MC1476237 - Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout

Microsoft 365 Message Center announcement MC1476237.

MS Message Center's Summary

Microsoft is updating the Teams message entity flyout in Defender for Office 365 plans one and two to combine message submissions and sender or domain blocking into a single workflow. The rollout begins in late September 2026 and concludes by mid October 2026. Administrators should update internal security operations guides and train staff on the new unified remediation wizard before the feature becomes active.

Administrator impact
No direct administrator action is required.
End user impact
No direct end user impact is expected.
Importance
3/10: This is a feature enhancement that improves security operations workflows without requiring tenant configuration changes.

Teams message entity panel in Microsoft Defender for Office 365

Microsoft Summary

Microsoft Defender for Office 365 will enhance the Teams message entity flyout by late September 2026, enabling security admins to submit messages to Microsoft and block senders or domains in one workflow. This streamlines Teams message investigations for Plan 1 and Plan 2 customers without requiring configuration changes.

Message Center ID
MC1476237
Category
stay Informed
Severity
normal
Services
Microsoft Defender XDR
Tags
Feature update, User impact, Admin impact
Published
2026-09-21
Last updated
2026-09-21
Expires
2026-11-12

[What and why] We are enhancing the Teams message entity flyout in Microsoft Defender for Office 365 to help security teams investigate and remediate malicious Teams messages more efficiently. Administrators will be able to submit messages to Microsoft and block external senders or associated domains from a single workflow, reducing the need to navigate between investigation experiences. [Rollout schedule] General Availability (Worldwide): Beginning in late September 2026 and expected to complete by mid-October 2026 [Impact on your organization] Who is affected Security administrators and analysts in organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2 who investigate Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine Platforms and services Microsoft Defender for Office 365 Microsoft Teams Microsoft Defender portal What will happen Administrators investigating Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine will be able to open the Teams message entity flyout and access the Take action workflow directly from the message. The updated action wizard will support the following actions: Submit to Microsoft: Submit the Teams message to Microsoft for review and analysis: Block sender: Add the external sender to the Tenant Allow/Block List (TABL). When available, sender information will be prepopulated to reduce manual entry. Block domain: Add one or more domains associated with the investigated message to TABL. The wizard will identify and prepopulate domains associated with an external sender, allowing administrators to select the domains to block. Administrators can perform multiple actions in a single workflow. For example, they can submit a message to Microsoft while also blocking the associated sender or domain. These actions will be available to Microsoft Defender for Office 365 Plan 1 and Plan 2 customers. Existing investigation experiences and workflows will remain available. No configuration changes are required for this capability. [Action required and recommendations] No action is required before rollout. We recommend that organizations: Review internal security operations procedures for Teams message investigations. Update administrator training materials and documentation to include the new remediation actions available from the Teams message entity flyout. Inform security operations teams about the streamlined investigation and remediation workflow. Learn more [To be updated closer to launch.] Teams message entity panel in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn [Compliance considerations] No compliance considerations were identified in the source content. Review this change as appropriate for your organization.