ACR Index Get a draft ACR

Microsoft Defender for Office

Accessibility Conformance Report published by Microsoft

Conformance by level

Reported by the vendor. WCAG Level AA is the benchmark referenced by ADA Title II, Section 508 and the European Accessibility Act; Level AAA is optional and often left unevaluated.

Source: Download the original report from Microsoft (Word document). Or browse all of Microsoft's reports on Microsoft's own site.

These figures are extracted from that document. They are the vendor's own statements, not an independent assessment, and automated extraction can misread a table.

All reported criteria (87)

Conformance as stated by Microsoft in its published report.
CriterionNameLevel ConformanceRemarks from vendor
1.1.1 Non-text Content A Partially Supports 1) Screen reader user does not receive any information indicating that activating the "Open email entity" menu item will redirect the user to a new browser tab in Submissions in Email & Collaboration Report Insights in Microsoft Defender portal.2) The 'Microsoft' <img> elements do not have alternative text or a role of none or presentation on the Outlook.com Postmaster webpage.
1.2.1 Audio-only and Video-only (Prerecorded) A Supports
1.2.2 Captions (Prerecorded) A Supports
1.2.3 Audio Description or Media Alternative (Prerecorded) A Partially Supports Audio description is not provided for the video in the Scenario flyout in Training modules in Attack Simulation - Content Library.
1.3.1 Info and Relationships A Partially Supports 1) Screen reader fails to announce label association for 'Email' and 'More info' link in URL table dialog in User Reported under Submissions in Microsoft Defender.2) Screen reader is not announcing group name ‘Start/End date’ for ‘Date’ controls in Set preferences step in URL threat protection under Email & collaboration reports in Microsoft Defender - Reports.3) Headings are not defined for 'Business email compromise' dialog in Training modules in Attack Simulation - Content Library.4) Visually appearing heading text 'From' is not programmatically defined as a heading in Training modules in Attack Simulation - Content Library.5) 'Question' information is not announced by the screen reader when focus lands on the first checkbox in Training modules in Attack Simulation - Content Library.6) Screen reader announces incorrect step number when navigating with Next/Previous buttons in Training modules in Attack Simulation - Content Library.7) Screen reader is not announcing grouping information for 'PI' buttons on What is Considered Personal Information? page in Privacy awareness under Training modules in Attack Simulation - Content Library.8) "Select each button to learn more." and "Select each term to view the definition." are not associated with the list of items in Training modules in Attack Simulation - Content Library.9) The visual heading "Disclaimer" is not defined under a heading level in Training modules in Attack Simulation - Content Library.10) Screen reader announces incorrect feedback as both 'Right' and 'Wrong' answer upon submitting questions in Privacy awareness under Training modules in Attack Simulation - Content Library.11) The screen reader does not announce the automatic reset of invalid time values (Hour/Minute) after focus shifts in the "Set preferences" step in URL threat protection under Email & collaboration reports in Microsoft Defender.12) The screen reader does not announce required field indicators and validation messages in the “Select filters” step of the 'Create on-demand report' wizard in URL threat protection under Email & collaboration reports in Microsoft Defender.13) Visually appearing heading text 'Welcome to the Evaluation' is not defined programmatically as a heading in Privacy awareness under Training modules in Attack Simulation – Content Library.14)Screen Reader announces, 'List item not selected 1 of 1' as list item for Invalid search in 'Recipient tag' combo box in quarantine of review page in Microsoft Defender.15) Incorrect heading structure is defined on the page: multiple H1 headings are present, and all email addresses are unnecessarily defined under H2 level heading in Entity page of Microsoft Defender.
1.3.2 Meaningful Sequence A Partially Supports In browse mode, while navigating with the 'H' shortcut key, screen reader focus moves to the previous page header in Training modules in Attack Simulation - Content Library.
