Skip to the main content.

Microsoft Defender for Office 365 · Teams user reporting

Teams user reporting turns on by default starting October 25 in tenants that left it unconfigured. Decide who reads the reports first.

A report option in Teams turns every employee into an early warning. Someone flags the strange chat or the help desk call that felt wrong, and your security team gets an alert for it. Microsoft says that in tenants that have left Teams user-reported settings unconfigured, Teams user reporting switches on by default beginning October 25, 2026. Microsoft's default destination sends each report to Microsoft and to a reporting mailbox, and Microsoft Learn says the default reporting mailbox is the global admin's.

  • Beginning October 25, 2026: on by default for licensed tenants that have left the settings unconfigured, per Microsoft 365 Message Center post MC1478463
  • October 7, 2026: the settings move to their own page in the Microsoft Defender portal, and changes made after the move may take until the week of October 15 to apply
  • In scope for commercial Microsoft 365 tenants licensed for Defender for Office 365 Plan 1 or Plan 2, and Microsoft includes Plan 1 in Microsoft 365 Business Premium and, since July 1, 2026, Office 365 E3 and Microsoft 365 E3
Teams reporting October 2026
October 7
Settings get their own page
Configured settings carry over to the new Defender portal page
Week of October 15
Late changes catch up
Changes made after the move may apply from this week
From October 25
On by default
Unconfigured tenants get Teams user reporting switched on
Settle the settings before October 7
Nearly 10x
Weekly malicious Microsoft Teams call attempts reached nearly ten times the mid-2025 baseline by the end of June 2026.
Source: Microsoft Security Blog, Email threat landscape Q2 2026
Oct 25
The date Microsoft begins switching on Teams user reporting in licensed tenants that have left the settings unconfigured.
Source: Microsoft 365 Message Center, MC1478463
15
Up to fifteen messages before and after a reported Teams message might be shared with the report for analysis, Microsoft says.
Source: Microsoft Learn, User reported settings in Teams

What is Microsoft changing about Teams user reporting in October?

Reporting in Teams runs on two settings, one in the Teams admin center and one in the Microsoft Defender portal. Microsoft moves the Defender side to its own page on October 7 and begins switching reporting on by default on October 25 for tenants that have left it unconfigured.

Today

Two settings, two portals

The Teams admin center setting is on by default. The Defender portal setting, Monitor reported items in Microsoft Teams, is on by default for new tenants, and Microsoft Learn says existing tenants need to enable it.

October 7, 2026

A dedicated settings page

Teams user-reported settings move to their own page in the Microsoft Defender portal. Microsoft says settings you have already configured carry over.

Week of October 15

Late changes catch up

Microsoft says changes made after the migration may take until the week of October 15, 2026 to show up. Settings made before October 7 avoid the wait.

October 25, 2026

On by default

Where Teams user-reported settings were left unconfigured, Microsoft begins switching Teams user reporting on from this date, unless the tenant opts out.

"Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft."

Microsoft 365 Message Center post MC1478463, Microsoft Defender for Office 365: Teams user reporting enabled by default, published September 24, 2026

Microsoft lists the rollout for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5, beginning in late October 2026 and expected to complete by late October 2026. Microsoft's service description adds that Plan 1 is included in Microsoft 365 Business Premium and, effective July 1, 2026, in Office 365 E3 and Microsoft 365 E3. Institutions on those plans are in scope in commercial Microsoft 365, and Microsoft Learn lists Teams reporting as unavailable in Microsoft 365 GCC, GCC High, and DoD.

What users see is simple. In the Teams desktop client and the Teams web app, a message's More options menu carries Report this message, and call history carries Report call. The Teams apps for iPhone, iPad, and Android report messages. Microsoft's post describes reporting of suspicious messages, calls, and meetings, and Microsoft Learn covers messages in chats, channels, and meeting conversations, plus calls.

Reporting is the easy part. The decisions are where a report goes, who reads it, and what travels with it to Microsoft. ABT recommends settling them before October 7, so they carry over to the new page.

