← Back
Microsoft Teams: Report external users for security concerns
MC1309744 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2026-05-13 23:09:34
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
2026-06-10 00:00:00
Services
Microsoft Teams
Tags
New feature, User impact, Admin impact
Master tags
User, Admin, Security
Roadmap IDs
560547

One-line summary

Teams users can report suspicious external users directly in Teams, with reports surfaced to admins for investigation via a new User reported security submission report.

Similar updates

More like this
MC1162276 (Updated) Microsoft Teams: Trust Indicators – a new way of representing users outside your organization
(Updated) Microsoft Teams: Trust Indicators – a new way of representing users outside your organization Teams will show Trust Indicators—visual badges next to names—to identify external, guest, or anonymous participants, helping users avoid oversharing; feature i... [Introduction:] To help users quickly identify external participants in .
MC1187679 Microsoft Teams: Protection against tenant-owned domain impersonation in Teams chat
Microsoft Teams: Protection against tenant-owned domain impersonation in Teams chat Teams will soon alert users of external chat attempts impersonating tenant-owned domains, enhancing security for organizations with external access enabled. [Introduction:] Coming soon to Microsoft Teams : A new security feature to enhance external collaboration..
MC1147984 (Updated) Microsoft Teams: User reporting for incorrectly identified security concerns
(Updated) Microsoft Teams: User reporting for incorrectly identified security concerns Teams users can now report messages incorrectly flagged as security threats; feature rolls out GA by end of Nov 2025 and is on by default, with admin controls in Teams and Defender portals. Introduction Microsoft Teams now enables users to report messages they.
MC1200576 Teams admin center: Messaging safety defaults changing to "On" by default
Teams admin center: Messaging safety defaults changing to "On" by default Starting January 12, 2026, Teams will enable weaponizable file and malicious URL protection, plus reporting, by default for tenants using default messaging safety settings. [Introduction] We’re improving messaging security in Microsoft Teams by enabling key safety.
MC1200058 Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal
Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal Teams and Defender for Office 365 integration lets security admins centrally manage blocked external users/domains in Teams via the Defender portal; rollout starts January 2026. [Introduction] We’re introducing an integration between.
MC1150123 (Updated) Teams Admin Center: Control External Access by Domain for Specific Users and Groups
(Updated) Teams Admin Center: Control External Access by Domain for Specific Users and Groups Teams admins can now assign custom external access policies to users/groups, enabling granular control over which external domains they can interact with; GA rollout starts late Octobe... Introduction We are introducing a new capability in Microsoft.

Details

RoadmapIds
560547
FeatureStatusJson
{"560547":[{"RoadmapId":560547,"Platform":"Mac","Status":"Scheduled","LastUpdateTime":"2026-05-14T03:00:20.2967976Z","LatestRing":null},{"RoadmapId":560547,"Platform":"iOS","Status":"Scheduled","LastUpdateTime":"2026-05-14T03:00:20.2967977Z","LatestRing":null},{"RoadmapId":560547,"Platform":"Desktop","Status":"Scheduled","LastUpdateTime":"2026-05-14T03:00:20.2967977Z","LatestRing":null},{"RoadmapId":560547,"Platform":"Android","Status":"Scheduled","LastUpdateTime":"2026-05-14T03:00:20.2967978Z","LatestRing":null},{"RoadmapId":560547,"Platform":"All","Status":"Scheduled","LastUpdateTime":"2026-05-14T03:00:20.2967978Z","LatestRing":null}]}
Summary
Microsoft Teams will enable users to report suspicious external users directly, with reports visible to admins in the Teams admin center for faster security response. This feature, rolling out June 2026, supports chats, meetings, and channels, is enabled by default, and integrates with existing messaging policies.
Platforms
Android, Desktop, iOS, Mac

Body (from Message Center)

[Introduction]

To help organizations respond more quickly to external security threats, Microsoft Teams will allow users to report suspicious external users directly from Teams. These reports will surface in the Teams admin center, giving admins greater visibility into potentially risky interactions and enabling faster investigation and response. This enhancement will build on existing reporting capabilities and will use user signals as an additional layer of protection against phishing, impersonation, and social engineering attacks.

This message is associated with Microsoft 365 Roadmap ID 560547.

[When this will happen]

  • Targeted Release: We will begin rolling out in early June 2026 and expect to complete by early June 2026.
  • General Availability (Worldwide): We will begin rolling out in mid-June 2026 and expect to complete by late June 2026.

