Microsoft Defender for Office 365 · Teams user reporting
Teams user reporting turns on by default starting October 25 in tenants that left it unconfigured. Decide who reads the reports first.
A report option in Teams turns every employee into an early warning. Someone flags the strange chat or the help desk call that felt wrong, and your security team gets an alert for it. Microsoft says that in tenants that have left Teams user-reported settings unconfigured, Teams user reporting switches on by default beginning October 25, 2026. Microsoft's default destination sends each report to Microsoft and to a reporting mailbox, and Microsoft Learn says the default reporting mailbox is the global admin's.
- Beginning October 25, 2026: on by default for licensed tenants that have left the settings unconfigured, per Microsoft 365 Message Center post MC1478463
- October 7, 2026: the settings move to their own page in the Microsoft Defender portal, and changes made after the move may take until the week of October 15 to apply
- In scope for commercial Microsoft 365 tenants licensed for Defender for Office 365 Plan 1 or Plan 2, and Microsoft includes Plan 1 in Microsoft 365 Business Premium and, since July 1, 2026, Office 365 E3 and Microsoft 365 E3
The change
What is Microsoft changing about Teams user reporting in October?
Reporting in Teams runs on two settings, one in the Teams admin center and one in the Microsoft Defender portal. Microsoft moves the Defender side to its own page on October 7 and begins switching reporting on by default on October 25 for tenants that have left it unconfigured.
Two settings, two portals
The Teams admin center setting is on by default. The Defender portal setting, Monitor reported items in Microsoft Teams, is on by default for new tenants, and Microsoft Learn says existing tenants need to enable it.
A dedicated settings page
Teams user-reported settings move to their own page in the Microsoft Defender portal. Microsoft says settings you have already configured carry over.
Late changes catch up
Microsoft says changes made after the migration may take until the week of October 15, 2026 to show up. Settings made before October 7 avoid the wait.
On by default
Where Teams user-reported settings were left unconfigured, Microsoft begins switching Teams user reporting on from this date, unless the tenant opts out.
"Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft."
Microsoft 365 Message Center post MC1478463, Microsoft Defender for Office 365: Teams user reporting enabled by default, published September 24, 2026Microsoft lists the rollout for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5, beginning in late October 2026 and expected to complete by late October 2026. Microsoft's service description adds that Plan 1 is included in Microsoft 365 Business Premium and, effective July 1, 2026, in Office 365 E3 and Microsoft 365 E3. Institutions on those plans are in scope in commercial Microsoft 365, and Microsoft Learn lists Teams reporting as unavailable in Microsoft 365 GCC, GCC High, and DoD.
What users see is simple. In the Teams desktop client and the Teams web app, a message's More options menu carries Report this message, and call history carries Report call. The Teams apps for iPhone, iPad, and Android report messages. Microsoft's post describes reporting of suspicious messages, calls, and meetings, and Microsoft Learn covers messages in chats, channels, and meeting conversations, plus calls.
Reporting is the easy part. The decisions are where a report goes, who reads it, and what travels with it to Microsoft. ABT recommends settling them before October 7, so they carry over to the new page.
The decision
Where does a reported Teams message go, and who sees it?
Microsoft offers three destinations for reported items. The choice sets who sees a report first and what Microsoft receives.
The destination lives in the Reported items destinations section of the User reported settings page in the Microsoft Defender portal, and from October 7 on the dedicated Teams page. Microsoft's own default is Microsoft and my reporting mailbox. Microsoft explains the choice: reporting items to Microsoft is an important part of training the service to improve the accuracy of filtering, cutting both false positives and false negatives.
| Microsoft and my reporting mailbox (Microsoft's default) | My reporting mailbox only | Microsoft only | |
|---|---|---|---|
| Who receives the report | Microsoft, for analysis, and your reporting mailbox | Your reporting mailbox | Microsoft, for analysis |
| Microsoft's analysis | Automatic, on every report | When an admin submits an item from the User reported tab; Microsoft says submission of Teams messages to Microsoft is in Preview | Automatic, on every report |
| What goes to Microsoft | For a message: its content, headers, attachments, and routing metadata, plus up to fifteen messages before and after. For a call: the call metadata. | Only the items an admin submits | For a message: its content, headers, attachments, and routing metadata, plus up to fifteen messages before and after. For a call: the call metadata. |
| Your security team's copy | In the reporting mailbox | In the reporting mailbox | Reports skip the mailbox |
| User reported tab and alerts in the Defender portal | Included | Included | Included |
| Good fit when | You want Microsoft's analysis and your own copy of every report | Your compliance review wants a person to decide each submission, and your portal offers submission of Teams messages to Microsoft | Your security team works from the Defender portal and its alerts |
Microsoft's default reporting mailbox belongs to your global admin.
