MC1478463: Microsoft Defender for Office 365 Enables Teams User Reporting by Default

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
60
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsSecurity TeamsCompliance TeamsTeams AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The feature introduces a default-on setting for Teams user reporting, requiring admins to review and potentially change settings to control reporting behaviour and data destinations. Security and Teams admins need to prepare before the default enablement date and inform helpdesk teams. Users gain new reporting options, but the impact on their workflow is moderate. Urgency is high due to an opt-out deadline in late October and configuration work needed in the Defender portal.
70
🛡️ Admin Impact
35
👥 User Impact
65
⚡ Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Teams user reporting will be turned on by default for Defender for Office 365 customers to help identify suspicious messages, calls and meetings. Review settings if you do not want this enabled automatically.
👥

END USERS

Users may see an option in Teams to report suspicious messages, calls or meetings.
🛡️

IT ADMINS

Check Teams user-reported settings in the Defender portal and opt out or adjust destinations before October 25, 2026.
📅

ROLLOUT TIMELINE

Upcoming:
Late October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender for Office 365: Teams user reporting enabled by default
Message ID: MC1478463

[What and why]

To help organizations identify and respond to security threats in Microsoft Teams, Microsoft Defender for Office 365 will enable Teams user reporting by default. Users can report suspicious messages, calls, and meetings, helping organizations improve detection of phishing, spam, impersonation, malicious content, and other threats.

This capability is available for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5.

[Rollout schedule]

  • General Availability (Worldwide): Beginning in late October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5
  • Microsoft Teams and security administrators
  • Teams users in affected organizations

Platforms/Services

  • Microsoft Teams
  • Microsoft Defender portal
  • Microsoft Defender for Office 365

What will happen

  • Users can report suspicious messages, calls, and meetings directly from Teams. Reported content is submitted per your configured reported destination for security analysis.
  • Security risk items can include phishing, spam, impersonation, malicious content, and phishing URLs.
  • Beginning October 7, 2026, Teams user-reported settings will be managed on a dedicated page in the Microsoft Defender portal. 
  • If you have already configured Teams user-reported settings, your existing settings will be carried over. Changes made after migration may not be reflected until the week of October 15, 2026.
  • If you have not already configured Teams user-reported settings, Teams user reporting will be enabled by default beginning October 25, 2026, unless you opt out. 

Image 1 – Teams user reported settings view:  

22004 1

Image 2 – Email user reported settings view:

22004 2

[Action required/Recommendations]

Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft.

Recommended actions:

  • Review Teams user-reported settings in the Microsoft Defender portal.
  • Decide whether user-reported Teams content should be submitted to Microsoft for security analysis.
  • Opt out before October 25, 2026, if desired.
  • Inform security administrators and help desk staff about this change.

Learn More

[Compliance considerations]

QuestionAnswer
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Teams user-reported settings will move to a dedicated configuration page in the Defender portal.
Does the change include an admin control, and can it be controlled through Entra ID group membership?Administrators can opt out by configuring Teams user-reported settings in the Defender portal. Group-based controls are not specified.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update