Microsoft Teams to Gain New Security Detection Reporting Feature
Key Takeaways Microsoft is introducing a new Security Detection Report for Teams administrators. The feature centralizes threat monitoring for impersonation, malicious URLs, and weaponizable files...
Key Takeaways
- Microsoft is introducing a new Security Detection Report for Teams administrators.
- The feature centralizes threat monitoring for impersonation, malicious URLs, and weaponizable files within Teams.
- It provides a unified dashboard, detailed detection tables, and exportable data for security investigations.
- The global rollout for standard multi-tenant customers is anticipated to begin in late August 2026 and conclude by early September 2026.
Microsoft is set to launch a significant enhancement for its Teams communication platform, introducing a dedicated Security Detection Report within the Teams admin center. This new feature aims to provide administrators with a consolidated view of messaging-based threats, a capability that security professionals have long sought to streamline their organizational defenses.
Table Of Content
Operating under Microsoft 365 Roadmap ID 560702, this update integrates previously disparate threat intelligence into a singular dashboard. This integration is expected to drastically simplify the process for security teams to identify and respond to malicious activities occurring within Teams chats and channels.
Teams Security Detection Report Overview
The upcoming report will be accessible within the Teams admin center under the navigation path: Analytics & Reports > Protection Reports > Security Detections. It is designed to consolidate three primary categories of messaging threats: attempts at impersonation, the distribution of malicious URLs, and the sharing of weaponizable file types.
Rather than requiring administrators to consult multiple security tools to construct a comprehensive understanding of ongoing attacks, this new report will present a centralized graphical representation of detection volumes over a specified period. This visual summary will be complemented by a detailed table outlining individual detections.

Each entry within the report will offer contextual information crucial for investigation, including details about the sender and recipient, the specific type of detection, and relevant thread identifiers. This forensic depth is intended to enable rapid action against suspicious conversations.
Data Export and Integration
Beyond simply providing visibility, the Security Detection Report will support data export functionalities. Administrators will have the option to download both high-level chart summaries and complete table records as CSV files. This capability is particularly valuable for integrating threat data into broader security information and event management (SIEM) systems or for documenting incidents during compliance audits.
An especially practical feature highlighted during early previews is the direct ability to block malicious external users. Administrators can initiate this action directly from the report via External Access settings, significantly reducing the time between identifying a threat and implementing containment measures.
Rollout Schedule and Strategic Importance
The timeline for this feature’s release has seen several adjustments. Initially slated for mid-July 2026, it was subsequently revised to late June. The most current update from Microsoft indicates that general availability will commence in late August 2026, with a global rollout for worldwide standard multi-tenant customers projected to conclude by early September 2026.
These repeated timeline revisions suggest that Microsoft is actively refining the underlying detection logic and reporting infrastructure. This cautious approach is prudent, given Teams’ critical role in modern enterprise collaboration and its increasing attractiveness as a target for attackers.
Teams has evolved into a frequent vector for various cyber threats, including phishing-style impersonation, the delivery of malicious links, and the distribution of file-based malware. These tactics mirror those traditionally observed in email-based attacks.
Until now, administrators have lacked a purpose-built, centralized mechanism to track these specific detections natively within the Teams admin center. Many have had to rely on the broader email and collaboration reports available through the Microsoft Defender portal. By integrating Teams-specific detections directly into the platform’s administration interface, Microsoft is addressing a critical visibility gap that security teams have consistently highlighted.
This upcoming launch also complements another related update that is already being deployed: user-reported security signals. This feature allows end users to directly flag suspicious messages within Teams, with these reports now feeding into the same Protection Reports section. Together, these two capabilities signify Microsoft’s commitment to building a more comprehensive, native security telemetry layer within the Teams ecosystem.
What You Should Do
- Confirm that malicious link and file scanning settings are appropriately enabled under Messaging Safety in your Teams environment.
- Update your organization’s incident response runbooks to incorporate the Teams Security Detection Report as a primary signal source for threat investigations once it becomes generally available.
- Familiarize yourself with the new report’s interface and capabilities during the rollout period to maximize its utility for your security operations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.