Timeline of the October 2026 Microsoft Teams user reporting change in Microsoft Defender for Office 365, with Microsoft branding. Today, two settings control reporting: the Teams admin center setting is on by default, and the Microsoft Defender portal setting Monitor reported items in Microsoft Teams is on by default for new tenants while existing tenants turn it on. October 7, 2026: Teams user-reported settings move to a dedicated page in the Microsoft Defender portal and configured settings carry over. Week of October 15, 2026: changes made after the move may apply from this week. October 25, 2026: Teams user reporting is on by default for tenants that left the settings unconfigured, unless they opt out.
Two settings today, a new settings page on October 7, and the default switch-on October 25. Decisions made before October 7 carry over.

Where does a reported Teams message go, and who sees it?

Microsoft offers three destinations for reported items. The choice sets who sees a report first and what Microsoft receives.

The destination lives in the Reported items destinations section of the User reported settings page in the Microsoft Defender portal, and from October 7 on the dedicated Teams page. Microsoft's own default is Microsoft and my reporting mailbox. Microsoft explains the choice: reporting items to Microsoft is an important part of training the service to improve the accuracy of filtering, cutting both false positives and false negatives.

The three destinations for user-reported Teams items. Source: Microsoft Learn, User reported settings in Microsoft Teams, last updated September 21, 2026, and User reported settings, last updated August 7, 2026.
  Microsoft and my reporting mailbox (Microsoft's default) My reporting mailbox only Microsoft only
Who receives the report Microsoft, for analysis, and your reporting mailbox Your reporting mailbox Microsoft, for analysis
Microsoft's analysis Automatic, on every report When an admin submits an item from the User reported tab; Microsoft says submission of Teams messages to Microsoft is in Preview Automatic, on every report
What goes to Microsoft For a message: its content, headers, attachments, and routing metadata, plus up to fifteen messages before and after. For a call: the call metadata. Only the items an admin submits For a message: its content, headers, attachments, and routing metadata, plus up to fifteen messages before and after. For a call: the call metadata.
Your security team's copy In the reporting mailbox In the reporting mailbox Reports skip the mailbox
User reported tab and alerts in the Defender portal Included Included Included
Good fit when You want Microsoft's analysis and your own copy of every report Your compliance review wants a person to decide each submission, and your portal offers submission of Teams messages to Microsoft Your security team works from the Defender portal and its alerts

Microsoft's default reporting mailbox belongs to your global admin.

Microsoft Learn puts it in one line: the default user reporting mailbox is the Exchange Online mailbox of the global admin. Ask who reads that mailbox, and how often. If your global admin accounts are kept free of mailboxes, confirm in the portal where reports land today.

A mailbox your security team works from every day is the better home for reports. Microsoft lists the requirements: one Exchange Online mailbox, since distribution groups, external mailboxes, and on-premises mailboxes are ruled out; identified as a SecOps mailbox in the advanced delivery policy, so reported messages arrive unfiltered; and, if you use data loss prevention, excluded from those policies. If you run Attack simulation training or another phishing simulation product, the SecOps setting matters twice: Microsoft notes that a user reported message might otherwise trigger a training assignment.

What does a Teams report send to Microsoft?

Microsoft documents exactly what travels with a report. It belongs in the written destination decision in step 3 below.

The item itself

For a message, its content, headers, attachments, and routing metadata. For a call, the call metadata. Microsoft says all data directly associated with the item is copied.

Up to fifteen messages before and after

Microsoft says up to fifteen messages before and after the reported message might also be shared for analysis, as context for the report.

Microsoft staff may read it

Microsoft personnel might read submitted messages, calls, and files. Microsoft notes this is typically not permitted for Teams items in Microsoft 365, and a report is the exception.

Stored in the USA while it's needed

Submitted content is stored in secured, compliance-audited data centers located in the USA, and Microsoft says it keeps that content only as long as it's required.

"Microsoft treats this feedback as your organization's authorization to analyze the submitted information to improve hygiene algorithms."

Microsoft Learn, User reported settings in Microsoft Teams, last updated September 21, 2026

The same Microsoft page says the submission remains confidential between your organization and Microsoft during the review process, and it sets out how Microsoft limits the use of customer data to train generative AI foundation models. Read those lines with your privacy officer. They are part of the decision.

