SHD / MC Checker

MC1478463 | Microsoft Defender for Office 365: Teams user reporting enabled by default



MC1478463 | Microsoft Defender for Office 365: Teams user reporting enabled by default


Classification planForChange
Last Updated 09/24/2026 15:52:09
Start Time 09/24/2026 15:50:15
End Time 11/30/2026 08:00:00
Message Content

[What and why]

To help organizations identify and respond to security threats in Microsoft Teams, Microsoft Defender for Office 365 will enable Teams user reporting by default. Users can report suspicious messages, calls, and meetings, helping organizations improve detection of phishing, spam, impersonation, malicious content, and other threats.

This capability is available for organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5.

[Rollout schedule]

  • General Availability (Worldwide): Beginning in late October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations licensed for Microsoft Defender for Office 365 Plan 1 or Plan 2, Microsoft 365 E5, or Office 365 E5
  • Microsoft Teams and security administrators
  • Teams users in affected organizations

Platforms/Services

  • Microsoft Teams
  • Microsoft Defender portal
  • Microsoft Defender for Office 365

What will happen

  • Users can report suspicious messages, calls, and meetings directly from Teams. Reported content is submitted per your configured reported destination for security analysis.
  • Security risk items can include phishing, spam, impersonation, malicious content, and phishing URLs.
  • Beginning October 7, 2026, Teams user-reported settings will be managed on a dedicated page in the Microsoft Defender portal. 
  • If you have already configured Teams user-reported settings, your existing settings will be carried over. Changes made after migration may not be reflected until the week of October 15, 2026.
  • If you have not already configured Teams user-reported settings, Teams user reporting will be enabled by default beginning October 25, 2026, unless you opt out. 

Image 1 – Teams user reported settings view:  

Image 2 – Email user reported settings view:

[Action required/Recommendations]

Review your Teams user-reported settings before October 25, 2026, if you do not want Teams user reporting enabled by default or want reported content sent to a destination other than Microsoft.

Recommended actions:

  • Review Teams user-reported settings in the Microsoft Defender portal.
  • Decide whether user-reported Teams content should be submitted to Microsoft for security analysis.
  • Opt out before October 25, 2026, if desired.
  • Inform security administrators and help desk staff about this change.

Learn More

[Compliance considerations]

Question Answer
Does the change alter how admins can monitor, report on, or demonstrate compliance activities? Teams user-reported settings will move to a dedicated configuration page in the Defender portal.
Does the change include an admin control, and can it be controlled through Entra ID group membership? Administrators can opt out by configuring Teams user-reported settings in the Defender portal. Group-based controls are not specified.

Machine Translation

[何となぜ]

組織がMicrosoft Teamsのセキュリティ脅威を特定し対応できるようにするため、Microsoft Defender for Office 365はデフォルトでTeamsユーザー報告を有効にします。ユーザーは疑わしいメッセージ、電話、会議を報告でき、組織がフィッシング、スパム、なりすまし、悪意のあるコンテンツ、その他の脅威の検出を改善するのに役立ちます。

この機能は、Microsoft Defender for Office 365 Plan 1またはPlan 2、Microsoft 365 E5、またはOffice 365 E5のライセンスを持つ組織で利用可能です。

[展開スケジュール]

  • 一般公開(世界):2026年10月下旬から始まり、2026年10月下旬までに完了予定です

[組織への影響]

影響を受ける人物

  • Microsoft Defender for Office 365 Plan 1またはPlan 2、Microsoft 365 E5、またはOffice 365 E5のライセンスを受けた組織
  • Microsoft Teamsとセキュリティ管理者
  • 影響を受ける組織のTeamsユーザー

プラットフォーム/サービス

  • Microsoft Teams
  • Microsoft Defender ポータル
  • Microsoft Defender for Office 365

何が起こるのか

  • ユーザーはTeamsから直接、疑わしいメッセージ、通話、会議を報告できます。報告されたコンテンツは、設定済みの報告先に基づいてセキュリティ分析のために提出されます。
  • セキュリティリスク項目には、フィッシング、スパム、なりすまし、悪意のあるコンテンツ、フィッシングURLなどが含まれます。
  • 2026年10月7日以降、Teamsのユーザー報告設定はMicrosoft Defenderポータル内の専用ページで管理されます。 
  • すでにTeamsのユーザー報告設定を設定している場合、既存の設定は引き継がれます。移行後の変更は2026年10月15日の週まで反映されない場合があります。
  • もしまだTeamsのユーザー報告設定を設定していない場合、2026年10月25日以降、Teamsのユーザー報告はデフォルトで有効になります。ただし、オプトアウトしない限り。 

画像1 – Teamsユーザー報告設定ビュー:  

画像2 – メールユーザー報告設定表示:

[行動必要/提言]

Teamsユーザーレポートをデフォルトで有効にしたい場合や、報告されたコンテンツをMicrosoft以外の宛先に送りたい場合は、2026年10月25日までにTeamsのユーザー報告設定を確認してください。

推奨される行動:

  • Microsoft DefenderポータルのTeamsユーザー報告設定を確認してください。
  • ユーザー報告したTeamsコンテンツをMicrosoftに提出してセキュリティ分析を行うべきかどうかを判断してください。
  • 希望すれば2026年10月25日までにオプトアウトしてください。
  • この変更についてセキュリティ管理者やヘルプデスクスタッフに知らせてください。

詳細はこちら

[コンプライアンスの考慮事項]

質問 回答
この変更は管理者がコンプライアンス活動を監視、報告、または示す方法に変化をもたらしますか? Teamsのユーザー報告設定はDefenderポータル内の専用設定ページに移動します。
変更には管理者権限が含まれていますか?また、Entra IDのグループメンバーシップを通じて管理できますか? 管理者はDefenderポータルでTeamsのユーザー報告設定を設定することでオプトアウトできます。グループベースのコントロールは指定されていません。