MC1474106 Medium
Microsoft Defender for Office 365: New MessageContents table in Advanced Hunting for Microsoft Teams messages
Summary AI-generated
A new MessageContents table in Defender XDR Advanced Hunting enables authorized analysts to query Teams message snippets and metadata for enhanced threat investigations.
Suggested actions AI-generated
- Review existing role assignments for Teams message content access
- Review required Advanced Hunting and message preview permissions
- Update internal security investigation procedures and documentation if needed
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1088729 (Updated) Microsoft Defender for Office 365: Two new data tables in Advanced hunting (preview)
- MC1476237 Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout
- MC1239187 Defender for Office 365 URL click alerts now include Microsoft Teams
- MC1219788 (Updated) Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1
- MC1163754 Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365
- MC1237728 (Updated) Advanced Hunting: new actions to block attachments and top-level URL domains
Original post from Microsoft
[What and why]
We're introducing a new MessageContents table in Advanced Hunting for Microsoft Teams messages. This new table helps security operations teams investigate threats in Teams by providing access to Teams message snippets and associated message metadata during threat investigations.
This capability enhances security investigations by allowing authorized analysts to correlate Teams message activity with other security signals available in Advanced Hunting, helping organizations detect, investigate, and respond to threats more effectively.
[Rollout schedule]
- General Availability (Worldwide): Beginning in late September 2026 and expected to complete by mid-October 2026
[Impact on your organization]
Who is affected
- Security administrators and security analysts who use Microsoft Defender XDR Advanced Hunting
- Organizations that investigate security incidents involving Microsoft Teams communications
Platforms and services
- Microsoft Defender XDR
- Microsoft Defender for Office 365
- Microsoft Teams
- Advanced Hunting
What will happen
- A new MessageContents table will become available in Advanced Hunting.
- Authorized users will be able to query Teams message snippets and related message metadata.
- Analysts can correlate Teams message information with other Advanced Hunting data sources during investigations.
- The table can contain Teams message content, so access is permission controlled.
- Users must have the required Advanced Hunting and message preview permissions to access and query the table. Users without the required permissions will not have access to the table.
- Users without the required permissions will not have access to the table.
- The table currently supports Teams messages available through the underlying Teams message metadata source, including messages containing URLs and federated messages.
[Action required and recommendations]
No action is required if your organization does not plan to use this capability.
If you plan to use this feature:
- Review existing role assignments and determine which security administrators and analysts should have access to Teams message content for security investigations.
- Review the required Advanced Hunting and message preview permissions before providing access.
- Consider updating internal security investigation procedures and documentation.
Learn more
[Compliance considerations]
| Question | Answer |
| Does the change alter how existing customer data is processed, stored, or accessed? | Authorized users with the required permissions can access Teams message snippets and associated message metadata through the new MessageContents table in Advanced Hunting. |
Additional details from Microsoft
- Summary
- Microsoft Defender for Office 365 introduces a new MessageContents table in Advanced Hunting for Teams messages, enabling authorized security analysts to query message snippets and metadata for threat investigations. It rolls out worldwide from late September to mid-October 2026, requiring appropriate permissions for access.