← Back
(Updated) Microsoft Teams: User reporting for incorrectly identified security concerns
MC1147984 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-11-17 17:04:04
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Microsoft Teams, Microsoft Defender XDR
Tags
Updated message, New feature, User impact, Admin impact
Master tags
Security
Roadmap IDs
501202

One-line summary

Teams users can now report messages incorrectly flagged as security threats; feature rolls out GA by end of Nov 2025 and is on by default, with admin controls in Teams and Defender portals.

Similar updates

More like this
MC1200576 Teams admin center: Messaging safety defaults changing to "On" by default
Teams admin center: Messaging safety defaults changing to "On" by default Starting January 12, 2026, Microsoft Teams will enable messaging safety features by default, including weaponizable file type protection, malicious URL protection, and reporting incorrect detections. [Introduction] We’re improving messaging security in Microsoft Teams by.
MC1187837 Microsoft Defender for Office 365 Zero-hour auto-purge (ZAP) Teams protection capabilities to Defender for Office Plan 1
Microsoft Defender for Office 365 Zero-hour auto-purge (ZAP) Teams protection capabilities to Defender for Office Plan 1 Starting January 6, 2026, Zero-hour auto-purge (ZAP) will be enabled by default for Teams in Defender for Office 365 Plan 1, automatically quarantining malicious messages. ...Starting January 6, 2026 ,  Zero-hour auto-purge.
MC1147387 Microsoft Defender for Office 365: Alert experience enhancements for faster triage
Microsoft Defender for Office 365: Alert experience enhancements for faster triage Defender for Office 365 will consolidate related alerts into richer, single alerts starting mid-September 2025, reducing alert fatigue and improving triage without changing detection or workflows. Introduction We’re improving the alert experience in Microsoft.
MC1148539 (Updated) Microsoft Teams: Malicious URL Protection for Teams Chat and Channels
(Updated) Microsoft Teams: Malicious URL Protection for Teams Chat and Channels Malicious URL Protection in Teams rolls out globally in Nov 2025, warning users about unsafe links; feature defaults ON at GA, with admin override possible. ...osoft Teams is expected to finish before the end of November 2025 for General AvailabilityIntroduction.
MC1133508 (Updated) Microsoft Teams Integration with Microsoft Defender for Office Tenant Allow/Block List for blocking domains
(Updated) Microsoft Teams Integration with Microsoft Defender for Office Tenant Allow/Block List for blocking domains Microsoft Teams now integrates with Microsoft Defender for Office 365 Tenant Allow/Block List, enabling security admins to cen... Introduction We're introducing a new integration between Microsoft Teams and Microsoft Defender for.
MC1187679 Microsoft Teams: Protection against tenant-owned domain impersonation in Teams chat
Microsoft Teams: Protection against tenant-owned domain impersonation in Teams chat Teams will soon alert users of external chat attempts impersonating tenant-owned domains, enhancing security for organizations with external access enabled. Feature is on by default and requires no admin action. [Introduction:] Coming soon to Microsoft Teams : A.

Details

RoadmapIds
501202
Summary
Microsoft Teams will enable users to report messages incorrectly flagged as security threats, available by end of November 2025 worldwide. The feature requires Microsoft Defender for Office 365 Plan 2 or Defender XDR and must be enabled in both Teams admin center and Microsoft Defender portal.
Platforms
Android, Desktop, iOS, Mac, Web

Body (from Message Center)

Updated November 17, 2025: The rollout of “Report incorrect security detection in Microsoft teams is expected to finish by the end of November 2025 for General Availability (Worldwide). The previously announced update to make “Report incorrect security detections” settings in Messaging settings in Teams admin center On by default has been postponed to early 2026. A separate communication will be issued detailing the roll out schedule for the default-on change in advance.

Thank you for your patience.

Introduction

Microsoft Teams now enables users to report messages they believe were incorrectly flagged as security threats in chats and channels. This capability is available to organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft Defender XDR. It empowers users to provide feedback on false positives, helping improve detection accuracy and strengthen organizational security.

This feature will be available across Microsoft Teams on Android, Desktop (Windows), iOS, Mac, and Web platforms, ensuring broad accessibility for users regardless of device.

This feature is associated with Microsoft 365 Roadmap ID 501202.

When this will happen

Targeted Release (Worldwide): Begins in early September 2025; expected completion by mid-September 2025.

General Availability (Worldwide): Begins in early November 2025; expected completion by end of November 2025 (previously mid-November).

How this affects your organization

Users will be able to report messages they believe contain URLs that were incorrectly flagged as malicious:

 user settings

  • During Targeted Release, the feature is off by default in Teams.
  • At General Availability, the feature will be on by default in Teams. Admin settings saved during Targeted Release will remain unchanged.
  • In the Microsoft Defender portal, the setting is on by default for new tenants. Existing tenants must enable it manually.

What you can do to prepare

To enable this feature and ensure reported messages appear in the User reported tab in Submissions:

  • In the Teams admin center, go to Messaging settings > Messaging safety and turn on Report incorrect security detections.
  • admin settings

  • In the Microsoft Defender portal, ensure the corresponding setting is enabled.
  •   admin settings

Both settings must be turned on for full functionality.

Learn more: [Updated documentation to be made available on Microsoft Learn in the second week of September 2025.]

Compliance considerations

Does the change store new customer data, and if so, where is it stored?Yes. When users report messages they believe were incorrectly flagged, those submissions are stored in the Microsoft Defender portal under the Submissions tab.
Does the change introduce or significantly modify AI/ML or agent capabilities that interact with or provide access to customer data?Yes. User feedback on incorrectly flagged messages is used to improve detection models, which modifies how AI/ML systems classify threats over time.
Does the change include an admin control, and can it be controlled through Entra ID group membership?Yes. Admins can enable or disable the feature in both the Teams admin center and the Microsoft Defender portal. Access to these controls can be managed through Entra ID group membership.

Additional Resources: End user reporting for security - Microsoft Teams | Microsoft Learn

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Enable \u0027Report incorrect security detections\u0027 in Teams admin center",
      "Enable corresponding setting in Microsoft Defender portal"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Teams users can now report messages incorrectly flagged as security threats; feature rolls out GA by end of Nov 2025 and is on by default, with admin controls in Teams and Defender portals.",
    "ai_topics": [
      "Teams",
      "Defender",
      "Entra"
    ],
    "category": "stayInformed",
    "details_map": {
      "Platforms": "Android, Desktop, iOS, Mac, Web",
      "RoadmapIds": "501202",
      "Summary": "Microsoft Teams will enable users to report messages incorrectly flagged as security threats, available by end of November 2025 worldwide. The feature requires Microsoft Defender for Office 365 Plan 2 or Defender XDR and must be enabled in both Teams admin center and Microsoft Defender portal."
    },
    "id": "MC1147984",
    "importance": 1,
    "is_major_change": false,
    "last_modified": "2025-11-17T17:04:04Z",
    "ms_products": [
      "Teams",
      "Defender"
    ],
    "platforms": "Android, Desktop, iOS, Mac, Web",
    "roadmap_ids": [
      "501202"
    ],
    "services": [
      "Microsoft Teams",
      "Microsoft Defender XDR"
    ],
    "severity": "normal",
    "tags": [
      "Updated message",
      "New feature",
      "User impact",
      "Admin impact"
    ],
    "title": "(Updated) Microsoft Teams: User reporting for incorrectly identified security concerns"
  }
}