Microsoft Learn puts it in one line: the default user reporting mailbox is the Exchange Online mailbox of the global admin. Ask who reads that mailbox, and how often. If your global admin accounts are kept free of mailboxes, confirm in the portal where reports land today.
A mailbox your security team works from every day is the better home for reports. Microsoft lists the requirements: one Exchange Online mailbox, since distribution groups, external mailboxes, and on-premises mailboxes are ruled out; identified as a SecOps mailbox in the advanced delivery policy, so reported messages arrive unfiltered; and, if you use data loss prevention, excluded from those policies. If you run Attack simulation training or another phishing simulation product, the SecOps setting matters twice: Microsoft notes that a user reported message might otherwise trigger a training assignment.
What a report carries
What does a Teams report send to Microsoft?
Microsoft documents exactly what travels with a report. It belongs in the written destination decision in step 3 below.
The item itself
For a message, its content, headers, attachments, and routing metadata. For a call, the call metadata. Microsoft says all data directly associated with the item is copied.
Up to fifteen messages before and after
Microsoft says up to fifteen messages before and after the reported message might also be shared for analysis, as context for the report.
Microsoft staff may read it
Microsoft personnel might read submitted messages, calls, and files. Microsoft notes this is typically not permitted for Teams items in Microsoft 365, and a report is the exception.
Stored in the USA while it's needed
Submitted content is stored in secured, compliance-audited data centers located in the USA, and Microsoft says it keeps that content only as long as it's required.
"Microsoft treats this feedback as your organization's authorization to analyze the submitted information to improve hygiene algorithms."
Microsoft Learn, User reported settings in Microsoft Teams, last updated September 21, 2026The same Microsoft page says the submission remains confidential between your organization and Microsoft during the review process, and it sets out how Microsoft limits the use of customer data to train generative AI foundation models. Read those lines with your privacy officer. They are part of the decision.
For a credit union, bank, or mortgage company, a Teams chat can hold member or borrower details, so the fifteen-message context is the line to weigh. My reporting mailbox only sends reports to your mailbox and leaves submission to Microsoft to an admin. Microsoft Learn says they go to Microsoft only if an admin submits them from the User reported tab, and Microsoft says submission of Teams messages to Microsoft "is currently in Preview, isn't available in all organizations, and is subject to change." The other two destinations send each report automatically, which is how Microsoft's filtering learns from your users.
Find out where your tenant's Teams reports are set to go before October 25
ABT checks both reporting settings, the destination, the reporting mailbox, and who receives the alerts in your Microsoft 365 tenant, as part of a free security assessment.
Request the free assessmentThe short list
What should an administrator settle before October 7?
Seven steps. Settings in place before October 7 carry over to the new page. Changes made after the move may take until the week of October 15 to apply, which still lands ahead of the October 25 default.
Read the Teams side of the setting
In the Teams admin center, open Settings & policies. On the Global (Org-wide) default and each custom messaging policy, find Report a security concern. Under Messaging settings, Messaging safety, find Report incorrect security detections. Under Calling settings, General, find Report a call. Microsoft says the Teams side is on by default, so record any policy where someone switched it off. Viewing or changing these takes the Teams Administrator or Global Administrator role.
Read the Defender side
In the Microsoft Defender portal, go to Settings, then Email & collaboration, then User reported settings, and find Monitor reported items in Microsoft Teams in the Microsoft Teams section. Changing it takes membership in the Organization Management or Security Administrator role groups. Write down its state and the current destination today. That record is your baseline for the October changes.
Choose the destination with your compliance officer
Put the three destinations in front of your privacy or compliance officer and your security lead together. The trade is Microsoft's analysis, which Microsoft says improves its filtering, against what a report carries to Microsoft: the item, up to fifteen messages before and after it, and the possibility that Microsoft personnel read it. Record the choice and the reason. Any of the three can be the right choice. Before you pick mailbox-only, check that your portal lets an admin submit Teams items to Microsoft, because Microsoft says submission of Teams messages to Microsoft is in Preview and isn't available in all organizations. A written decision is far easier to explain later than an inherited default.
Give reports a mailbox your security team reads
If your destination includes a reporting mailbox, replace the global admin default with one Exchange Online mailbox that belongs to security operations. Identify it as a SecOps mailbox in the advanced delivery policy, exclude it from data loss prevention if you use it, and give one person the job of reading it every business day.
Route the four alerts
Microsoft ships four alert policies that fire by default when users report Teams items: Teams message reported by user as a security risk, Teams message reported by user as a not security risk, Teams call reported by user as a security risk, and Teams call reported by user as a not security risk. Check who receives them and how quickly someone looks. A reported help desk impersonation call deserves an answer the same day, and our guide to the first 24 hours after an impersonation email shows what that response looks like on the email side.
