You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-for-identity/whats-new.md
+5Lines changed: 5 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,6 +23,11 @@ For more information, see also:
23
23
24
24
For updates about versions and features released six months ago or earlier, see the [What's new archive for Microsoft Defender for Identity](whats-new-archive.md).
25
25
26
+
## December 2025
27
+
|Version number |Updates |
28
+
|---------|---------|
29
+
|2.252|Includes bug fixes and stability improvements for the Microsoft Defender for Identity sensor.|
Copy file name to clipboardExpand all lines: defender-office-365/mdo-support-teams-about.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.collection:
16
16
- tier1
17
17
description: Admins can learn about Microsoft Teams features in Microsoft Defender for Office 365.
18
18
ms.service: defender-office-365
19
-
ms.date: 09/11/2025
19
+
ms.date: 10/27/2025
20
20
appliesto:
21
21
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -58,6 +58,9 @@ Microsoft 365 E5 and Defender for Office 365 Plan 2 extend Teams protection with
58
58
59
59
-**Teams message entity panel**: A single place to store all Teams message metadata for immediate SecOps review. Any threats coming from Teams chats, group chats, meeting chats, and other channels can be found in one place as soon as they're assessed. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
60
60
61
+
> [!TIP]
62
+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
63
+
61
64
-**Attack simulation training using Teams messages**: To ensure users are resilient to phishing attacks in Microsoft Teams, admins can configure phishing simulations using Teams messages instead of email messages. For more information, see [Microsoft Teams in Attack simulation training](attack-simulation-training-teams.md).
62
65
63
66
-**Hunting on Teams messages with URLs**: You can hunt for Teams messages containing URL across three new advanced hunting tables: [MessageEvents](/defender-xdr/advanced-hunting-messageevents-table), [MessagePostDeliveryEvents](/defender-xdr/advanced-hunting-messagepostdeliveryevents-table), and [MessageURLInfo](/defender-xdr/advanced-hunting-messageurlinfo-table).
Copy file name to clipboardExpand all lines: defender-office-365/quarantine-admin-manage-messages-files.md
+13-3Lines changed: 13 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ ms.custom:
18
18
- seo-marvel-apr2020
19
19
description: Admins can learn how to view and manage quarantined messages for all users in Microsoft 365 organizations with cloud mailboxes. Admins in organizations with Microsoft Defender for Office 365 can also manage quarantined files in SharePoint, OneDrive, and Microsoft Teams.
20
20
ms.service: defender-office-365
21
-
ms.date: 10/07/2025
21
+
ms.date: 10/27/2025
22
22
appliesto:
23
23
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
24
24
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -789,7 +789,7 @@ The next section in the details flyout is related to quarantined Teams messages:
789
789
-**Policy name**: The value is **Teams Protection Policy**.
790
790
-**Quarantine policy**
791
791
792
-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
792
+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
793
793
794
794
When you're finished in the details flyout, select **Close**.
795
795
@@ -811,7 +811,7 @@ On the **Teams messages** tab, select the quarantined message by using either of
811
811
812
812
Using either method to select the message, some actions are available under :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More**.
813
813
814
-
After you select the quarantined message, the available actions are described in the following subsections.
814
+
After you select the quarantined Teams message, the available actions are described in the following subsections.
815
815
816
816
#### Release quarantined Teams messages
817
817
@@ -878,6 +878,16 @@ By default, The .html message file is saved in a compressed file named Quarantin
878
878
879
879
Back on the **Download messages** flyout, select **Done**.
880
880
881
+
#### Remove users from quarantined Teams chats
882
+
883
+
> [!TIP]
884
+
> Currently, this feature is in Preview, isn't available in all organizations, and is subject to change.
885
+
886
+
1. On the **Teams messages** tab, select the Teams message by clicking anywhere in the row other than the check box next to the first column.
887
+
2. In the details flyout that opens (the Teams message entity panel), select :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More actions**\> :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout.
