages. It is a governance problem because it concentrates authority, weakens accountability, and can let one person or account carry out a complete harmful action chain without independent scrutiny.
- Identity-Adjacent Control: A security control that is not itself IAM, but directly affects authentication, access, or recovery outcomes. Email security often functions this way because mailbox compromise can trigger resets, approvals, and session abuse.
- Mailbox compromise: Mailbox compromise occurs when an attacker gains control of an email account or can act within it as if they were the legitimate user. In identity terms, it turns email into an abuse channel for fraud, lateral trust exploitation, and policy bypass unless the organisation can detect and contain the takeover quickly.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org