Show your staff the two buttons
Teach Report this message from a message's More options menu and Report call from call history. Microsoft Learn says senders and callers aren't told they were reported, the item stays visible to the user, and the same item can be reported more than once. Teams also lets users report a suspicious external person while blocking them, and Microsoft Learn says those person reports are still outside Microsoft Defender, so message and call reports are what your security team sees. Pair the lesson with the pattern Microsoft sees most in Teams attacks, someone posing as the IT help desk and warning that an account is about to be locked, which our breakdown of the Teams help desk impersonation attack chain walks through stage by stage.
Test it once and keep the record
Before October 25, have a volunteer report a test message and a test call. Check four outcomes separately: the item appears on the User reported tab of the Submissions page, the alert fires, the alert notification reaches the person who triages, and, if your destination includes a mailbox, the mailbox receives its copy. File the dated results with the destination decision from step 3.
Read the sources in two minutes
Open Message Center post MC1478463 in your Microsoft 365 admin center. Then read Microsoft Learn's User reported settings in Microsoft Teams, last updated September 21, 2026, and User reported settings for the reporting mailbox requirements.
For credit unions, banks, and mortgage companies
Why does Teams reporting matter at a financial institution?
Teams is where your staff get work done, and Microsoft's own data shows attackers calling them there.
Start with the productive version. The loan team clears a condition in a chat, a branch pings operations about a member's card, and a vendor joins a meeting from outside the tenant. A report option puts the people doing that work on your security team's side of the table, one click from the message that looked wrong.
Microsoft's Q2 2026 email threat report puts numbers on the risk. In Microsoft's words, vishing through Teams showed the steepest growth of any threat category tracked in the report during Q2. Average weekly malicious call attempts rose 31% from April to May and another 27% into June, and since the beginning of 2026 weekly vishing attempts have increased roughly 80% and now run at nearly ten times the mid-2025 baseline. Those figures count calls. Microsoft reports Teams-based phishing messages separately: up 19% from March to April, 1% into May, and 10% into June. The dominant lure remained technical support impersonation: attackers posing as an employee's IT help desk, warning of an impending account lockout.
Two more findings explain why a person's report matters. Microsoft notes that Teams traffic typically bypasses secure email gateways, and that for the second consecutive month more than half, 52%, of Teams-based phishing attacks in June used generic display names in place of obvious IT support names. The lures look more ordinary each month, and the employee who says "that call felt wrong" can be the first signal your security team gets. Our analysis of Microsoft's Q2 2026 Teams vishing data covers the rest of the report.
What protects Teams at each license level
User reporting is one of several Teams protections that arrive with Defender for Office 365. Microsoft Learn's feature table, last updated September 21, 2026, splits them this way.
Every Teams license
Built into Microsoft 365
- Built-in virus protection in SharePoint, OneDrive, and Teams
- The Teams external domain anomalies report
- Near real-time warnings on malicious URLs in Teams messages, up to 48 hours after delivery
Defender for Office 365 Plan 1
In Business Premium, Office 365 E3, and Microsoft 365 E3
- User-reported Teams items
- Safe Links and Safe Attachments at time of click
- Zero-hour auto purge (ZAP) for Teams, with admin-managed quarantine
- Tenant Allow/Block List for domains, URLs, and files
- Teams message and call entity panels for investigation
Defender for Office 365 Plan 2
In Microsoft 365 E5 and Office 365 E5
- Everything in Plan 1
- Removing users from Teams chats as an admin remediation
- Advanced hunting on Teams messages
If your institution runs Microsoft 365 E3 and wants the Plan 2 tools without a full E5 move, our page on Microsoft 365 E3 security add-ons lays out the step up. Teams settings beyond reporting, from guest access to retention, are covered in our guide to Teams governance for financial institutions.
Why does a person's report matter when the sign-in page is real?
A real Microsoft sign-in page can sit at the end of a fake invitation. Microsoft Threat Intelligence described one such attack in February 2025: Storm-2372 generated a legitimate device code request and tricked targets into entering it into a legitimate sign-in page. Its lures resembled messaging apps including WhatsApp, Signal, and Microsoft Teams, and its phishing emails were dressed as Teams meeting invitations.
The Short from our channel walks through that pattern: the victim signs in on the real portal and completes the real multifactor prompt. Microsoft's guidance for device code phishing is to block device code flow wherever possible, and that control belongs in place first. Where a lure still reaches someone, the person who says "that meeting invite was strange" is part of your detection, and the report option is how that observation reaches your security team.
How ABT helps
A free security assessment
ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 financial institutions, and the Teams reporting check is part of this assessment.
