MC1476237: Microsoft Defender for Office 365 Adds Remediation Actions to Teams Message Flyout

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
37
0 25 50 75 100
MODERATE IMPACT • ASSESS BUSINESS IMPACT
Recommended Action:
Take a look and decide whether this affects your tenant, users or support teams.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Security TeamsMicrosoft 365 AdminsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This update adds new remediation actions in the Teams message entity flyout within Microsoft Defender for Office 365. It affects security operations by allowing admins to submit messages and block senders or domains more efficiently, improving investigation workflows. No immediate configuration changes are required, but procedures and training documents may need revision. End users are unaffected as this is an admin-facing enhancement.
46
🛡️ Admin Impact
15
👥 User Impact
40
Urgency
35
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Security admins can now take remediation actions, like submitting messages or blocking senders/domains, directly from the Teams message flyout in Defender for Office 365.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review security workflows, update training docs, and inform your security teams about the new actions.
📅

ROLLOUT TIMELINE

Start:
Late September 2026

📢 Official Microsoft Message Center Announcement


Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout
Message ID: MC1476237

[What and why]

We are enhancing the Teams message entity flyout in Microsoft Defender for Office 365 to help security teams investigate and remediate malicious Teams messages more efficiently. Administrators will be able to submit messages to Microsoft and block external senders or associated domains from a single workflow, reducing the need to navigate between investigation experiences.

[Rollout schedule]

  • General Availability (Worldwide): Beginning in late September 2026 and expected to complete by mid-October 2026

[Impact on your organization]

Who is affected

  • Security administrators and analysts in organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2 who investigate Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine

Platforms and services

  • Microsoft Defender for Office 365
  • Microsoft Teams
  • Microsoft Defender portal

What will happen

Administrators investigating Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine will be able to open the Teams message entity flyout and access the Take action workflow directly from the message.

The updated action wizard will support the following actions:

  • Submit to Microsoft: Submit the Teams message to Microsoft for review and analysis:
  • 21878 2
  • Block sender: Add the external sender to the Tenant Allow/Block List (TABL). When available, sender information will be prepopulated to reduce manual entry.
  • Block domain: Add one or more domains associated with the investigated message to TABL. The wizard will identify and prepopulate domains associated with an external sender, allowing administrators to select the domains to block.
  •  21878 1

Administrators can perform multiple actions in a single workflow. For example, they can submit a message to Microsoft while also blocking the associated sender or domain.

These actions will be available to Microsoft Defender for Office 365 Plan 1 and Plan 2 customers. Existing investigation experiences and workflows will remain available. No configuration changes are required for this capability.

[Action required and recommendations]

No action is required before rollout.

We recommend that organizations:

  • Review internal security operations procedures for Teams message investigations.
  • Update administrator training materials and documentation to include the new remediation actions available from the Teams message entity flyout.
  • Inform security operations teams about the streamlined investigation and remediation workflow.

Learn more

[Compliance considerations]

No compliance considerations were identified in the source content. Review this change as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update