For a credit union, bank, or mortgage company, a Teams chat can hold member or borrower details, so the fifteen-message context is the line to weigh. My reporting mailbox only sends reports to your mailbox and leaves submission to Microsoft to an admin. Microsoft Learn says they go to Microsoft only if an admin submits them from the User reported tab, and Microsoft says submission of Teams messages to Microsoft "is currently in Preview, isn't available in all organizations, and is subject to change." The other two destinations send each report automatically, which is how Microsoft's filtering learns from your users.

How a reported Microsoft Teams message or call flows in Microsoft Defender for Office 365, with Microsoft branding. An employee selects Report this message or Report call in Microsoft Teams. The report follows the destination the organization chose: Microsoft and my reporting mailbox, which is Microsoft's default, My reporting mailbox only, or Microsoft only. A reported message sent to Microsoft carries its content, headers, attachments, routing metadata, and up to fifteen messages before and after; a reported call carries the call metadata. In every option the report appears on the User reported tab of the Submissions page in the Microsoft Defender portal and raises an alert, and the security team triages it.
One report, three possible destinations, and the same Defender portal record in every case. The destination decides what reaches Microsoft and where your team's copy lands.

Find out where your tenant's Teams reports are set to go before October 25

ABT checks both reporting settings, the destination, the reporting mailbox, and who receives the alerts in your Microsoft 365 tenant, as part of a free security assessment.

Request the free assessment

What should an administrator settle before October 7?

Seven steps. Settings in place before October 7 carry over to the new page. Changes made after the move may take until the week of October 15 to apply, which still lands ahead of the October 25 default.

1

Read the Teams side of the setting

In the Teams admin center, open Settings & policies. On the Global (Org-wide) default and each custom messaging policy, find Report a security concern. Under Messaging settings, Messaging safety, find Report incorrect security detections. Under Calling settings, General, find Report a call. Microsoft says the Teams side is on by default, so record any policy where someone switched it off. Viewing or changing these takes the Teams Administrator or Global Administrator role.

2

Read the Defender side

In the Microsoft Defender portal, go to Settings, then Email & collaboration, then User reported settings, and find Monitor reported items in Microsoft Teams in the Microsoft Teams section. Changing it takes membership in the Organization Management or Security Administrator role groups. Write down its state and the current destination today. That record is your baseline for the October changes.

3

Choose the destination with your compliance officer

Put the three destinations in front of your privacy or compliance officer and your security lead together. The trade is Microsoft's analysis, which Microsoft says improves its filtering, against what a report carries to Microsoft: the item, up to fifteen messages before and after it, and the possibility that Microsoft personnel read it. Record the choice and the reason. Any of the three can be the right choice. Before you pick mailbox-only, check that your portal lets an admin submit Teams items to Microsoft, because Microsoft says submission of Teams messages to Microsoft is in Preview and isn't available in all organizations. A written decision is far easier to explain later than an inherited default.

4

Give reports a mailbox your security team reads

If your destination includes a reporting mailbox, replace the global admin default with one Exchange Online mailbox that belongs to security operations. Identify it as a SecOps mailbox in the advanced delivery policy, exclude it from data loss prevention if you use it, and give one person the job of reading it every business day.

5

Route the four alerts

Microsoft ships four alert policies that fire by default when users report Teams items: Teams message reported by user as a security risk, Teams message reported by user as a not security risk, Teams call reported by user as a security risk, and Teams call reported by user as a not security risk. Check who receives them and how quickly someone looks. A reported help desk impersonation call deserves an answer the same day, and our guide to the first 24 hours after an impersonation email shows what that response looks like on the email side.

6

Show your staff the two buttons

Teach Report this message from a message's More options menu and Report call from call history. Microsoft Learn says senders and callers aren't told they were reported, the item stays visible to the user, and the same item can be reported more than once. Teams also lets users report a suspicious external person while blocking them, and Microsoft Learn says those person reports are still outside Microsoft Defender, so message and call reports are what your security team sees. Pair the lesson with the pattern Microsoft sees most in Teams attacks, someone posing as the IT help desk and warning that an account is about to be locked, which our breakdown of the Teams help desk impersonation attack chain walks through stage by stage.

