You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/mdo-support-teams-about.md
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.collection:
16
16
- tier1
17
17
description: Admins can learn about Microsoft Teams features in Microsoft Defender for Office 365.
18
18
ms.service: defender-office-365
19
-
ms.date: 09/11/2025
19
+
ms.date: 10/27/2025
20
20
appliesto:
21
21
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -58,6 +58,9 @@ Microsoft 365 E5 and Defender for Office 365 Plan 2 extend Teams protection with
58
58
59
59
-**Teams message entity panel**: A single place to store all Teams message metadata for immediate SecOps review. Any threats coming from Teams chats, group chats, meeting chats, and other channels can be found in one place as soon as they're assessed. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
60
60
61
+
> [!TIP]
62
+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
63
+
61
64
-**Attack simulation training using Teams messages**: To ensure users are resilient to phishing attacks in Microsoft Teams, admins can configure phishing simulations using Teams messages instead of email messages. For more information, see [Microsoft Teams in Attack simulation training](attack-simulation-training-teams.md).
62
65
63
66
-**Hunting on Teams messages with URLs**: You can hunt for Teams messages containing URL across three new advanced hunting tables: [MessageEvents](/defender-xdr/advanced-hunting-messageevents-table), [MessagePostDeliveryEvents](/defender-xdr/advanced-hunting-messagepostdeliveryevents-table), and [MessageURLInfo](/defender-xdr/advanced-hunting-messageurlinfo-table).
Copy file name to clipboardExpand all lines: defender-office-365/quarantine-admin-manage-messages-files.md
+13-3Lines changed: 13 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ ms.custom:
18
18
- seo-marvel-apr2020
19
19
description: Admins can learn how to view and manage quarantined messages for all users in Microsoft 365 organizations with cloud mailboxes. Admins in organizations with Microsoft Defender for Office 365 can also manage quarantined files in SharePoint, OneDrive, and Microsoft Teams.
20
20
ms.service: defender-office-365
21
-
ms.date: 10/07/2025
21
+
ms.date: 10/27/2025
22
22
appliesto:
23
23
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
24
24
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -789,7 +789,7 @@ The next section in the details flyout is related to quarantined Teams messages:
789
789
-**Policy name**: The value is **Teams Protection Policy**.
790
790
-**Quarantine policy**
791
791
792
-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
792
+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
793
793
794
794
When you're finished in the details flyout, select **Close**.
795
795
@@ -811,7 +811,7 @@ On the **Teams messages** tab, select the quarantined message by using either of
811
811
812
812
Using either method to select the message, some actions are available under :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More**.
813
813
814
-
After you select the quarantined message, the available actions are described in the following subsections.
814
+
After you select the quarantined Teams message, the available actions are described in the following subsections.
815
815
816
816
#### Release quarantined Teams messages
817
817
@@ -878,6 +878,16 @@ By default, The .html message file is saved in a compressed file named Quarantin
878
878
879
879
Back on the **Download messages** flyout, select **Done**.
880
880
881
+
#### Remove users from quarantined Teams chats
882
+
883
+
> [!TIP]
884
+
> Currently, this feature is in Preview, isn't available in all organizations, and is subject to change.
885
+
886
+
1. On the **Teams messages** tab, select the Teams message by clicking anywhere in the row other than the check box next to the first column.
887
+
2. In the details flyout that opens (the Teams message entity panel), select :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More actions**\> :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout.
888
+
889
+
For complete instructions, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
890
+
881
891
#### Take action on multiple quarantined Teams messages
882
892
883
893
When you select multiple quarantined messages on the **Teams messages** tab by selecting the check boxes next to the first column, the following bulk actions are available on the **Teams messages** tab:
Copy file name to clipboardExpand all lines: defender-office-365/submissions-admin.md
+8-6Lines changed: 8 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,7 +16,7 @@ ms.collection:
16
16
ms.custom: seo-marvel-apr2020
17
17
description: "Admins can learn how to use the Submissions page in the Microsoft Defender portal to submit messages, URLs, and email attachments to Microsoft for analysis. Reasons for submission include: legitimate messages that were blocked, suspicious messages that were allowed, suspected phishing email, spam, malware, and other potentially harmful messages."