[How this affects your organization]

Who is affected

  • All Microsoft 365 tenants using Microsoft Teams
  • Users who interact with external users in Teams
  • Admins managing Teams security and reporting in the Teams admin center

What will happen

  • Users will be able to report suspicious external users directly in Teams, in addition to blocking them: 

    user settings

  • Reporting will be available during first time external chat requests and from an external user profile card.
  • Reporting will be supported across Teams experiences including chats, meetings, channels, and search results.
  • When a user is reported, the submission will appear in the Teams admin center under Protection reports > User reported security submission report

    user settings

  • Admins will be able to review reported users and investigate potential phishing, impersonation, or other suspicious activity.
  • Additional metadata will be available through report export to support investigation and response workflows.
  • This feature will be enabled by default and will respect existing Teams messaging policies.

[What you can do to prepare]

No action will be required if you want to keep user reporting enabled.

Admins may choose to take the following actions:

  • Review current Teams messaging policies and confirm that the Report a security concern setting remains enabled.
  • Familiarize security and helpdesk teams with the User reported security submission report in the Teams admin center.
  • Update internal security guidance or user education materials, if applicable.
  • If a malicious external user is identified through these reports, block that user at the tenant level using External access settings to prevent further communication attempts.

[Compliance considerations]

QuestionAnswer
Does the change store new customer data, and if so, where?Yes. Reports submitted by users about external users will be processed and made available to admins for review and investigation, extending existing reporting workflows.
Does the change alter how existing customer data is processed, stored, or accessed?Yes. User generated reports about external users are processed and made available to admins for review and investigation, extending existing reporting workflows.
Does the change provide a new way of communicating between users, tenants, or subscriptions?Yes. Users will be able to submit reports about external users, which will be communicated to tenant admins through the Teams admin center reporting experience.
Does the change alter how admins can monitor, report on, or demonstrate compliance activities?Yes. Admins will gain access to a new User reported security submission report in the Teams admin center, which will enhance monitoring and investigation capabilities related to external security threats.
Does the change include an admin control?Yes. The feature will be governed by the existing Report a security concern setting in Teams messaging policies and can be enabled or disabled by admins.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": "2026-06-10T00:00:00Z",
    "ai_actions": [
      "Review Teams messaging policies and ensure report security concern is enabled",
      "Familiarize security/helpdesk with User reported security submission report",
      "Update internal security guidance or user materials"
    ],
    "ai_master_tags": [
      "User",
      "Admin",
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Teams users can report suspicious external users directly in Teams, with reports surfaced to admins for investigation via a new User reported security submission report.",
    "ai_topics": [
      "Teams"
    ],
    "category": "stayInformed",
    "details_map": {
      "FeatureStatusJson": "{\"560547\":[{\"RoadmapId\":560547,\"Platform\":\"Mac\",\"Status\":\"Scheduled\",\"LastUpdateTime\":\"2026-05-14T03:00:20.2967976Z\",\"LatestRing\":null},{\"RoadmapId\":560547,\"Platform\":\"iOS\",\"Status\":\"Scheduled\",\"LastUpdateTime\":\"2026-05-14T03:00:20.2967977Z\",\"LatestRing\":null},{\"RoadmapId\":560547,\"Platform\":\"Desktop\",\"Status\":\"Scheduled\",\"LastUpdateTime\":\"2026-05-14T03:00:20.2967977Z\",\"LatestRing\":null},{\"RoadmapId\":560547,\"Platform\":\"Android\",\"Status\":\"Scheduled\",\"LastUpdateTime\":\"2026-05-14T03:00:20.2967978Z\",\"LatestRing\":null},{\"RoadmapId\":560547,\"Platform\":\"All\",\"Status\":\"Scheduled\",\"LastUpdateTime\":\"2026-05-14T03:00:20.2967978Z\",\"LatestRing\":null}]}",
      "Platforms": "Android, Desktop, iOS, Mac",
      "RoadmapIds": "560547",
      "Summary": "Microsoft Teams will enable users to report suspicious external users directly, with reports visible to admins in the Teams admin center for faster security response. This feature, rolling out June 2026, supports chats, meetings, and channels, is enabled by default, and integrates with existing messaging policies."
    },
    "id": "MC1309744",
    "importance": 4,
    "is_major_change": false,
    "last_modified": "2026-05-13T23:09:34Z",
    "ms_products": [
      "Teams"
    ],
    "platforms": "Android, Desktop, iOS, Mac",
    "roadmap_ids": [
      "560547"
    ],
    "services": [
      "Microsoft Teams"
    ],
    "severity": "normal",
    "tags": [
      "New feature",
      "User impact",
      "Admin impact"
    ],
    "title": "Microsoft Teams: Report external users for security concerns"
  }
}