7

Test it once and keep the record

Before October 25, have a volunteer report a test message and a test call. Check four outcomes separately: the item appears on the User reported tab of the Submissions page, the alert fires, the alert notification reaches the person who triages, and, if your destination includes a mailbox, the mailbox receives its copy. File the dated results with the destination decision from step 3.

Read the sources in two minutes

Open Message Center post MC1478463 in your Microsoft 365 admin center. Then read Microsoft Learn's User reported settings in Microsoft Teams, last updated September 21, 2026, and User reported settings for the reporting mailbox requirements.

Why does Teams reporting matter at a financial institution?

Teams is where your staff get work done, and Microsoft's own data shows attackers calling them there.

Start with the productive version. The loan team clears a condition in a chat, a branch pings operations about a member's card, and a vendor joins a meeting from outside the tenant. A report option puts the people doing that work on your security team's side of the table, one click from the message that looked wrong.

Microsoft's Q2 2026 email threat report puts numbers on the risk. In Microsoft's words, vishing through Teams showed the steepest growth of any threat category tracked in the report during Q2. Average weekly malicious call attempts rose 31% from April to May and another 27% into June, and since the beginning of 2026 weekly vishing attempts have increased roughly 80% and now run at nearly ten times the mid-2025 baseline. Those figures count calls. Microsoft reports Teams-based phishing messages separately: up 19% from March to April, 1% into May, and 10% into June. The dominant lure remained technical support impersonation: attackers posing as an employee's IT help desk, warning of an impending account lockout.

Two more findings explain why a person's report matters. Microsoft notes that Teams traffic typically bypasses secure email gateways, and that for the second consecutive month more than half, 52%, of Teams-based phishing attacks in June used generic display names in place of obvious IT support names. The lures look more ordinary each month, and the employee who says "that call felt wrong" can be the first signal your security team gets. Our analysis of Microsoft's Q2 2026 Teams vishing data covers the rest of the report.

What protects Teams at each license level

User reporting is one of several Teams protections that arrive with Defender for Office 365. Microsoft Learn's feature table, last updated September 21, 2026, splits them this way.

Every Teams license

Built into Microsoft 365

  • Built-in virus protection in SharePoint, OneDrive, and Teams
  • The Teams external domain anomalies report
  • Near real-time warnings on malicious URLs in Teams messages, up to 48 hours after delivery

Defender for Office 365 Plan 1

In Business Premium, Office 365 E3, and Microsoft 365 E3

  • User-reported Teams items
  • Safe Links and Safe Attachments at time of click
  • Zero-hour auto purge (ZAP) for Teams, with admin-managed quarantine
  • Tenant Allow/Block List for domains, URLs, and files
  • Teams message and call entity panels for investigation

Defender for Office 365 Plan 2

In Microsoft 365 E5 and Office 365 E5

  • Everything in Plan 1
  • Removing users from Teams chats as an admin remediation
  • Advanced hunting on Teams messages

If your institution runs Microsoft 365 E3 and wants the Plan 2 tools without a full E5 move, our page on Microsoft 365 E3 security add-ons lays out the step up. Teams settings beyond reporting, from guest access to retention, are covered in our guide to Teams governance for financial institutions.

Why does a person's report matter when the sign-in page is real?

A real Microsoft sign-in page can sit at the end of a fake invitation. Microsoft Threat Intelligence described one such attack in February 2025: Storm-2372 generated a legitimate device code request and tricked targets into entering it into a legitimate sign-in page. Its lures resembled messaging apps including WhatsApp, Signal, and Microsoft Teams, and its phishing emails were dressed as Teams meeting invitations.

The Short from our channel walks through that pattern: the victim signs in on the real portal and completes the real multifactor prompt. Microsoft's guidance for device code phishing is to block device code flow wherever possible, and that control belongs in place first. Where a lure still reaches someone, the person who says "that meeting invite was strange" is part of your detection, and the report option is how that observation reaches your security team.

Featured Short

A free security assessment

ABT is a Tier 1 Microsoft Cloud Solution Provider. We manage Microsoft 365 tenants for more than 750 financial institutions, and the Teams reporting check is part of this assessment.

