Microsoft Defender for Office 365: Teams user reporting enabled by default
🚨 The Signal: Microsoft Defender for Office 365 will automatically enable user reporting for suspicious messages, calls, and meetings in Microsoft Teams. This enhances threat detection and response capabilities by leveraging user-submitted intelligence against phishing, spam, and malicious content.
The Impact
Teams users and security administrators are affected, improving the organisation's ability to detect and respond to phishing and other malicious content.
- Teams users: Can report suspicious content, improving threat intelligence.
- Security administrators: Gain more threat reports for analysis and response.
- Organisation: Improved detection of phishing, spam, and malicious content.
- Incident Response: Faster identification and remediation of Teams-based threats.
The Action
- Review existing Teams user-reported settings in Microsoft Defender portal (if configured).
- Familiarise with the new dedicated Teams user-reported settings page in Microsoft Defender portal post-October 2026.
- Communicate to Teams users how to report suspicious messages, calls, and meetings.
- Integrate user-reported Teams incidents into existing security operations workflows.
Domain: Defender · Impact: medium · Workload: Microsoft Defender