News thumbnail
Technology / Sun, 09 Aug 2026 CyberSecurityNews

Microsoft to Launch New Security Detection Report in Teams

Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to monitor messaging-based threats across their organization. Teams Security Detection ReportThe new report will live under Analytics & Reports > Protection Reports > Security Detections in the Teams admin center, and it consolidates three critical categories of messaging threats: impersonation attempts, malicious URLs, and weaponizable file types. Teams Security Detection ReportEach entry can be reviewed for context such as sender and recipient information, detection type, and thread identifiers, giving investigators enough forensic depth to act quickly on suspicious conversations. By surfacing Teams-specific detections directly where administrators already manage the platform, Microsoft is closing a visibility gap that security teams have flagged for a while. Together, these two capabilities point to Microsoft building a more comprehensive, native security telemetry layer inside Teams.

Microsoft is preparing to roll out a new Security Detection Report inside the Teams admin center, giving administrators a long-awaited, unified way to monitor messaging-based threats across their organization.

The feature, tracked under Microsoft 365 Roadmap ID 560702, brings together previously scattered threat signals into a single dashboard, making it significantly easier for security teams to spot and respond to malicious activity happening through Teams chats and channels.

Teams Security Detection Report

The new report will live under Analytics & Reports > Protection Reports > Security Detections in the Teams admin center, and it consolidates three critical categories of messaging threats: impersonation attempts, malicious URLs, and weaponizable file types.

Instead of admins having to cross-reference multiple tools to piece together a picture of ongoing attacks, the report presents a centralized chart showing detection volume over a selected date range, paired with a detailed table listing individual detections.

Teams Security Detection Report

Each entry can be reviewed for context such as sender and recipient information, detection type, and thread identifiers, giving investigators enough forensic depth to act quickly on suspicious conversations.

Beyond just visibility, the report supports exportable data. Admins can download both chart-level summaries and full table records as CSV files, which is particularly useful for feeding data into broader security information and event management (SIEM) workflows or for documenting incidents during compliance reviews.

One especially practical capability highlighted by early previews is the direct path to blocking malicious external users straight from the report via External Access settings, cutting down the time between detection and containment.

Microsoft’s rollout timeline for this feature has shifted more than once. It was originally expected in mid-July 2026, then pushed to late June, and the most recent update from Microsoft places general availability starting in late August 2026, with a global rollout expected to complete by early September 2026 for worldwide standard multi-tenant customers.

The repeated timeline revisions suggest Microsoft is still refining the detection logic and reporting infrastructure before pushing it broadly, which is a sensible move given how central Teams has become to enterprise collaboration and, by extension, to attacker targeting.

Teams has increasingly become a vector for phishing-style impersonation, malicious link delivery, and file-based malware drops, mirroring tactics long seen in email-based attacks.

Until now, admins lacked a purpose-built, centralized way to track these detections natively within the Teams admin center, often relying on the Microsoft Defender portal’s broader email and collaboration reports instead.

By surfacing Teams-specific detections directly where administrators already manage the platform, Microsoft is closing a visibility gap that security teams have flagged for a while.

This launch also complements a related update already rolling out: user-reported security signals, which let end users flag suspicious messages directly from Teams, with those reports now feeding into the same Protection Reports section.

Together, these two capabilities point to Microsoft building a more comprehensive, native security telemetry layer inside Teams. Security teams should use the coming weeks to confirm that malicious link and file scanning settings are enabled under Messaging Safety, and update their investigation runbooks to treat Teams as a first-class signal source once the report reaches general availability.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

© All Rights Reserved.