We show you where your Teams reports are set to go today, and what to set before October 7

The assessment is free and ends with written findings you keep. We work through your reporting settings with an administrator on your team, and your team decides what changes in the tenant and who makes each change.

  • The reporting settings, both portals. The Teams admin center policies and the Defender portal setting, recorded as they stand today.
  • The destination brief. The three destinations laid out for your compliance officer, with what each one sends and to whom.
  • The reporting mailbox. One mailbox for security operations, with its advanced delivery and data loss prevention settings.
  • The alert path. Who receives the four Teams report alerts, and how quickly someone looks.
  • The wider Teams picture. External access, Safe Links, and ZAP for Teams, measured by what each setting does in your tenant.

ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies. Learn about M365 Guardian

If this opened a bigger question

Teams reporting sits between your phishing defenses, your help desk process, and your Defender for Office 365 configuration. These three pick up each thread.

Split scene showing a dimmed email inbox on the left and a bright Microsoft Teams incoming call notification on the right, with Microsoft 365 branding

Microsoft's Q2 2026 Threat Data on Teams Vishing

What Microsoft's April to June 2026 report says about Teams calls, generic display names, and business email compromise.

Read the analysis
Microsoft Teams helpdesk impersonation 9-stage attack chain targeting financial institutions

Teams Help Desk Impersonation: The 9-Stage Attack Chain

How a fake IT support chat becomes an intrusion, and the Teams settings that break the chain at each stage.

Read the guide
Microsoft Defender for Office 365 anti-phishing configuration for credit unions, banks, and mortgage companies

Defender for Office 365 Anti-Phishing for Financial Institutions

The six anti-phishing controls to verify in Defender for Office 365, and a 30-day plan to roll them out.

Read the guide

Teams user reporting, answered

Yes, for tenants that have left the settings unconfigured. Microsoft 365 Message Center post MC1478463 says that if you have not already configured Teams user-reported settings, Teams user reporting will be enabled by default beginning October 25, 2026, unless you opt out. It applies to organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5, and the settings move to a dedicated page in the Microsoft Defender portal on October 7, 2026.
Microsoft Learn says users can report messages from chats, channels, and meeting conversations as malicious or not malicious, and calls from their call history as scam or not scam. Reporting works in the Teams desktop client and the Teams web app, and the Teams apps for iOS, iPadOS, and Android report messages. Microsoft's Message Center post describes the change as covering suspicious messages, calls, and meetings.
To the destination set under Reported items destinations: Microsoft and my reporting mailbox, which is Microsoft's default; My reporting mailbox only; or Microsoft only. Microsoft Learn says the default reporting mailbox is the Exchange Online mailbox of the global admin. Whatever the destination, the report's metadata appears on the User reported tab of the Submissions page in the Microsoft Defender portal, and alert policies generate alerts by default.
When the destination includes Microsoft, Microsoft Learn lists the message content, headers, attachments, and routing metadata, and for a call the call metadata. Up to fifteen messages before and after the reported message might also be shared for analysis. Microsoft says its personnel might read submitted messages, calls, and files, that submitted content is stored in compliance-audited data centers located in the USA, and that Microsoft keeps it only as long as it's required.
Until October 7, 2026, use the Microsoft Teams section and the Reported items destinations section of the User reported settings page in the Microsoft Defender portal, along with the reporting toggles in the Teams admin center. From October 7, Teams user-reported settings have their own page in the Defender portal. Microsoft says changes made after that migration may take until the week of October 15, 2026 to be reflected, and asks you to review the settings before October 25.
Microsoft Learn lists user-reported Teams items as a feature of Microsoft Defender for Office 365 Plan 1 and Plan 2. The Message Center post names Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, and Office 365 E5, and Microsoft's service description says Plan 1 is included in Microsoft 365 Business Premium and, effective July 1, 2026, in Office 365 E3 and Microsoft 365 E3. Microsoft Learn lists Teams reporting as unavailable in Microsoft 365 GCC, GCC High, and DoD.
No. Microsoft Learn says message senders aren't notified that their messages were reported, and callers aren't notified that their calls were reported. Reported items stay visible to the user, and the same item can be reported more than once. For a shared channel, the report goes to the organization that owns the channel.
One Exchange Online mailbox that your security team reads. Microsoft Learn rules out distribution groups, external mailboxes, and on-premises mailboxes, asks you to identify the reporting mailbox as a SecOps mailbox in the advanced delivery policy so reported messages arrive unfiltered, and, if you use data loss prevention, asks you to exclude it. With a phishing simulation product in use, the SecOps setting also keeps a user's report from triggering a training assignment.
Open Message Center post MC1478463, Microsoft Defender for Office 365: Teams user reporting enabled by default, in your Microsoft 365 admin center. On Microsoft Learn, read User reported settings in Microsoft Teams and User reported settings. Every Microsoft statement on this page was read from those sources and the others listed below on September 25, 2026.

