Microsoft Teams: Users can report security concerns in group calls

🚨 The Signal: Teams users can now report suspicious group calls directly from call history. This enhances an organization's ability to detect and investigate potential scams, impersonation, and unwanted external calls, improving overall communication security posture.

The Impact

All Teams users are affected by a new reporting option, providing security teams with enhanced visibility into potential communication-based threats.

  • End Users: Gain a new capability to report suspicious group calls, improving their ability to contribute to organizational security.
  • Security Teams: Receive new telemetry for investigating potential scams and impersonation attempts within Teams group calls.
  • Administrators: Must configure Defender for Office 365 to fully leverage reported call data for investigation.
  • Organization: Enhanced ability to identify and respond to communication-based security incidents.

The Action

  1. Review Microsoft Defender for Office 365 licensing and configuration to ensure reported call data is ingested for analysis.
  2. Communicate the new 'Report a call' feature to end-users, including guidance on when and how to use it.
  3. Establish or update incident response playbooks to incorporate the investigation of reported Teams group calls.
  4. Monitor the Microsoft Teams admin center for reported call submissions and integrate findings into security operations.

Domain: Teams · Impact: medium · Workload: Teams