Skip to content

Commit beeb7fb

Browse files
Merge pull request #5848 from MicrosoftDocs/main
[AutoPublish] main to live - 12/05 10:37 PST | 12/06 00:07 IST
2 parents 1826050 + cecf322 commit beeb7fb

File tree

6 files changed

+96
-21
lines changed

6 files changed

+96
-21
lines changed

defender-office-365/mdo-support-teams-about.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.collection:
1616
- tier1
1717
description: Admins can learn about Microsoft Teams features in Microsoft Defender for Office 365.
1818
ms.service: defender-office-365
19-
ms.date: 09/11/2025
19+
ms.date: 10/27/2025
2020
appliesto:
2121
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
2222
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
@@ -58,6 +58,9 @@ Microsoft 365 E5 and Defender for Office 365 Plan 2 extend Teams protection with
5858

5959
- **Teams message entity panel**: A single place to store all Teams message metadata for immediate SecOps review. Any threats coming from Teams chats, group chats, meeting chats, and other channels can be found in one place as soon as they're assessed. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
6060

61+
> [!TIP]
62+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
63+
6164
- **Attack simulation training using Teams messages**: To ensure users are resilient to phishing attacks in Microsoft Teams, admins can configure phishing simulations using Teams messages instead of email messages. For more information, see [Microsoft Teams in Attack simulation training](attack-simulation-training-teams.md).
6265

6366
- **Hunting on Teams messages with URLs**: You can hunt for Teams messages containing URL across three new advanced hunting tables: [MessageEvents](/defender-xdr/advanced-hunting-messageevents-table), [MessagePostDeliveryEvents](/defender-xdr/advanced-hunting-messagepostdeliveryevents-table), and [MessageURLInfo](/defender-xdr/advanced-hunting-messageurlinfo-table).

defender-office-365/quarantine-admin-manage-messages-files.md

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.custom:
1818
- seo-marvel-apr2020
1919
description: Admins can learn how to view and manage quarantined messages for all users in Microsoft 365 organizations with cloud mailboxes. Admins in organizations with Microsoft Defender for Office 365 can also manage quarantined files in SharePoint, OneDrive, and Microsoft Teams.
2020
ms.service: defender-office-365
21-
ms.date: 10/07/2025
21+
ms.date: 10/27/2025
2222
appliesto:
2323
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
2424
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -789,7 +789,7 @@ The next section in the details flyout is related to quarantined Teams messages:
789789
- **Policy name**: The value is **Teams Protection Policy**.
790790
- **Quarantine policy**
791791

792-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
792+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
793793

794794
When you're finished in the details flyout, select **Close**.
795795

@@ -811,7 +811,7 @@ On the **Teams messages** tab, select the quarantined message by using either of
811811

812812
Using either method to select the message, some actions are available under :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More**.
813813

814-
After you select the quarantined message, the available actions are described in the following subsections.
814+
After you select the quarantined Teams message, the available actions are described in the following subsections.
815815

816816
#### Release quarantined Teams messages
817817

@@ -878,6 +878,16 @@ By default, The .html message file is saved in a compressed file named Quarantin
878878

879879
Back on the **Download messages** flyout, select **Done**.
880880

881+
#### Remove users from quarantined Teams chats
882+
883+
> [!TIP]
884+
> Currently, this feature is in Preview, isn't available in all organizations, and is subject to change.
885+
886+
1. On the **Teams messages** tab, select the Teams message by clicking anywhere in the row other than the check box next to the first column.
887+
2. In the details flyout that opens (the Teams message entity panel), select :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More actions** \> :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout.
888+
889+
For complete instructions, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
890+
881891
#### Take action on multiple quarantined Teams messages
882892