1.3.3 Sensory Characteristics A Partially Supports No tooltip is defined for 'Submit for analysis' and 'Manage indicator' submenu in URLs table dialog in User Reported under Submissions in Microsoft Defender.
1.4.1 Use of Color A Partially Supports Colour is the only method used to indicate Pass/Fail status based on score display in Privacy awareness under Training modules in Attack Simulation - Content Library.
1.4.2 Audio Control A Supports
2.1.1 Keyboard A Partially Supports 1) On applying text spacing, the 'Choose target entities' table data is truncated and headers are not resizable in User Reported under Submissions in Microsoft Defender2) The tooltip displayed for the truncated user list within the 'Recipient Address' combo box is not keyboard accessible in URL threat protection under Email & collaboration reports in Reports in Microsoft Defender.3) Table headers are not draggable with keyboard at mail flow tab under Email & collaboration Reports in Microsoft Defender.
2.1.2 No Keyboard Trap A Supports
2.1.4 Character Key Shortcuts A Supports
2.2.1 Timing Adjustable A Supports
2.2.2 Pause, Stop, Hide A Supports
2.3.1 Three Flashes or Below Threshold A Supports
2.4.1 Bypass Blocks A Supports
2.4.2 Page Titled A Supports
2.4.3 Focus Order A Partially Supports 1) On activating 'Picture-in-Picture', the keyboard focus does not move to the mini-player in Generative AI under Training modules in Attack Simulation - Content Library.2) After the Exit course button, screen reader focus lands on a hidden element and announces information for hidden controls in Training modules in Attack Simulation - Content Library.3) A hidden link is observed when dragging and placing objects under PI and Non-PI in Privacy awareness under Training modules in Attack Simulation - Content Library.4) In 'Outlook.com Postmaster' webpage, on selecting left navigation links keyboard focus is getting lost.5) On activating apply button in the filter flyout, then the keyboard focus moves out of the UI under email & collaboration reports of Microsoft Defender.
2.4.4 Link Purpose (In Context) A Supports
2.5.1 Pointer Gestures A Supports
2.5.2 Pointer Cancellation A Supports
2.5.3 Label in Name A Partially Supports The visual name and accessible name for the 'Learn more about social engineering via email' button are not the same in Training modules in Attack Simulation – Content Library.
2.5.4 Motion Actuation A Not Applicable
3.1.1 Language of Page A Partially Supports In the New support request webpage, the lang attribute is missing for dynamically selected languages, causing the screen reader to not announce content changes in OLC Support Form – New support request.
3.2.1 On Focus A Supports
3.2.2 On Input A Partially Supports The “What domain are you sending to?” combo box auto-selects the last focused option when dismissed without user confirmation in OLC Support Form – New support request.
3.2.6 Consistent Help A Supports
3.3.1 Error Identification A Partially Supports 1) No input validation is provided for the "Provide the URL of your website" field in the New support request form in OLC Support Form – New support request.2) A client error message appears and is not descriptive when saving the Create on-demand report wizard in URL threat protection under Email & collaboration reports in Reports in Microsoft Defender.3) No field-level error message is displayed for an invalid date selection in the Filter dialog in URL threat protection under Email & collaboration reports in Reports in Microsoft Defender.
3.3.2 Labels or Instructions A Supports
3.3.7 Redundant Entry A Supports
4.1.1 Parsing A Not Applicable
4.1.2 Name, Role, Value A Partially Supports 1) Incorrect title name as 'Introduction' defined for 'Welcome to the Evaluation' Page in Training modules in Attack Simulation – Content Library.2) The screen reader announces an incorrect selected state for steps during navigation and announces incorrect information when any step is activated in Training modules in Attack Simulation – Content Library.3) An incorrect name is defined for the ‘Legitimate mail’ and ‘Phishing’ buttons in the learning activity flyout in Training modules in Attack Simulation – Content Library.4) The correct name is not provided for the info icons in the dialog, and the screen reader announces the same name for all info icons in Training modules in Attack Simulation – Content Library.
1.2.4 Captions (Live) AA Supports
