Microsoft Teams: Report a Message or an External User for Security Concern in Gov Clouds

🚨 The Signal: Government cloud users can now report suspicious Teams messages and external users. This provides security teams with new signals for phishing, impersonation, and spam, enhancing threat detection and response capabilities.

The Impact

All users and security teams are affected, reducing the risk of successful phishing and impersonation attacks.

  • End users: New capability to report suspicious messages.
  • Security teams: Enhanced visibility into potential Teams threats.
  • Admins: New reports to review in the Teams admin center.
  • Organisation: Improved detection of phishing and spam.

The Action

  1. Communicate new reporting capability to end-users.
  2. Review existing incident response playbooks for Teams threats.
  3. Integrate Teams admin center reports into security operations.
  4. Monitor Teams admin center for reported messages and users.

Domain: Teams · Impact: medium · Workload: Teams