18
18
ms.service: defender-office-365
19
-
ms.date: 09/11/2025
19
+
ms.date: 10/27/2025
20
20
appliesto:
21
21
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
22
22
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -556,9 +556,6 @@ When you're finished in the details flyout, select **Close**.
556
556
557
557
### View Teams admin submissions to Microsoft in Defender for Office 365 Plan 2
558
558
559
-
> [!TIP]
560
-
> [Submission of Teams message to Microsoft](submissions-teams.md) is currently in Preview, isn't available in all organizations, and is subject to change.
561
-
562
559
In the Defender portal at <https://security.microsoft.com>, go to the **Submissions** page at **Actions & submissions**\>**Submissions**. Or, to go directly to the **Submissions** page, use <https://security.microsoft.com/reportsubmission>.
563
560
564
561
On the **Submissions** page, select the **Teams messages** tab.
@@ -642,7 +639,10 @@ The next sections in the details flyout are related to Teams submissions:
642
639
-**Submitted by**
643
640
-**Submission status**
644
641
645
-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
642
+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
643
+
644
+
> [!TIP]
645
+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
646
646
647
647
When you're finished in the details flyout, select **Close**.
648
648
@@ -1120,9 +1120,11 @@ The next sections in the details flyout are related to user reported Teams submi
1120
1120
-**Phish simulation**: The value is **Yes** or **No**.
1121
1121
-**Converted to admin submission**: The value is **Yes** or **No**. For more information, see [View converted admin submissions](#view-converted-admin-submissions).
1122
1122
1123
-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
1123
+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
1124
1124
1125
1125
> [!TIP]
1126
+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
1127
+
>
1126
1128
> If the **Result** value is **Phish simulation**, the details flyout might contain the following information only:
Copy file name to clipboardExpand all lines: defender-office-365/submissions-outlook-report-messages.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.collection:
14
14
description: Learn how to report phishing and suspicious emails in supported versions of Outlook using the built-in Report button.
15
15
ms.service: defender-office-365
16
16
search.appverid: met150
17
-
ms.date: 09/28/2025
17
+
ms.date: 12/05/2025
18
18
appliesto:
19
19
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
20
20
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -51,7 +51,7 @@ The built-in **Report** button is available in the following versions of Outlook
51
51
- The new Outlook for Windows<sup>\*</sup>
52
52
- Outlook on the web<sup>\*</sup>
53
53
54
-
<sup>\*</sup> In this version of Outlook, the built-in **Report** button also supports reporting messages from shared mailboxes or other mailboxes by a delegate.
54
+
<sup>\*</sup> In this version of Outlook, the built-in **Report** button also supports reporting messages from shared mailboxes or other mailboxes by a delegate. The delegate user needs [Send As permissions](/microsoft-365/admin/add-users/give-mailbox-permissions-to-another-user) to report messages from the shared mailbox. Without Send As permission, the message is **not** sent to the reporting mailbox. Instead, the message is removed from the folder.
55
55
56
56
The **Report** button is available in supported versions of Outlook if both of the following conditions are true:
Copy file name to clipboardExpand all lines: defender-office-365/teams-message-entity-panel.md
+67-7Lines changed: 67 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -16,9 +16,9 @@ ms.collection:
16
16
- highpri
17
17
description: Describes the Teams message entity panel for Microsoft Teams in Microsoft Defender for Office 365 Plan 2, how it does post-breach work like ZAP and Safe Links and gives admins a single pane of glass on Teams chat and channel threats like suspicious URLs..
