MC1478463: Microsoft Defender for Office 365 Enables Teams User Reporting by Default

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
61
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
▶ What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsSecurity TeamsCompliance TeamsTeams AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
The update introduces default enablement of Teams user reporting for Defender for Office 365 tenants starting in late October 2026. Admins need to review reporting settings and decide whether to opt out or direct submissions to a specific destination, requiring configuration and communication with security teams. Users will gain new reporting options in Teams but with limited workflow disruption. The deadline-driven default activation makes this moderately urgent for security and Teams administrators.
70
🛡️ Admin Impact
40
👥 User Impact
65
⚡ Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Teams user reporting in Microsoft Defender for Office 365 will soon be turned on by default. It helps identify and respond to suspicious Teams content such as phishing or spam.
👥

END USERS

Users may see a new option to report suspicious messages, calls, or meetings in Teams.
🛡️

IT ADMINS

Review Teams user-reported settings in the Defender portal and opt out before 25 October 2026 if needed.
📅

ROLLOUT TIMELINE

Upcoming:
Late October 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender for Office 365: Teams user reporting enabled by default
Message ID: MC1478463 (Updated)

[What and why]

To help organizations identify and respond to security threats in Microsoft Teams, Microsoft Defender for Office 365 will enable Teams user reporting by default. Users can report suspicious messages, calls, and meetings, helping organizations improve detection of phishing, spam, impersonation, malicious content, and other threats.

This capability is available for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5.

[Rollout schedule]

  • General Availability (Worldwide): Beginning in late October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5
  • Microsoft Teams and security administrators
  • Teams users in affected organizations

Platforms/Services

  • Microsoft Teams
  • Microsoft Defender portal
  • Microsoft Defender for Office 365

What will happen

  • Users can report suspicious messages, calls, and meetings directly from Teams. Reported content is submitted per your configured reported destination for security analysis.
  • Security risk items can include phishing, spam, impersonation, malicious content, and phishing URLs.
  • Beginning October 7, 2026, Teams user-reported settings will be managed on a dedicated page in the Microsoft Defender portal. 
  • If you have already configured Teams user-reported settings, your existing settings will be carried over. Changes made after migration may not be reflected until the week of October 15, 2026.
  • If you have not already configured Teams user-reported settings, Teams user reporting will be enabled by default beginning October 25, 2026, unless you opt out. 

Image 1 – Teams user reported settings view:  

22004 1

Image 2 – Email user reported settings view:

22004 2

[Action required/Recommendations]

Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft.

Recommended actions:

  • Review Teams user-reported settings in the Microsoft Defender portal.
  • Decide whether user-reported Teams content should be submitted to Microsoft for security analysis.
  • Opt out before October 25, 2026, if desired.
  • Inform security administrators and help desk staff about this change.

Learn More

[Compliance considerations]

QuestionAnswer
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Teams user-reported settings will move to a dedicated configuration page in the Defender portal.
Does the change include an admin control, and can it be controlled through Entra ID group membership?Administrators can opt out by configuring Teams user-reported settings in the Defender portal. Group-based controls are not specified.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1478463] Archive
Tooltip: View earlier revisions of this post

Share This Update