Share via


End user reporting for Security

In organizations with Microsoft Defender for Office 365 Plan 2 or Microsoft Defender XDR, admins can decide whether users can report malicious messages in Microsoft Teams. Security admins can also get visibility into the Teams messages that users are reporting.

Users can report messages in Teams from chats and channels for security concern and for incorrect detection.

User experience in Teams – Report Security Concern

Users who see a concerning chat or a channel message in Teams can report it as a security risk. To report a message:

  1. Go to chat or channel message and select … > Report this message.

  2. Select Security concern. Depending on the organization settings, you maybe asked to choose a reason for reporting the message.

  3. Review the selections and select Report.

Screenshot of selecting 'Report this message'.    

Screenshot of 'Report message as security risk'.

User reporting settings for Teams messages – Security Concern

'Report a security concern' reporting of messages in Teams is made of two separate settings:

  • In the Teams admin center: 'On' by default and controls whether users are able to report messages from Teams. When this setting is turned off, users can't report messages within Teams, so the corresponding setting in the Microsoft Defender portal is irrelevant.
  • In the Microsoft Defender portal: 'On' by default for new tenants. Existing tenants need to enable it. If user reporting of messages is turned on in the Teams admin center, it also needs to be turned on in the Defender portal for user reported messages to show up correctly on the User reported tab on the Submissions page.

Turn off or turn on user reporting for security concerns in Teams admin center.

  1. Sign in to the Teams Admin Center at https://admin.teams.microsoft.com.
  2. In the left navigation, select Messaging policies.
  3. Select a policy.
  4. Turn on the setting: Report a security concern.
  5. Select Save to apply the changes.

Screenshot of turning on user reporting for security concerns in Teams admin center.

Learn about turning off or turning on user reporting of Teams messages in the Defender portal.

User experience in Teams – Report Not a Security Concern

Note

The feature 'Not a Security Concern' is in preview.

Users can report messages in Teams chats or channels that are incorrectly flagged by Link Protection as containing malicious URLs.

To report a message as not a security concern:

  1. In the Teams chat or channel, locate the message that was flagged.
  2. Hover over the message without selecting it.
  3. Select ... More options > Report this message.
  4. In the report dialog that opens, select Not a security concern.
  5. Select Report to submit your feedback.

Screenshot of 'Report this message' for 'report not a security concern.    

Screenshot of 'Report not a security concern'.

User reporting settings for Teams messages – Not a Security Concern

Note

The feature 'Not a security concern' is in preview.

Incorrect detection (Not a security concern) reporting of messages in Teams is made of two separate settings:

  • In the Teams admin center: The setting controls whether users are able to report incorrect detections on messages flagged as security risks from Teams. When this setting is turned off, users can't report messages within Teams, so the corresponding setting in the Microsoft Defender portal is irrelevant.
  • In the Microsoft Defender portal: 'On' by default for new tenants. Existing tenants need to enable it. If user reporting of messages is turned on in the Teams admin center, it also needs to be turned on in the Defender portal for user reported messages to show up correctly on the User reported tab on the Submissions page.

Turn off or turn on user reporting for incorrect detections concerns in Teams admin center

  1. Sign in to the Teams Admin Center at https://admin.teams.microsoft.com.
  2. In the left navigation, select Messaging settings.
  3. Scroll down to Messaging safety settings.
  4. Turn on the setting: Report incorrect security detections.
  5. Select Save to apply the changes.

Screenshot of turning on 'Report incorrect security detections'.

Learn about turning off or turning on user reporting of Teams messages in the Defender portal.

User reported message settings in Microsoft Teams

Manage messaging policies in Teams