Where the facts on this page come from

Every Microsoft date, figure, and quotation above was read from the Microsoft sources listed here on September 25, 2026.

  • Microsoft 365 Message Center post MC1478463, Microsoft Defender for Office 365: Teams user reporting enabled by default, plan for change, major change, published September 24, 2026. Source for the October 25, 2026 default, the opt-out, the dedicated Defender portal page from October 7, 2026, settings carrying over, changes after migration taking until the week of October 15, 2026, the licensing line, the late October rollout, and the recommendation to review settings before October 25. Visible to administrators in your own Microsoft 365 admin center.
  • Microsoft Learn, User reported settings in Microsoft Teams, last updated September 21, 2026. Source for what users can report and on which clients, the two separate settings and their defaults, the Teams admin center toggles, what a report sends to Microsoft, the fifteen-message context, Microsoft personnel reading submissions, USA storage, the three destinations and the global admin default mailbox, the four alert policies, sender and caller notification, shared channels, and the U.S. Government cloud exclusion.
  • Microsoft Learn, User reported settings, last updated August 7, 2026. Source for the reporting mailbox requirements: an Exchange Online mailbox, the SecOps mailbox setting in the advanced delivery policy, the data loss prevention exclusion, the phishing simulation training assignment note, and manual submission to Microsoft from the Submissions page.
  • Microsoft Learn, Submit messages, URLs, and attachments for analysis in the Microsoft Defender portal, last updated July 30, 2026. Source for admin submission of user-reported Teams messages from the User reported tab, Microsoft's note that submission of Teams messages to Microsoft is in Preview, isn't available in all organizations, and is subject to change, and the Not Submitted to Microsoft result for mailbox-only reports.
  • Microsoft Learn, End user reporting for Security (Microsoft Teams), last updated July 28, 2026. Source for reporting a suspicious external person while blocking them, and those person reports sitting outside Microsoft Defender.
  • Microsoft Learn, Microsoft Defender for Office 365 support for Microsoft Teams, last updated September 21, 2026. Source for the Teams protection features by license level.
  • Microsoft Learn, Microsoft Defender for Office 365 service description, last updated July 17, 2026. Source for Plan 1 being included in Microsoft 365 Business Premium and, effective July 1, 2026, in Office 365 E3 and Microsoft 365 E3.
  • Microsoft Security Blog, Email threat landscape: Q2 2026 trends and insights, July 23, 2026. Source for the Teams vishing growth figures, the separate Teams phishing figures, the mid-2025 baseline comparison, the help desk impersonation lure, the 52% generic display name finding, and Teams traffic bypassing secure email gateways.
  • Microsoft Security Blog, Storm-2372 conducts device code phishing campaign, February 13, 2025. Source for device code phishing through a legitimate sign-in page, the Teams-style lures, and Microsoft's recommendation to block device code flow wherever possible.

A reported Teams call is an early warning.
Make sure it reaches someone.

Deciding where Teams reports go is a short piece of work before October 7. Once it is settled, reports land with the people you chose to receive them.

Tell us a little about your environment and we will come back with what we would check first.

Tier 1 Microsoft CSP 750+ financial institutions SOC 1 Type 2 · Security Controls SOC 2 Type 1

What should we look at? Optional.

Teams reporting settings
Reporting mailbox setup
Teams phishing and vishing defenses
Security assessment

Encrypted. Private.

Thank you. That is with us.

An ABT specialist will be in touch shortly. If you want the settings in place before October 7, say so in your reply and we will move it to the front.