883893
When you select multiple quarantined messages on the **Teams messages** tab by selecting the check boxes next to the first column, the following bulk actions are available on the **Teams messages** tab:

defender-office-365/submissions-admin.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.collection:
1616
ms.custom: seo-marvel-apr2020
1717
description: "Admins can learn how to use the Submissions page in the Microsoft Defender portal to submit messages, URLs, and email attachments to Microsoft for analysis. Reasons for submission include: legitimate messages that were blocked, suspicious messages that were allowed, suspected phishing email, spam, malware, and other potentially harmful messages."
1818
ms.service: defender-office-365
19-
ms.date: 09/11/2025
19+
ms.date: 10/27/2025
2020
appliesto:
2121
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
2222
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -556,9 +556,6 @@ When you're finished in the details flyout, select **Close**.
556556

557557
### View Teams admin submissions to Microsoft in Defender for Office 365 Plan 2
558558

559-
> [!TIP]
560-
> [Submission of Teams message to Microsoft](submissions-teams.md) is currently in Preview, isn't available in all organizations, and is subject to change.
561-
562559
In the Defender portal at <https://security.microsoft.com>, go to the **Submissions** page at **Actions & submissions** \> **Submissions**. Or, to go directly to the **Submissions** page, use <https://security.microsoft.com/reportsubmission>.
563560

564561
On the **Submissions** page, select the **Teams messages** tab.
@@ -642,7 +639,10 @@ The next sections in the details flyout are related to Teams submissions:
642639
- **Submitted by**
643640
- **Submission status**
644641

645-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
642+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
643+
644+
> [!TIP]
645+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
646646
647647
When you're finished in the details flyout, select **Close**.
648648

@@ -1120,9 +1120,11 @@ The next sections in the details flyout are related to user reported Teams submi
11201120
- **Phish simulation**: The value is **Yes** or **No**.
11211121
- **Converted to admin submission**: The value is **Yes** or **No**. For more information, see [View converted admin submissions](#view-converted-admin-submissions).
11221122

1123-
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams mMessage entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
1123+
The rest of the details flyout contains the **Message details**, **Sender**, **Participants**, **Channel details**, and **URLs** sections that are part of the _Teams message entity panel_. For more information, see [The Teams message entity panel in Microsoft Defender for Office 365 Plan 2](teams-message-entity-panel.md).
11241124

11251125
> [!TIP]
1126+
> To remove users from Teams chats, see [Remove users from Teams chats in the Teams message entity panel](teams-message-entity-panel.md#remove-users-from-teams-chats-in-the-teams-message-entity-panel).
1127+
>
11261128
> If the **Result** value is **Phish simulation**, the details flyout might contain the following information only:
11271129
>
11281130
> - **Result details** section

defender-office-365/submissions-outlook-report-messages.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
description: Learn how to report phishing and suspicious emails in supported versions of Outlook using the built-in Report button.
1515
ms.service: defender-office-365
1616
search.appverid: met150
17-
ms.date: 09/28/2025
17+
ms.date: 12/05/2025
1818
appliesto:
1919
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Default email protections for cloud mailboxes</a>
2020
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -51,7 +51,7 @@ The built-in **Report** button is available in the following versions of Outlook
5151
- The new Outlook for Windows<sup>\*</sup>
5252
- Outlook on the web<sup>\*</sup>
5353

54-
<sup>\*</sup> In this version of Outlook, the built-in **Report** button also supports reporting messages from shared mailboxes or other mailboxes by a delegate.
54+
<sup>\*</sup> In this version of Outlook, the built-in **Report** button also supports reporting messages from shared mailboxes or other mailboxes by a delegate. The delegate user needs [Send As permissions](/microsoft-365/admin/add-users/give-mailbox-permissions-to-another-user) to report messages from the shared mailbox. Without Send As permission, the message is **not** sent to the reporting mailbox. Instead, the message is removed from the folder.
5555

5656
The **Report** button is available in supported versions of Outlook if both of the following conditions are true:
5757

defender-office-365/teams-message-entity-panel.md

Lines changed: 67 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,9 @@ ms.collection:
1616
- highpri
1717
description: Describes the Teams message entity panel for Microsoft Teams in Microsoft Defender for Office 365 Plan 2, how it does post-breach work like ZAP and Safe Links and gives admins a single pane of glass on Teams chat and channel threats like suspicious URLs..
1818
ms.service: defender-office-365
19-
ms.date: 11/16/2023
19+
ms.date: 10/27/2025
2020
appliesto:
21-
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
21+
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 2</a>
2222
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
2323
---
2424