888
+
889
+
For complete instructions, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
890
+
881
891
#### Take action on multiple quarantined Teams messages
882
892
883
893
When you select multiple quarantined messages on the **Teams messages** tab by selecting the check boxes next to the first column, the following bulk actions are available on the **Teams messages** tab:
title: (False Negatives) How to handle malicious emails that are delivered to recipients using Microsoft Defender for Office 365
3
-
description: The steps to handle malicious emails coming through to end users and inboxes (as False Negatives) with Microsoft Defender for Office 365 in order to prevent loss of business.
2
+
title: (False negatives) How to use Microsoft Defender for Office 365 to handle malicious emails delivered to recipients.
3
+
description: Steps in Microsoft Defender for Office 365 to handle malicious emails delivered to end users (false negatives) to prevent the loss of business.
4
4
ms.service: defender-office-365
5
5
f1.keywords:
6
6
- NOCSH
@@ -15,37 +15,37 @@ ms.collection:
15
15
- tier3
16
16
ms.topic: how-to
17
17
search.appverid: met150
18
-
ms.date: 01/31/2023
18
+
ms.date: 12/08/2025
19
19
---
20
20
21
-
# How to handle malicious emails that are delivered to recipients (False Negatives), using Microsoft Defender for Office 365
21
+
# How to handle malicious emails that are delivered to recipients (false negatives) using Microsoft Defender for Office 365
22
22
23
-
Microsoft Defender for Office 365 helps deal with malicious emails (False Negative) that are delivered to recipients and that put your organizational productivity at risk.
23
+
Microsoft Defender for Office 365 helps deal with undetected malicious email delivered to recipients (known as false negatives) that put your organizational productivity at risk.
24
24
25
-
Defender for Office 365 can help you understand whyemails are getting delivered, how to resolve the situation quickly, and how to prevent similar situations from happening in the future.
25
+
Defender for Office 365 can help admins understand *why* malicious emails were delivered, how to quickly resolve the issue, and how to prevent similar issues from happening in the future.
26
26
27
-
## What you'll need
27
+
## What you need
28
28
29
-
- Microsoft Defender for Office 365 Plan 1 and 2 (included as part of E5). Exchange Online customers can also leverage this.
- Microsoft Defender for Office 365 Plan 1 or Plan 2. Microsoft 365 A5/E5/G5 includes Plan 2.
30
+
- Sufficient permissions. For example, membership in the **Security Administrator** role in [Microsoft Entra ID](/entra/identity/role-based-access-control/manage-roles-portal).
31
+
- 5-10 minutes to perform the following steps.
32
32
33
33
## Handling malicious emails in the Inbox folder of end users
34
34
35
-
1. Ask end users to report the email as **phishing** or **junk** using Microsoft Message Add-in or Microsoft Phish add-in or the Outlook buttons.
36
-
2. End users can also add the sender to the [block senders list](https://support.microsoft.com/office/block-a-mail-sender-b29fd867-cac9-40d8-aed1-659e06a706e4#:~:text=1%20On%20the%20Home%20tab%2C%20in%20the%20Delete,4%20Click%20OK%20in%20both%20open%20dialog%20boxes..) in Outlook to prevent emails from this sender from being delivered to their inbox.
35
+
1. Ask end users to report the email as **Phishing** or **Junk** using the [built-in **Report** button in supported versions of Outlook](../submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook).
36
+
2. End users can also add senders to their **[Blocked Senders List](https://support.microsoft.com/office/block-or-unblock-senders-in-outlook-9bf812d4-6995-4d19-901a-76d6e26939b0#picktab=classic_outlook)** in Outlook to prevent emails from this sender from being delivered to their inbox.
37
37
3. Admins can triage the user reported messages from [User reported tab on the Submissions page](../submissions-admin.md#view-user-reported-messages-to-microsoft).
38
38
4. From those reported messages, admins can **submit to**[Microsoft for analysis](../submissions-admin-review-user-reported-messages.md#notify-users-from-within-the-portal) to learn why that email was allowed in the first place.
39
39
5. If needed, while submitting to Microsoft for analysis, admins can [create a block entry for the sender](../tenant-allow-block-list-email-spoof-configure.md#create-block-entries-for-domains-and-email-addresses) to mitigate the problem.
40
-
6. Once the results for submissions are available, read the verdict to understand why emails were allowed, and how your tenant setup could be improved to prevent similar situations from happening in the future.
