Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1
Microsoft Defender for Office 365 Plan 1 will allow users to report suspicious Teams messages as security risks or false positives starting mid-February 2026. Reports appear in the Defender portal, with opt-in settings and automatic Teams admin toggles. Organizations should enable user reporting and update guidance accordingly. Introduction We’re expanding the ability for users to report suspicious Microsoft Teams messages to customers with Microsoft Defender for Office 365 Plan 1. Previously available only to Plan 2, this update helps security teams identify and investigate potential phishing, malware, and spam across internal and external Teams chats, channels, and meeting chats. This enhancement strengthens protection by incorporating user-reported signals into existing Defender detections. Users will be able to report messages in two ways: Report as security risk — for messages suspected to contain phishing, malware, or other malicious content. Report as not a security risk — for messages that were incorrectly identified as threats (false positives). This message is associated with Microsoft 365 Roadmap ID 531760. When this will happen General Availability (Worldwide): Rollout begins in mid-February 2026 and is expected to complete in mid-February 2026. How this affects your organization Who is affected: Microsoft 365 tenants using Microsoft Defender for Office 365 Plan 1 Users across Microsoft Teams Security admins reviewing reported messages What will happen: What you can do to prepare Enable and configure User reported settings in the Defender portal. Review message reported destination preferences for reported messages. Communicate reporting guidance to users. Review supporting documentation. Update internal documentation as needed. Learn more: Users will see options to report messages as security risks or not security risks. Reports will appear on the User reported page in the Defender portal and/or your configured mailbox. This feature is opt-in and respects your existing User reported settings. Teams admin center toggles for reporting will be automatically enabled when User reported settings are turned on. How your submissions to Defender for Office 365 are processed behind-the-scenes | Microsoft Defender for Office 365 Blog Turn off or turn on user reporting of Teams messages in the Defender portal | Microsoft Learn User reported message settings in […]
The post Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1 appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...
Outlook for iOS: Minimum system requirements updated to iOS 26 and above
Outlook for iOS will require iOS 26 or later starting mid-September 2026, supporting only the two latest iOS, iPadOS, and watchOS versions. Us...
Allow connections to copilot.cloud.microsoft before the Copilot URL redirect
Starting September 2026, Microsoft will redirect users from m365.cloud.microsoft to copilot.cloud.microsoft. Organizations must ensure network...
Prepare for the removal of WMIC from Windows 11
The Windows Management Instrumentation command-line (WMIC) utility has been removed from Windows 11, version 24H2 and later. It’s no longer av...
Microsoft Agent 365: Active Users export for agent usage reporting
Microsoft Agent 365 will add an Active Users export in the Microsoft 365 admin center, allowing AI and Global Admins to generate a CSV report ...
The August 2026 Windows non-security preview update is now available
The August 2026 non-security preview update is now available for Windows 11, versions 26H1, 25H2, and 24H2. Information about the contents of ...
Dynamics 365 Project Operations – Assign task level schedule mode for precise planning
We are announcing the ability to assign task level schedule mode for precise planning in Dynamics 365 Project Operations. This feature will re...