@@ -34,10 +34,12 @@ This article explains the information and actions on the Teams message entity pa
3434

3535
To use the Email entity page, you need to be assigned permissions. You have the following options:
3636

37-
- [Email & collaboration permissions in the Microsoft Defender portal](mdo-portal-permissions.md): Membership in the **Organization Management**, **Security Administrator**, or **Quarantine Administrator** role groups.
38-
- [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in these roles gives users the required permissions _and_ permissions for other features in Microsoft 365:
39-
- _Full access_: Membership in the **Global Administrator**<sup>\*</sup> or **Security Administrator** roles.
40-
- _Read-only access_: Membership in the **Global Reader** or **Security Reader** roles.
37+
- _Full access_:
38+
- [Email & collaboration permissions in the Microsoft Defender portal](mdo-portal-permissions.md): Membership in the **Organization Management**, **Security Administrator**, or **Quarantine Administrator** role groups.
39+
- [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal): Membership in one of the following roles gives users the required permissions _and_ permissions for other features in Microsoft 365: **Global Administrator**<sup>\*</sup>, **Security Administrator**, or **Security Operator**.
40+
- _Read-only access_:
41+
- Microsoft Entra permissions: **Global Reader** or **Security Reader**.
42+
- _[Remove users from Teams chats](#remove-users-from-teams-chats-in-the-teams-message-entity-panel)_: Requires membership in one of the following Microsoft Entra roles: **Global Administrator**<sup>\*</sup>, **Security Administrator**, or **Security Operator**.
4143

4244
> [!IMPORTANT]
4345
> <sup>\*</sup> Microsoft strongly advocates for the principle of least privilege. Assigning accounts only the minimum permissions necessary to perform their tasks helps reduce security risks and strengthens your organization's overall protection. Global Administrator is a highly privileged role that you should limit to emergency scenarios or when you can't use a different role.
@@ -50,7 +52,25 @@ There are no direct links to the Teams message entity panel from the top levels
5052

5153
- From the **Submissions** page at <https://security.microsoft.com/reportsubmission>:
5254
- Select the **Teams messages** tab \> select an entry by clicking anywhere in the row other than the check box.
53-
- Select the **User reported** tab \> select a Teams entry by clicking anywhere in the row other than the check box. You can filter the entries by selecting :::image type="icon" source="media/m365-cc-sc-filter-icon.png" border="false"::: **Filter** \> **Message type** \> **Teams**. The details flyout that opens is the Teams message entity panel.
55+
- Select the **User reported** tab \> select a Teams entry by clicking anywhere in the row other than the check box. The details flyout that opens is the Teams message entity panel.
56+
57+
You can filter the entries by selecting :::image type="icon" source="media/m365-cc-sc-filter-icon.png" border="false"::: **Filter** \> **Message type** \> **Teams**.
58+
59+
- From the **Advanced Hunting** page at <https://security.microsoft.com/v2/advanced-hunting>, select a **TeamsMessageId** value (link) from the **MessageEvents** table in the query results. The details flyout that opens is the Teams message entity panel. For example:
60+
61+
```kusto
62+
UrlClickEvents
63+
| where ThreatTypes !="" and Workload =="Teams"
64+
| summarize count() by Url, ThreatTypes, ActionType, Workload
65+
| project Url, ThreatTypes, ActionType, Workload, ClickCount=count_
66+
| top 20 by ClickCount
67+
68+
UrlClickEvents
69+
| limit 100
70+
71+
MessageEvents
72+
| limit 100
73+
```
5474

5575
## What's on the Teams message entity panel
5676

@@ -103,6 +123,46 @@ The rest of the Teams message entity panel contains the following information, r
103123

104124
:::image type="content" source="media/teams-message-entity-panel-shown-in-quarantine.png" alt-text="Screenshot of the Teams Message Entity panel from a quarantined Teams message showing the common sections." lightbox="media/teams-message-entity-panel-shown-in-quarantine.png":::
105125

