Microsoft is adding a faster way for security teams to act on suspicious Teams messages, rolling out through Microsoft Defender for Office 365 from late September.
- What it is: A new remediation option inside the Teams message investigation flyout that lets administrators submit a suspicious message to Microsoft and block the sender or domain in a single step.
- Who is affected: Organisations using Microsoft Defender for Office 365 Plan 1 or Plan 2.
- Why it matters: This closes the gap between spotting a suspicious Teams message and actually blocking the sender, reducing the window attackers have to run phishing or scam messages through Teams.
- What to do: No action is required before the rollout completes, expected by mid-October 2026. We recommend updating your internal security procedures once the feature appears, so your team knows to use the one-click option rather than manual blocking steps.
This is a welcome tightening of the response process for any business relying on Teams for day-to-day communication.