Microsoft Teams: Report security concerns in Teams meetings

🚨 The Signal: Teams meetings will gain a 'Report a meeting' feature, allowing participants to flag suspicious activity like phishing or impersonation directly. This enhances threat intelligence for security teams.

The Impact

All Teams users are affected, gaining a new reporting capability that reduces social engineering risk.

  • End users: Can report suspicious meeting activity, reducing their risk of falling victim to social engineering.
  • Security teams: Gain a new source of threat intelligence for Teams meetings, improving incident response capabilities.
  • Administrators: Will need to understand the data flow and investigation paths for reported meetings.
  • Organisations: Enhanced ability to detect and respond to phishing and impersonation attempts within Teams.

The Action

  1. Review Microsoft Defender portal for new reporting data: Security.microsoft.com
  2. Communicate new reporting capability to end-users via internal security awareness campaigns.
  3. Update incident response playbooks to incorporate reported Teams meeting data.
  4. Verify appropriate roles have access to reported meeting data in Microsoft Defender.

Domain: Defender · Impact: medium · Workload: Microsoft Defender