Loading...

Defender for Office 365 URL click alerts now include Microsoft Teams

Defender for Office 365 URL click alerts now include Microsoft Teams

Microsoft Defender for Office 365 URL click alerts will now include Microsoft Teams, enabling detection of malicious link clicks in Teams messages. This feature, rolling out from February to May 2026, enhances alert visibility and investigation in the Defender portal for licensed organizations, with no user workflow changes. We’re extending Microsoft Defender for Office 365 (MDO) URL click alerting to Microsoft Teams, giving security teams greater visibility into potentially malicious activity beyond email. By surfacing alerts when users click malicious or suspicious links in Teams messages, organizations can detect threats earlier, investigate faster, and respond more effectively—all from the Microsoft Defender portal. This message is associated with Microsoft Roadmap ID 557549. When this will happen: Public Preview (Worldwide): We will begin rolling out late February 2026 and expect to complete by early March 2026. General Availability (Worldwide): We will begin rolling out early March 2026 and expect to complete by mid-March 2026. General Availability (GCC, GCCH, DoD): We will begin rolling out early May 2026 and expect to complete by late May 2026. How this affects your organization: Who is affected: Organizations licensed for Microsoft Defender for Office 365 Plan 2 Organizations licensed for Microsoft 365 E5 Security admins and SOC teams monitoring alerts in the Microsoft Defender portal Users who send or receive Microsoft Teams messages containing URLs What will happen: Two existing MDO alerts will now also trigger for Microsoft Teams URL clicks, in addition to email: A user clicked through to a potentially malicious URL A potentially malicious URL click was detected Alerts will appear on the Defender alerts page alongside existing alerts. Alerts will include the associated Teams message as evidence, providing richer investigation context. Teams signals will be included in incident correlation, helping connect related activity across email and Teams. Incident pages will surface Teams message data directly, reducing the need to switch investigation contexts. Automated investigation and response (AIR) will not be supported for the Teams URL click alerts. The feature is enabled by default for eligible tenants. No changes are made to user workflows. What you can do to prepare: No action is […]

The post Defender for Office 365 URL click alerts now include Microsoft Teams appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Defender for Office 365 URL click alerts now include Microsoft Teams

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.