Microsoft is set to launch a new Security Detection Report within the Teams admin center, providing administrators with a unified platform to track messaging threats across their organizations. This development, identified as Microsoft 365 Roadmap ID 560702, integrates previously scattered threat signals into a single, accessible dashboard.
Centralized Threat Monitoring
The upcoming report, categorized under Analytics & Reports > Protection Reports > Security Detections, consolidates three major types of messaging threats: impersonation attempts, malicious URLs, and risky file types. This integration simplifies the process for security teams, who previously had to use multiple tools to identify and respond to threats in Teams chats and channels.
The report features a centralized chart that displays detection volumes over specified dates, along with a comprehensive table detailing individual threats. This setup allows investigators to quickly access contextual information such as sender and recipient data, detection type, and thread identifiers.
Enhanced Data Export and Blocking Features
Besides offering detailed visibility, the report enables data export. Administrators can download chart summaries and table records as CSV files, facilitating integration into broader security information and event management (SIEM) systems or for documentation in compliance reviews.
An early preview of the report highlights a practical feature: the ability to block malicious external users directly through External Access settings, effectively reducing response time to threats.
Timeline and Additional Security Measures
The release date for this report has been adjusted several times. Initially slated for mid-July 2026, it was postponed to late June, with the latest update indicating general availability by late August 2026, and a global rollout by early September 2026 for standard multi-tenant customers.
These schedule changes suggest Microsoft is fine-tuning detection logic and reporting infrastructure, an essential step considering Teams’ role in enterprise collaboration and its consequent vulnerability to cyber attacks.
This new report addresses a longstanding gap, as admins previously depended on the broader Microsoft Defender portal for email and collaboration reports. By introducing Teams-specific detections, Microsoft is enhancing security visibility where it is most needed.
Future Outlook
This initiative is complemented by another update: user-reported security signals, allowing users to flag suspicious messages directly in Teams. These reports are integrated into the same Protection Reports section, indicating Microsoft’s commitment to a comprehensive security framework within Teams.
Security teams are advised to ensure malicious link and file scanning settings are active under Messaging Safety, and to update their response protocols to include Teams as a critical signal source once the report is fully operational.