40
+
6. Once the results for submissions are available, read the verdict to understand why emails were allowed, and how your organization setup could be improved to prevent similar issues from happening in the future.
41
41
42
42
## Handling malicious emails in junk folder of end users
43
43
44
-
1. Ask end users to report the email as **phishing** using Microsoft Message Add-in, or Microsoft Phish Add-in, or the Outlook buttons.
44
+
1. Ask end users to report the email as **phishing** using the [built-in**Report** button in supported versions of Outlook](../submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook).
45
45
2. Admins can triage the user reported messages from the [User reported tab on the Submissions page](../submissions-admin.md#view-user-reported-messages-to-microsoft).
46
46
3. From those reported messages admins can **submit to**[Microsoft for analysis](../submissions-admin.md#notify-users-about-admin-submitted-messages-to-microsoft) and learn why that email was allowed in the first place.
47
47
4. If needed, while submitting to Microsoft for analysis, admins can [create a block entry for the sender](../tenant-allow-block-list-email-spoof-configure.md#create-block-entries-for-domains-and-email-addresses) to mitigate the problem.
48
-
5. Once the results for submissions are available, read the verdict to understand why emails were allowed, and how your tenant setup could be improved to prevent similar situations from happening in the future.
48
+
5. Once the results for submissions are available, read the verdict to understand why emails were allowed, and how your organization setup could be improved to prevent similar issues from happening in the future.
49
49
50
50
## Handling malicious emails landing in the quarantine folder of end users
51
51
@@ -55,5 +55,5 @@ Defender for Office 365 can help you understand why emails are getting delivered
55
55
## Handling malicious emails landing in the quarantine folder of admins
56
56
57
57
1. Admins can view the quarantined emails (including the ones asking permission to request release) from the [review page](../quarantine-admin-manage-messages-files.md).
58
-
2. Admins can submit any malicious, or suspicious messages to Microsoft for analysis, and create a block to mitigate the situation while waiting for verdict.
59
-
3. Once the results for submissions are available, read the verdict to learn why the emails were allowed, and how your tenant setup could be improved to prevent similar situations from happening in the future.
58
+
2. Admins can submit any malicious, or suspicious messages to Microsoft for analysis, and create a block to mitigate the issue while waiting for a verdict.
59
+
3. Once the results for submissions are available, read the verdict to learn why the emails were allowed, and how your organization setup could be improved to prevent similar issues from happening in the future.
title: (False Positives) How to handle legitimate emails getting blocked from delivery using Microsoft Defender for Office 365
3
-
description: The steps to handle legitimate email getting blocked(False Positive) by Microsoft Defender for Office 365 in order to prevent lose of business.
2
+
title: (False positives) How to use Microsoft Defender for Office 365 to handle legitimate emails that were blocked from delivery to recipients.
3
+
description: Steps in Microsoft Defender for Office 365 to handle legitimate emails getting blocked from delivery to end users (false positives) to prevent the loss of business.
4
4
ms.service: defender-office-365
5
5
f1.keywords:
6
6
- NOCSH
@@ -15,27 +15,29 @@ ms.collection:
15
15
- tier3
16
16
ms.topic: how-to
17
17
search.appverid: met150
18
-
ms.date: 01/31/2023
18
+
ms.date: 12/08/2025
19
19
---
20
20
21
-
# How to handle Legitimate emails getting blocked (False Positive), using Microsoft Defender for Office 365
21
+
# How to handle legitimate emails getting blocked (false positives) using Microsoft Defender for Office 365
22
22
23
-
Microsoft Defender for Office 365 helps deal with important legitimate business emails that are mistakenly blocked as threats (False Positives). Defender for Office 365 can help admins understand *why* legitimate emails are being blocked, how to resolve the situation quickly, and prevent similar situations from happening in the future.
23
+
Microsoft Defender for Office 365 helps deal with legitimate business emails that are mistakenly blocked as threats (known as false positives).
24
24
25
-
## What you'll need
25
+
Defender for Office 365 can help admins understand *why* legitimate emails were blocked, how to quickly resolve the issue, and how to prevent similar issues from happening in the future.