We show you where your Teams reports are set to go today, and what to set before October 7
The assessment is free and ends with written findings you keep. We work through your reporting settings with an administrator on your team, and your team decides what changes in the tenant and who makes each change.
- The reporting settings, both portals. The Teams admin center policies and the Defender portal setting, recorded as they stand today.
- The destination brief. The three destinations laid out for your compliance officer, with what each one sends and to whom.
- The reporting mailbox. One mailbox for security operations, with its advanced delivery and data loss prevention settings.
- The alert path. Who receives the four Teams report alerts, and how quickly someone looks.
- The wider Teams picture. External access, Safe Links, and ZAP for Teams, measured by what each setting does in your tenant.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian
Related reading
If this opened a bigger question
Teams reporting sits between your phishing defenses, your help desk process, and your Defender for Office 365 configuration. These three pick up each thread.
Microsoft's Q2 2026 Threat Data on Teams Vishing
What Microsoft's April to June 2026 report says about Teams calls, generic display names, and business email compromise.
Read the analysis
Teams Help Desk Impersonation: The 9-Stage Attack Chain
How a fake IT support chat becomes an intrusion, and the Teams settings that break the chain at each stage.
Read the guide
Defender for Office 365 Anti-Phishing for Financial Institutions
The six anti-phishing controls to verify in Defender for Office 365, and a 30-day plan to roll them out.
Read the guideAnswered
Teams user reporting, answered
Verify it yourself
Where the facts on this page come from
Every Microsoft date, figure, and quotation above was read from the Microsoft sources listed here on September 25, 2026.
- Microsoft 365 Message Center post MC1478463, Microsoft Defender for Office 365: Teams user reporting enabled by default, plan for change, major change, published September 24, 2026. Source for the October 25, 2026 default, the opt-out, the dedicated Defender portal page from October 7, 2026, settings carrying over, changes after migration taking until the week of October 15, 2026, the licensing line, the late October rollout, and the recommendation to review settings before October 25. Visible to administrators in your own Microsoft 365 admin center.
- Microsoft Learn, User reported settings in Microsoft Teams, last updated September 21, 2026. Source for what users can report and on which clients, the two separate settings and their defaults, the Teams admin center toggles, what a report sends to Microsoft, the fifteen-message context, Microsoft personnel reading submissions, USA storage, the three destinations and the global admin default mailbox, the four alert policies, sender and caller notification, shared channels, and the U.S. Government cloud exclusion.
- Microsoft Learn, User reported settings, last updated August 7, 2026. Source for the reporting mailbox requirements: an Exchange Online mailbox, the SecOps mailbox setting in the advanced delivery policy, the data loss prevention exclusion, the phishing simulation training assignment note, and manual submission to Microsoft from the Submissions page.
- Microsoft Learn, Submit messages, URLs, and attachments for analysis in the Microsoft Defender portal, last updated July 30, 2026. Source for admin submission of user-reported Teams messages from the User reported tab, Microsoft's note that submission of Teams messages to Microsoft is in Preview, isn't available in all organizations, and is subject to change, and the Not Submitted to Microsoft result for mailbox-only reports.
- Microsoft Learn, End user reporting for Security (Microsoft Teams), last updated July 28, 2026. Source for reporting a suspicious external person while blocking them, and those person reports sitting outside Microsoft Defender.
- Microsoft Learn, Microsoft Defender for Office 365 support for Microsoft Teams, last updated September 21, 2026. Source for the Teams protection features by license level.
- Microsoft Learn, Microsoft Defender for Office 365 service description, last updated July 17, 2026. Source for Plan 1 being included in Microsoft 365 Business Premium and, effective July 1, 2026, in Office 365 E3 and Microsoft 365 E3.
- Microsoft Security Blog, Email threat landscape: Q2 2026 trends and insights, July 23, 2026. Source for the Teams vishing growth figures, the separate Teams phishing figures, the mid-2025 baseline comparison, the help desk impersonation lure, the 52% generic display name finding, and Teams traffic bypassing secure email gateways.
- Microsoft Security Blog, Storm-2372 conducts device code phishing campaign, February 13, 2025. Source for device code phishing through a legitimate sign-in page, the Teams-style lures, and Microsoft's recommendation to block device code flow wherever possible.
A reported Teams call is an early warning.
Make sure it reaches someone.
Deciding where Teams reports go is a short piece of work before October 7. Once it is settled, reports land with the people you chose to receive them.
Tell us a little about your environment and we will come back with what we would check first.
What should we look at? Optional.
Encrypted. Private.
Thank you. That is with us.
An ABT specialist will be in touch shortly. If you want the settings in place before October 7, say so in your reply and we will move it to the front.