18
18
ms.service: defender-office-365
19
-
ms.date: 11/16/2023
19
+
ms.date: 10/27/2025
20
20
appliesto:
21
-
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
21
+
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
@@ -34,10 +34,12 @@ This article explains the information and actions on the Teams message entity pa
34
34
35
35
To use the Email entity page, you need to be assigned permissions. You have the following options:
36
36
37
-
-[Email & collaboration permissions in the Microsoft Defender portal](mdo-portal-permissions.md): Membership in the **Organization Management**, **Security Administrator**, or **Quarantine Administrator** role groups.
38
-
-[Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in these roles gives users the required permissions _and_ permissions for other features in Microsoft 365:
39
-
-_Full access_: Membership in the **Global Administrator**<sup>\*</sup> or **Security Administrator** roles.
40
-
-_Read-only access_: Membership in the **Global Reader** or **Security Reader** roles.
37
+
-_Full access_:
38
+
-[Email & collaboration permissions in the Microsoft Defender portal](mdo-portal-permissions.md): Membership in the **Organization Management**, **Security Administrator**, or **Quarantine Administrator** role groups.
39
+
-[Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in one of the following roles gives users the required permissions _and_ permissions for other features in Microsoft 365: **Global Administrator**<sup>\*</sup>, **Security Administrator**, or **Security Operator**.
40
+
-_Read-only access_:
41
+
- Microsoft Entra permissions: **Global Reader** or **Security Reader**.
42
+
-_[Remove users from Teams chats](#remove-users-from-teams-chats-in-the-teams-message-entity-panel)_: Requires membership in one of the following Microsoft Entra roles: **Global Administrator**<sup>\*</sup>, **Security Administrator**, or **Security Operator**.
41
43
42
44
> [!IMPORTANT]
43
45
> <sup>\*</sup> Microsoft strongly advocates for the principle of least privilege. Assigning accounts only the minimum permissions necessary to perform their tasks helps reduce security risks and strengthens your organization's overall protection. Global Administrator is a highly privileged role that you should limit to emergency scenarios or when you can't use a different role.
@@ -50,7 +52,25 @@ There are no direct links to the Teams message entity panel from the top levels
50
52
51
53
- From the **Submissions** page at <https://security.microsoft.com/reportsubmission>:
52
54
- Select the **Teams messages** tab \> select an entry by clicking anywhere in the row other than the check box.
53
-
- Select the **User reported** tab \> select a Teams entry by clicking anywhere in the row other than the check box. You can filter the entries by selecting :::image type="icon" source="media/m365-cc-sc-filter-icon.png" border="false"::: **Filter**\>**Message type**\>**Teams**. The details flyout that opens is the Teams message entity panel.
55
+
- Select the **User reported** tab \> select a Teams entry by clicking anywhere in the row other than the check box. The details flyout that opens is the Teams message entity panel.
56
+
57
+
You can filter the entries by selecting :::image type="icon" source="media/m365-cc-sc-filter-icon.png" border="false"::: **Filter**\>**Message type**\>**Teams**.
58
+
59
+
- From the **Advanced Hunting** page at <https://security.microsoft.com/v2/advanced-hunting>, select a **TeamsMessageId** value (link) from the **MessageEvents** table in the query results. The details flyout that opens is the Teams message entity panel. For example:
60
+
61
+
```kusto
62
+
UrlClickEvents
63
+
| where ThreatTypes !="" and Workload =="Teams"
64
+
| summarize count() by Url, ThreatTypes, ActionType, Workload
@@ -103,6 +123,46 @@ The rest of the Teams message entity panel contains the following information, r
103
123
104
124
:::image type="content" source="media/teams-message-entity-panel-shown-in-quarantine.png" alt-text="Screenshot of the Teams Message Entity panel from a quarantined Teams message showing the common sections." lightbox="media/teams-message-entity-panel-shown-in-quarantine.png":::
105
125
126
+
## Remove users from Teams chats in the Teams message entity panel
127
+
128
+
> [!TIP]
129
+
> Currently, this feature is in Preview, isn't available in all organizations, and is subject to change.