26
26
27
-
- Microsoft Defender for Office 365 Plan 1 or 2 (included as part of E5). Exchange Online customers can also leverage this feature.
- Microsoft Defender for Office 365 Plan 1 or Plan 2. Microsoft 365 A5/E5/G5 includes Plan 2.
30
+
- Sufficient permissions. For example, membership in the **Security Administrator** role in [Microsoft Entra ID](/entra/identity/role-based-access-control/manage-roles-portal).
31
+
- 5-10 minutes to perform the following steps.
30
32
31
33
## Handling legitimate emails in to Junk folder of end users
32
34
33
-
1. Ask end users to report the email as **not junk** using Microsoft Message Add-in or the Outlook buttons.
34
-
2. End users can also add the sender to the [**safe sender list**](https://support.microsoft.com/office/safe-senders-in-outlook-com-470d4ee6-e3b6-402b-8cd9-a6f00eda7339) in Outlook to prevent the email from these senders landing in Junk folder.
35
+
1. Ask end users to report the email as **Not junk** using the [built-in **Report** button in supported versions of Outlook](../submissions-outlook-report-messages.md#use-the-built-in-report-button-in-outlook).
36
+
2. End users can also add senders to their **[Safe Sender List](https://support.microsoft.com/office/add-recipients-to-the-safe-senders-list-in-outlook-be1baea0-beab-4a30-b968-9004332336ce)** in Outlook to prevent messages from these senders landing in Junk folder.
35
37
3. Admins can triage the user-reported messages from [the User reported tab on the Submission page](../submissions-admin.md#view-user-reported-messages-to-microsoft).
36
38
4. From those reported messages admins can submit to [**Microsoft for analysis**](../submissions-admin.md#notify-users-about-admin-submitted-messages-to-microsoft) and understand why was that email blocked in the first place.
37
39
5. If needed, while submitting to Microsoft for analysis, admins can judiciously [create an allow entry for the sender](../tenant-allow-block-list-email-spoof-configure.md#create-allow-entries-for-domains-and-email-addresses) to mitigate the problem.
38
-
6. Once the results from the admin submission are available, read it to understand why emails were blocked and how your tenant setup could be improved to *prevent* similar situations from happening in the future.
40
+
6. Once the results from the admin submission are available, read it to understand why emails were blocked and how your organization setup could be improved to *prevent* similar issues from happening in the future.
39
41
40
42
## Handling legitimate emails that are in quarantine folder of end users
41
43
@@ -45,10 +47,10 @@ Microsoft Defender for Office 365 helps deal with important legitimate business
45
47
## Handling legitimate emails in quarantine folder of an admin
46
48
47
49
1. Admins can view the quarantined emails (including the ones asking permission to request release) from the [review page](../quarantine-admin-manage-messages-files.md).
48
-
2. Admins can release the message from quarantine while submitting it to Microsoft for analysis, and create a temporary allow to mitigate the situation.
50
+
2. Admins can release the message from quarantine while submitting it to Microsoft for analysis. They can also create a temporary allow entry in the Tenant Allow/Block List during the submission to Microsoft to mitigate the issue.
49
51
3. Once the results for submissions are available, admins should read the verdict to understand the reason.
50
-
- If false positives are due to tenant configuration, admins can correct it to mitigate the issue.
52
+
- If false positives are due to organization configuration, admins can correct it to mitigate the issue.
51
53
- If false positives are due to other factors, Microsoft learns from the submission and similar messages aren't quarantined anymore.
52
54
53
55
> [!NOTE]
54
-
> Admins need to manually release any similar messages that have already been quarantined, as the quarantined messages aren't released automatically. To find and release quarantined messages in bulk, see [Can I release or report more than one quarantined message at a time?](../quarantine-faq.yml#can-i-release-or-report-more-than-one-quarantined-message-at-a-time-)
56
+
> Admins need to manually release any similar quarantined messages. Quarantined messages aren't released automatically. To find and release quarantined messages in bulk, see [Can I release or report more than one quarantined message at a time?](../quarantine-faq.yml#can-i-release-or-report-more-than-one-quarantined-message-at-a-time-)
0 commit comments