MC1476237 Medium
Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout
Summary AI-generated
Teams message entity flyout in Defender for Office 365 is enhanced to let admins submit suspicious messages and block senders/domains in one workflow, enabling faster remediation.
Suggested actions AI-generated
- Review internal security operations procedures for Teams message investigations
- Update administrator training materials and documentation
- Inform security operations teams about the new workflow
Written by Azure OpenAI (gpt-4.1) from the text of the post below. It can be incomplete or wrong; the original post is authoritative.
Similar posts
Search for more like this- MC1461704 Microsoft Defender XDR: Unified response actions across identity accounts
- MC1239187 Defender for Office 365 URL click alerts now include Microsoft Teams
- MC1219788 (Updated) Microsoft Defender for Office 365: Enable users to report suspicious Teams messages in Plan 1
- MC1237728 (Updated) Advanced Hunting: new actions to block attachments and top-level URL domains
- MC1474106 Microsoft Defender for Office 365: New MessageContents table in Advanced Hunting for Microsoft Teams messages
- MC1200058 Microsoft Defender for Office 365: Admins can block external users in Microsoft Teams from Defender Portal
Original post from Microsoft
[What and why]
We are enhancing the Teams message entity flyout in Microsoft Defender for Office 365 to help security teams investigate and remediate malicious Teams messages more efficiently. Administrators will be able to submit messages to Microsoft and block external senders or associated domains from a single workflow, reducing the need to navigate between investigation experiences.
[Rollout schedule]
- General Availability (Worldwide): Beginning in late September 2026 and expected to complete by mid-October 2026
[Impact on your organization]
Who is affected
- Security administrators and analysts in organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2 who investigate Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine
Platforms and services
- Microsoft Defender for Office 365
- Microsoft Teams
- Microsoft Defender portal
What will happen
Administrators investigating Teams messages through Submissions, Alerts, Advanced Hunting, or Quarantine will be able to open the Teams message entity flyout and access the Take action workflow directly from the message.
The updated action wizard will support the following actions:
- Submit to Microsoft: Submit the Teams message to Microsoft for review and analysis:

- Block sender: Add the external sender to the Tenant Allow/Block List (TABL). When available, sender information will be prepopulated to reduce manual entry.
- Block domain: Add one or more domains associated with the investigated message to TABL. The wizard will identify and prepopulate domains associated with an external sender, allowing administrators to select the domains to block.
-

Administrators can perform multiple actions in a single workflow. For example, they can submit a message to Microsoft while also blocking the associated sender or domain.
These actions will be available to Microsoft Defender for Office 365 Plan 1 and Plan 2 customers. Existing investigation experiences and workflows will remain available. No configuration changes are required for this capability.
[Action required and recommendations]
No action is required before rollout.
We recommend that organizations:
- Review internal security operations procedures for Teams message investigations.
- Update administrator training materials and documentation to include the new remediation actions available from the Teams message entity flyout.
- Inform security operations teams about the streamlined investigation and remediation workflow.
Learn more
- [To be updated closer to launch.] Teams message entity panel in Microsoft Defender for Office 365 - Microsoft Defender for Office 365 | Microsoft Learn
[Compliance considerations]
No compliance considerations were identified in the source content. Review this change as appropriate for your organization.
Additional details from Microsoft
- Summary
- Microsoft Defender for Office 365 will enhance the Teams message entity flyout by late September 2026, enabling security admins to submit messages to Microsoft and block senders or domains in one workflow. This streamlines Teams message investigations for Plan 1 and Plan 2 customers without requiring configuration changes.