130
+
>
131
+
> You can only remove _internal_ users in your organization from a chat.
132
+
>
133
+
> When you remove users from a chat, the sender of the chat isn't blocked, and the removed users can start new chats with the sender.
134
+
135
+
In the Teams entity panel, you can select :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout (often under :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More actions**) to remove users from a Teams chat.
136
+
137
+
Do the following steps in the **Take action** wizard:
138
+
139
+
1. On the **Choose response actions** page, select **Remove user from conversation** from the **Conversation level actions** section, and then select **Next**.
140
+
2. On the **Choose target entities** page, configure the following options:
141
+
-**Name** Enter a unique, descriptive name for the remove user scenario.
142
+
-**Description**: Enter optional details.
143
+
144
+
The rest of the page contains a details table with the following information about the users in the chat:
145
+
146
+
-**Impacted asset**: The email address of the user.
147
+
-**Action**: This value is always **Remove user from conversation**.
148
+
-**Target entity**: The **Thread id** GUID value of the chat.
149
+
-**Expires on**
150
+
151
+
By default, all users in the chat are selected, including external users you can't remove from the chat. Verify the _internal_ users to remove from the chat are selected.
152
+
153
+
When you're finished on the **Choose target entities** page, select **Next**.
154
+
155
+
3. On the **Review and submit** page, review your previous selections.
156
+
157
+
Select **Back** to go back and change your selections.
158
+
159
+
When you're finished on the **Review and submit** page, select **Submit**.
160
+
161
+
Removing users from a Teams chat is recorded on the **History** tab of the **Action center** page at <https://security.microsoft.com/action-center/history>. You can filter the results by **Action type**\>**Remove users from Teams conversations** and/or **Entity type**\>**Teams message**. In the alert details, you can confirm users were or were not removed from the Teams chat.
162
+
163
+
> [!TIP]
164
+
> Removing users from Teams chats doesn't create an investigation ID or an automated investigation.
165
+
106
166
## For more information
107
167
108
168
[The Microsoft Defender for Office 365 Email Entity Page and how it works](mdo-email-entity-page.md)
Copy file name to clipboardExpand all lines: defender-office-365/tenant-allow-block-list-about.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ manager: bagol
8
8
audience: ITPro
9
9
ms.topic: how-to
10
10
ms.localizationpriority: medium
11
-
ms.date: 09/22/2025
11
+
ms.date: 12/05/2025
12
12
search.appverid:
13
13
- MET150
14
14
ms.collection:
@@ -37,7 +37,7 @@ The Tenant Allow/Block list is available in the Microsoft Defender portal at <ht
37
37
For usage and configuration instructions, see the following articles:
38
38
39
39
-**Domains and email addresses** and **spoofed senders**: [Allow or block emails using the Tenant Allow/Block List](tenant-allow-block-list-email-spoof-configure.md)
40
-
- Entries apply to the MAIL FROM address (also known as the `5321.MailFrom` address, P1 sender, or envelope sender), not the From address (also known as the `5322.From` addressor P2 sender). For more information about these addresses, see [Why internet email needs authentication](email-authentication-about.md#why-internet-email-needs-authentication).
40
+
- Entries apply to the From address (also known as the `5322.From` addressor P2 sender), not the MAIL FROM address (also known as the `5321.MailFrom` address, P1 sender, or envelope sender). For more information about these addresses, see [Why internet email needs authentication](email-authentication-about.md#why-internet-email-needs-authentication).
41
41
- Entries apply to messages from both internal and external senders. Special handling applies to internal spoofing scenarios.
42
42
- Block entries for **Domains and email addresses** also prevent users in the organization from *sending* email to those blocked domains and addresses.
43
43
-**Files**: [Allow or block files using the Tenant Allow/Block List](tenant-allow-block-list-files-configure.md)
0 commit comments