Microsoft has published a new Security Detection Report in the Teams admin center, giving administrators a unified view of messaging security detections across Microsoft Teams.
The report brings together signals such as impersonation attempts, malicious links, and weaponizable file types from the past 7 or 30 days into a single, centralized reporting experience, making it easier for security and helpdesk teams to investigate and respond to suspicious messaging activity.
Teams administrators can find the report in the Teams admin center > Analytics & reports > Protection reports > Security detections.
The report provides detection details, including sender and recipient context, detection type, and available user actions. You can export report data for further investigation, including additional metadata such as sender identifier and thread ID.

As announced in December 2025, Microsoft has enabled the messaging security protections behind this report in January 2026 for Defender for Office 365 Plan 1, Plan 2, and Microsoft Defender XDR.
- Impersonation detection requires no configuration.
- Administrators can manage malicious link scanning and unsafe (weaponizable) file type scanning through Messaging safety settings in the Teams admin center.
When the report identifies malicious external users, administrators can block them directly through External access settings to prevent further communication attempts.
The new security detection report should be generally available in September 2026.
