check before: 2026-02-01
Product:
Defender, Defender for Office 365, Defender XDR, Microsoft 365 admin center, Teams
Platform:
Android, iOS, Linux, Mac, Online, Web, Windows Desktop, World tenant
Status:
In development
Change type:
New feature, User impact, Admin impact
Links:
Details:
Summary:
Microsoft Defender for Office 365 Plan 1 will allow users to report suspicious Teams messages as security risks or false positives starting mid-February 2026. Reports appear in the Defender portal, with opt-in settings and automatic Teams admin toggles. Organizations should enable user reporting and update guidance accordingly.
Details:
[Introduction]
We're expanding the ability for users to report suspicious Microsoft Teams messages to customers with Microsoft Defender for Office 365 Plan 1. Previously available only to Plan 2, this update helps security teams identify and investigate potential phishing, malware, and spam across internal and external Teams chats, channels, and meeting chats. This enhancement strengthens protection by incorporating user-reported signals into existing Defender detections.
Users will be able to report messages in two ways:
Report as security risk - for messages suspected to contain phishing, malware, or other malicious content.
Report as not a security risk - for messages that were incorrectly identified as threats (false positives).
This message is associated with Microsoft 365 Roadmap ID 531760.
[When this will happen]
General Availability (Worldwide): Rollout begins in mid-February 2026 and is expected to complete in mid-February 2026.
Change Category:
XXXXXXX ... free basic plan only
Scope:
XXXXXXX ... free basic plan only
Release Phase:
General Availability
Created:
2026-01-21
updated:
2026-01-21
Task Type
XXXXXXX ... free basic plan only
Docu to Check
XXXXXXX ... free basic plan only
MS How does it affect me
XXXXXXX ... free basic plan only
MS Preperations
XXXXXXX ... free basic plan only
MS Urgency
XXXXXXX ... free basic plan only
MS workload name
XXXXXXX ... free basic plan only
linked item details
XXXXXXX ... free basic plan only
summary for non-techies**
Starting in mid-February 2026, Microsoft Defender for Office 365 Plan 1 will allow users to report suspicious messages in Microsoft Teams, a feature previously exclusive to Plan 2, enabling organizations to enhance security by incorporating user feedback.
Direct effects for Operations**
User Reporting Feature Implementation
If the user reporting feature is enabled without proper training and communication, users may misuse the reporting function, leading to an increase in false reports and unnecessary investigations by security teams.
- roles: End Users, Security Admins
- references: https://learn.microsoft.com/defender-office-365/submissions-teams, https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/how-your-submissions-to-defender-for-office-365-are-processed-behind-the-scenes/4231551
Increased Security Team Workload
Without preparation, the influx of user-reported messages could overwhelm security teams, causing delays in addressing genuine threats and impacting overall security posture.
- roles: Security Admins, IT Operations
- references: https://learn.microsoft.com/defender-office-365/submissions-teams#turn-off-or-turn-on-user-reporting-of-teams-messages-in-the-defender-portal" target="_blank" rel="nofollow noopener noreferrer">https://learn.microsoft.com/defender-office-365/submissions-teams#turn-off-or-turn-on-user-reporting-of-teams-messages-in-the-defender-portal, https://www.microsoft.com/microsoft-365/roadmap?filters=&searchterms=531760
Configutation Options**
XXXXXXX ... paid membership only
IT Security**
XXXXXXX ... paid membership only
explanation for non-techies**
XXXXXXX ... free basic plan only
** AI generated content. This information must be reviewed before use.
a free basic plan is required to see more details. Sign up here
A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.
Last updated 2 weeks ago ago