Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout

🚨 The Signal: Microsoft Defender for Office 365 now allows security teams to directly block malicious Teams message senders and domains from the message flyout. This streamlines incident response for Teams-based threats, improving efficiency and reducing navigation.

The Impact

Security analysts are affected, gaining streamlined tools to block malicious Teams senders, reducing the risk of successful phishing or malware delivery.

  • Security Analysts: Faster remediation of malicious Teams messages.
  • Security Administrators: Centralised workflow for blocking external threats.
  • Organisations: Reduced exposure to Teams-borne phishing and malware.
  • Incident Responders: Improved efficiency in threat containment.

The Action

  1. Review existing incident response playbooks for Teams to incorporate the new direct remediation actions.
  2. Train security operations centre (SOC) staff on the enhanced 'Take action' workflow within the Teams message entity flyout in Microsoft Defender for Office 365.
  3. Monitor the Tenant Allow/Block List (TABL) for entries added via this new capability to ensure proper management.
  4. Verify that security administrators have the necessary permissions to perform block actions in Microsoft Defender for Office 365.

Domain: Defender · Impact: medium · Workload: Microsoft Defender