126+
## Remove users from Teams chats in the Teams message entity panel
127+
128+
> [!TIP]
129+
> Currently, this feature is in Preview, isn't available in all organizations, and is subject to change.
130+
>
131+
> You can only remove _internal_ users in your organization from a chat.
132+
>
133+
> When you remove users from a chat, the sender of the chat isn't blocked, and the removed users can start new chats with the sender.
134+
135+
In the Teams entity panel, you can select :::image type="icon" source="media/m365-cc-sc-take-actions-icon.png" border="false"::: **Take action** at the top of the flyout (often under :::image type="icon" source="media/m365-cc-sc-more-actions-icon.png" border="false"::: **More actions**) to remove users from a Teams chat.
136+
137+
Do the following steps in the **Take action** wizard:
138+
139+
1. On the **Choose response actions** page, select **Remove user from conversation** from the **Conversation level actions** section, and then select **Next**.
140+
2. On the **Choose target entities** page, configure the following options:
141+
- **Name** Enter a unique, descriptive name for the remove user scenario.
142+
- **Description**: Enter optional details.
143+
144+
The rest of the page contains a details table with the following information about the users in the chat:
145+
146+
- **Impacted asset**: The email address of the user.
147+
- **Action**: This value is always **Remove user from conversation**.
148+
- **Target entity**: The **Thread id** GUID value of the chat.
149+
- **Expires on**
150+
151+
By default, all users in the chat are selected, including external users you can't remove from the chat. Verify the _internal_ users to remove from the chat are selected.
152+
153+
When you're finished on the **Choose target entities** page, select **Next**.
154+
155+
3. On the **Review and submit** page, review your previous selections.
156+
157+
Select **Back** to go back and change your selections.
158+
159+
When you're finished on the **Review and submit** page, select **Submit**.
160+
161+
Removing users from a Teams chat is recorded on the **History** tab of the **Action center** page at <https://security.microsoft.com/action-center/history>. You can filter the results by **Action type** \> **Remove users from Teams conversations** and/or **Entity type** \> **Teams message**. In the alert details, you can confirm users were or were not removed from the Teams chat.
162+
163+
> [!TIP]
164+
> Removing users from Teams chats doesn't create an investigation ID or an automated investigation.
165+
106166
## For more information
107167

108168
[The Microsoft Defender for Office 365 Email Entity Page and how it works](mdo-email-entity-page.md)

defender-office-365/tenant-allow-block-list-about.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ manager: bagol
88
audience: ITPro
99
ms.topic: how-to
1010
ms.localizationpriority: medium
11-
ms.date: 09/22/2025
11+
ms.date: 12/05/2025
1212
search.appverid:
1313
- MET150
1414
ms.collection:
@@ -37,7 +37,7 @@ The Tenant Allow/Block list is available in the Microsoft Defender portal at <ht
3737
For usage and configuration instructions, see the following articles:
3838

3939
- **Domains and email addresses** and **spoofed senders**: [Allow or block emails using the Tenant Allow/Block List](tenant-allow-block-list-email-spoof-configure.md)
40-
- Entries apply to the MAIL FROM address (also known as the `5321.MailFrom` address, P1 sender, or envelope sender), not the From address (also known as the `5322.From` address or P2 sender). For more information about these addresses, see [Why internet email needs authentication](email-authentication-about.md#why-internet-email-needs-authentication).
40+
- Entries apply to the From address (also known as the `5322.From` address or P2 sender), not the MAIL FROM address (also known as the `5321.MailFrom` address, P1 sender, or envelope sender). For more information about these addresses, see [Why internet email needs authentication](email-authentication-about.md#why-internet-email-needs-authentication).
4141
- Entries apply to messages from both internal and external senders. Special handling applies to internal spoofing scenarios.
4242
- Block entries for **Domains and email addresses** also prevent users in the organization from *sending* email to those blocked domains and addresses.
4343
- **Files**: [Allow or block files using the Tenant Allow/Block List](tenant-allow-block-list-files-configure.md)

0 commit comments

Comments
 (0)