Microsoft is preparing to give Teams administrators a purpose-built way to monitor messaging-based threats, rolling out a new Security Detection Report inside the Teams admin center. Tracked under Microsoft 365 Roadmap ID 560702, the feature consolidates several previously scattered threat signals into a single dashboard, making it considerably easier for security teams to spot and act on malicious activity happening inside chats and channels.
One Dashboard for Three Threat Categories
The report will live under Analytics & Reports > Protection Reports > Security Detections in the Teams admin center. It brings together three categories of messaging threats that previously required admins to cross-reference multiple tools to fully understand: impersonation attempts, malicious URLs, and weaponizable file types.
Instead of piecing together a picture of an ongoing attack from disparate sources, admins get a centralized chart showing detection volume across a selected date range, alongside a detailed table listing individual detections. Each entry includes sender and recipient information, the detection type, and thread identifiers — enough forensic depth for an investigator to act on a suspicious conversation quickly rather than starting from scratch.
Built for Real Investigations, Not Just Visibility
The report isn’t purely informational. Both chart-level summaries and full table records can be exported as CSV files, which is useful for feeding detection data into broader SIEM workflows or for documentation during compliance reviews.
One particularly practical capability surfaced in early previews is a direct path to blocking malicious external users straight from the report via External Access settings — shortening the gap between spotting a threat and actually containing it, rather than requiring admins to jump into a separate settings panel.
A Rollout Timeline That Keeps Slipping
Microsoft’s timeline for this feature has moved more than once. It was originally expected in mid-July 2026, then pushed to late June, and the most recent update places general availability starting in late August 2026, with a global rollout to worldwide standard multi-tenant customers expected to complete by early September 2026.
The repeated revisions suggest Microsoft is still tuning the underlying detection logic and reporting infrastructure before a broad release — a reasonable choice given how central Teams has become to enterprise collaboration, and consequently to attacker targeting.
Closing a Gap Attackers Have Been Exploiting
Teams has increasingly become a vector for phishing-style impersonation, malicious link delivery, and file-based malware drops, mirroring tactics that have long been standard in email-based attacks. Until now, admins lacked a purpose-built, centralized way to track these detections natively within the Teams admin center itself, often falling back on the Microsoft Defender portal’s broader email and collaboration reports to get a partial picture.
By surfacing Teams-specific detections directly where administrators already manage the platform, Microsoft is closing a visibility gap that security teams have flagged for some time. The launch also complements an already-rolling-out related update: user-reported security signals, which let end users flag suspicious messages directly from within Teams, with those reports feeding into the same Protection Reports section.
What Security Teams Should Do Now
Together, these two capabilities point toward Microsoft building a more comprehensive, native security telemetry layer inside Teams rather than treating it as a secondary surface behind email. Ahead of general availability, security teams are advised to:
- Confirm that malicious link and file scanning settings are enabled under Messaging Safety
- Update incident investigation runbooks to treat Teams as a first-class signal source, not an afterthought
- Plan for CSV export of detection data into existing SIEM pipelines once the report reaches general availability
As collaboration platforms continue absorbing more of the traffic that used to run exclusively through email, native, platform-specific detection tooling like this is likely to become table stakes rather than a differentiator — and organizations that wait until attacks land in Teams to build a response process will be behind the curve.
Leave a Reply