Microsoft will turn on Teams message reporting in Defender for Office 365; opt out by 25 October
EditorialBy TrustList Editorial
Users will be able to report suspicious Teams messages to Defender by default. Settings move to a new Defender page on 7 October, and 25 October is the last date to opt out or pick where reports go.
About Microsoft will turn on Teams message reporting in Defender for Office 365; opt out by 25 October
Microsoft will turn on Teams message reporting in Defender for Office 365; opt out by 25 October
24 September 2026 — Microsoft has told administrators that it will switch on Teams user reporting by default, so that people can report suspicious Microsoft Teams messages to Microsoft Defender in the same way they already report suspicious email. The notice, Message Center post MC1478463, was published on 24 September 2026.
What changes, and when
- 7 October 2026: management of the Teams user-reported message settings moves to its own page in the Microsoft Defender portal.
- Week of 15 October 2026: changes made after that move take effect.
- 25 October 2026: the last date to opt out, or to choose a different destination for reports, before the default is switched on.
- Late October 2026: Microsoft expects the rollout to be complete.
The change applies to organisations licensed for Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5 or Office 365 E5.
Who is affected
Security and IT teams in any organisation with those licences. The practical effect is a new stream of user reports. Where reports go matters: to Microsoft only, to a reporting mailbox your team watches, or to both. Organisations that use a third-party email-security product, or a managed security provider that works from a reporting mailbox, need the Teams reports to reach the same place, or they will arrive somewhere nobody is looking.
What to do
- Before 25 October, decide where Teams user reports should go, and set it on the new Defender page once it appears on 7 October.
- Tell your security operations team or managed provider to expect Teams reports, and agree who triages them.
- If you use another vendor's email-security product, ask whether it ingests Teams reports or only email.
- Update the guidance you give staff on how to report suspicious messages, so it covers Teams as well as email.
Not yet independently verified. This rests on Microsoft’s own Message Center post, read through a public archive because the admin centre requires sign-in. No independent report of it was found, so every date here comes from the vendor's own page and is only as reliable as that page. We will update this when it can be confirmed, and remove this note.
Sources
- Microsoft 365 Message Center MC1478463, via the public Message Center archive — 24 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.