1.2.5 Audio Description (Prerecorded) AA Partially Supports Audio description is not provided for the video in the Scenario flyout in Training modules in Attack Simulation - Content Library.
1.3.4 Orientation AA Partially Supports The "Social engineering via email" training module requires an orientation change to view content in Training modules in Attack Simulation - Content Library.
1.3.5 Identify Input Purpose AA Supports
1.4.3 Contrast (Minimum) AA Partially Supports 1) In dark mode, the "Learn more about threat protection" link has a low contrast ratio of 3.75:1 in Email and collaboration Reports under Reports in Microsoft Defender.2) In dark mode, the contrast ratio for ‘Learn more about zero-hour auto purge’ link in Post-delivery activities webpage is 3.3:1 in Email & collaboration reports under Reports in Microsoft Defender.3) The contrast between foreground and background colors for the Exit course button meets WCAG 2 AA minimum contrast ratio thresholds in Training modules in Attack Simulation - Content Library.4) In high contrast aquatic mode, the keyboard-focused tag text has a low contrast ratio of 2.447:1 in Email and collaboration Reports under Reports in Microsoft Defender.
1.4.4 Resize text AA Partially Supports At 200% zoom, the main heading text 'New support request' gets cut off in OLC Support Form - New support request.
1.4.5 Images of Text AA Supports
1.4.10 Reflow AA Partially Supports 1) At 400% zoom, the main heading text 'New support request' gets cut off in OLC Support Form - New support request.2) At 400% zoom, captions menu items and the volume slider are truncated, and other controls are not clearly visible in reflow in Training modules in Attack Simulation - Content Library.3) At 400% zoom, the content and Start course button text are truncated when playing the video in Training modules in Attack Simulation - Content Library.4) At 400% zoom, 'your high score is' and 'Passing 80%' content is not visible when navigating the page with the keyboard in Training modules in Attack Simulation - Content Library.5) At 400% zoom in reflow, the keyboard-focused step number is not visible on the screen in Training modules in Attack Simulation - Content Library.6) At 400% zoom, multiple horizontal and vertical scrollbars appear on Privacy awareness accessible pages in Training modules in Attack Simulation - Content Library.7) The Start page in Privacy Awareness does not adapt to 400% zoom in Training modules in Attack Simulation - Content Library.8) At 400% zoom, content within the "Features of a Phishing Message" flyout becomes truncated, info icons overlap, and parts of the content are cut off in Training modules in Attack Simulation - Content Library.9) At 400% zoom, video controls (full screen & mute) are not clearly visible and become disoriented in Training modules in Attack Simulation - Content Library.10) At 400% zoom, the email address Office365Alerts@microsoft.com is truncated in the Email Preview tab in Entity Page under M365 Security.11) At 400% zoom, the link text '1 of 2 Generative AI: What is it? Understanding the risks' is truncated on the Exit Course screen in Training modules in Attack Simulation - Content Library.12) At 400% zoom in reflow, the complete graph is not visible, and graph dates overlap in Threat Explorer under Threat management in M365 Security.13)At 400% zoom in reflow mode, the complete graph is not clearly visible, the graph tooltip is misaligned, and legend labels are truncated in Campaigns under Threat management in M365 Security.14) At 400% zoom, the Mailflow graph is not visible properly in Mail flow status summary under Email & collaboration reports in Reports in M365 Security.15) At 400% zoom, a horizontal scrollbar is observed for the entire Review region in Preset Security Policies under Threat Management in Attack Simulation.16) At 400% zoom, horizontal scrolling observed in 'Outlook.com Postmaster' webpage of Microsoft Defender page.
