MC1478463 - Microsoft Defender for Office 365: Teams user reporting enabled by default

Microsoft 365 Message Center announcement MC1478463.

MS Message Center's Summary

Microsoft Defender for Office 365 will enable user reporting for Teams by default in late October 2026 for eligible organisations. This feature allows users to report suspicious messages, calls, and meetings to improve threat detection. Administrators should review their configuration settings in the Microsoft Defender portal before October 25, 2026, to ensure that the default behaviour aligns with corporate policy, or to opt out if necessary.

Administrator impact
Administrators must review and configure Teams reporting settings in the Microsoft Defender portal before the change takes effect.
End user impact
Users gain the ability to report suspicious Teams messages, calls, and meetings directly for security analysis.
Importance
6/10: This change modifies default security behaviour and introduces new reporting capabilities that affect user interfaces and administrative workflows.

User reported settings in Teams Microsoft Defender for Office 365 Microsoft Learn

Microsoft Summary

Microsoft Defender for Office 365 will enable Teams user reporting by default starting late October 2026 for licensed organizations. Users can report suspicious Teams content to improve threat detection. Admins can review or opt out via a dedicated Defender portal page before October 25, 2026.

Message Center ID
MC1478463
Category
plan For Change
Severity
normal
Services
Microsoft Defender XDR
Tags
User impact, Admin impact
Published
2026-09-24
Last updated
2026-09-24
Expires
2026-11-30

[What and why] To help organizations identify and respond to security threats in Microsoft Teams, Microsoft Defender for Office 365 will enable Teams user reporting by default. Users can report suspicious messages, calls, and meetings, helping organizations improve detection of phishing, spam, impersonation, malicious content, and other threats. This capability is available for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5. [Rollout schedule] General Availability (Worldwide): Beginning in late October 2026 and expected to complete by late October 2026 [Impact on your organization] Who is affected Organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5 Microsoft Teams and security administrators Teams users in affected organizations Platforms/Services Microsoft Teams Microsoft Defender portal Microsoft Defender for Office 365 What will happen Users can report suspicious messages, calls, and meetings directly from Teams. Reported content is submitted per your configured reported destination for security analysis. Security risk items can include phishing, spam, impersonation, malicious content, and phishing URLs. Beginning October 7, 2026 , Teams user-reported settings will be managed on a dedicated page in the Microsoft Defender portal. If you have already configured Teams user-reported settings, your existing settings will be carried over. Changes made after migration may not be reflected until the week of October 15, 2026. If you have not already configured Teams user-reported settings, Teams user reporting will be enabled by default beginning October 25, 2026, unless you opt out. Image 1 - Teams user reported settings view: Image 2 - Email user reported settings view: [Action required/Recommendations] Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft. Recommended actions: Review Teams user-reported settings in the Microsoft Defender portal. Decide whether user-reported Teams content should be submitted to Microsoft for security analysis. Opt out before October 25, 2026, if desired. Inform security administrators and help desk staff about this change. Learn More Email user-reported settings: security.microsoft.com/securitysettings/userSubmission Teams user-reported settings: security.microsoft.com/securitysettings/teamsUserSubmission User reported settings in Teams - Microsoft Defender for Office 365 | Microsoft Learn [Compliance considerations] Question Answer Does the change alter how admins can monitor, report on, or demonstrate compliance activities? Teams user-reported settings will move to a dedicated configuration page in the Defender portal. Does the change include an admin control, and can it be controlled through Entra ID group membership? Administrators can opt out by configuring Teams user-reported settings in the Defender portal. Group-based controls are not specified.