1.4.11 Non-text Contrast AA Partially Supports 1) The color contrast ratio of the keyboard focus boundary for 'accessible & interactive' control is 1.4:1 with respect to its background in Training modules in Attack Simulation - Content Library.2) In high contrast aquatic mode, the focus indicator at info icons in 'Features of a Phishing Message' flyout has a low contrast ratio of 1.3:1 in Training modules in Attack Simulation - Content Library.3) The luminosity ratio for 'Back & quit' keyboard focus indicator (black) and its background (gray) is 1.6:1 in Training modules in Attack Simulation - Content Library.4) The contrast ratio for the 'Settings' and 'Close' buttons in Picture-in-Picture screen is less than the required 3:1 in Training modules in Attack Simulation - Content Library.5) The contrast ratio of the keyboard focus border over header controls (Home, Audio, Quit) is less than the required 3:1 in Privacy awareness under Training modules in Attack Simulation - Content Library.6) Insufficient contrast ratio is provided for the 'Legitimate' and 'Phishing' controls, with ratios of 1.5:1 and 1.3:1 respectively in Training modules in Attack Simulation - Content Library.7) In normal mode, the keyboard focus indicator on the close button at the "added" tag has a low contrast ratio of 1.17:1 in Email and collaboration Reports under Reports in Microsoft Defender.8) In dark mode, the pink legend at the "Submissions" card has a low contrast ratio of 1.955:1 in Email and collaboration Reports under Reports in Microsoft Defender.9) In dark mode, the next/previous buttons at "Top senders and recipients" and "URL Protection report" charts have a low contrast ratio of 1.696:1 in Email and collaboration Reports under Reports in Microsoft Defender.
1.4.12 Text Spacing AA Supports
1.4.13 Content on Hover or Focus AA Supports
2.4.5 Multiple Ways AA Supports
2.4.6 Headings and Labels AA Supports
2.4.7 Focus Visible AA Partially Supports The keyboard focus indicator is not visible on the Start button on the Ransomware page in Training modules in Attack Simulation – Content Library.
2.4.11 Focus Not Obscured (Minimum) AA Supports
2.5.7 Dragging Movements AA Supports
2.5.8 Target Size (Minimum) AA Supports
3.1.2 Language of Parts AA Supports
3.2.3 Consistent Navigation AA Supports
3.2.4 Consistent Identification AA Supports
3.3.3 Error Suggestion AA Supports
3.3.4 Error Prevention (Legal, Financial, Data) AA Not Applicable
3.3.8 Accessible Authentication (Minimum) AA Supports
4.1.3 Status Messages AA Partially Supports 1) The screen reader fails to announce the status message ‘Thank you - your request was submitted Support request number: 7085080820’ when submitting the New support request form in OLC Support Form – New support request.2)The screen reader fails to announce the score information upon assessment submission in Privacy awareness under Training modules in Attack Simulation – Content Library.3) Screen reader does not announce “No data” information when all toggle buttons are turned off in graph Under Email and collaboration Reports
1.2.6 Sign Language (Prerecorded) AAA Not Evaluated
1.2.7 Extended Audio Description (Prerecorded) AAA Not Evaluated
1.2.8 Media Alternative (Prerecorded) AAA Not Evaluated
1.2.9 Audio-only (Live) AAA Not Evaluated
1.3.6 Identify Purpose AAA Not Evaluated
1.4.6 Contrast (Enhanced) AAA Not Evaluated
1.4.7 Low or No Background Audio AAA Not Evaluated
1.4.8 Visual Presentation AAA Not Evaluated
1.4.9 Images of Text (No Exception) AAA Not Evaluated
2.1.3 Keyboard (No Exception) AAA Not Evaluated
2.2.3 No Timing AAA Not Evaluated
2.2.4 Interruptions AAA Not Evaluated
2.2.5 Re-authenticating AAA Not Evaluated
2.2.6 Timeouts AAA Not Evaluated
2.3.2 Three Flashes AAA Not Evaluated
2.3.3 Animation from Interactions AAA Not Evaluated
2.4.8 Location AAA Not Evaluated
2.4.9 Link Purpose (Link Only) AAA Not Evaluated
2.4.10 Section Headings AAA Not Evaluated
2.4.12 Focus Not Obscured (Enhanced) AAA Not Evaluated
2.4.13 Focus Appearance AAA Not Evaluated
2.5.5 Target Size AAA Not Evaluated
2.5.6 Concurrent Input Mechanisms AAA Not Evaluated
3.1.3 Unusual Words AAA Not Evaluated
3.1.4 Abbreviations AAA Not Evaluated
3.1.5 Reading Level AAA Not Evaluated
3.1.6 Pronunciation AAA Not Evaluated
3.2.5 Change on Request AAA Not Evaluated
3.3.5 Help AAA Not Evaluated
3.3.6 Error Prevention (All) AAA Not Evaluated
3.3.9 Accessible Authentication (Enhanced) AAA Not Evaluated

Is this your product? If this report is out of date or misrepresented, we will correct or remove it. Contact us to claim this listing.

Get told when this changes

This report is dated November 25, 2025. An ACR can be quietly replaced at any time, and the published date is the only signal a buyer gets. We will email you when this one is updated.

Double opt-in — we email you once to confirm, and send nothing until you do. One-click unsubscribe on every message. We store your address and what you are watching, nothing else. Privacy.