Report a security concern now covers Teams meetings and group calls

Microsoft is updating the “Report a security concern” feature in Teams. The feature will soon be available in Teams meetings and group calls. Both capabilities let users report suspicious, malicious, or potentially fraudulent activity directly from a meeting or group call. The feature is intended to help organizations identify and investigate threats such as phishing, impersonation, and scams.

Report a security concern is available for organizations with a Defender for Office 365 Plan 1, Plan 2, or Microsoft Defender XDR.

Timeline

The rollout should be completed in October 2026.

How does this affect your users?

Users can now report suspected phishing attempts, impersonation, social engineering activity, scams, or other security concerns within Teams meetings or group calls.

Teams meeting:
Users will find the new Report a concern option in the More actions (…) menu during an active meeting…

Via the More actions (…) menu

…and the meeting chat header for both scheduled and Meet now meetings.

or in the meeting chat
or in the meeting chat

Users can enter a short note about the concern and optionally report the suspicious participants.

Provide additional security concerns
Provide additional security concerns

Group call:

In May 2026, Microsoft introduced the option to report a suspicious Teams call. Group calls were not yet supported at that time.

Read:  Report a suspicious call in Microsoft Teams

This update extends the reporting capability to group calls. Users will now also find the Report call option for group calls in the call history of their Teams client.

Report a suspicious group call
Report a suspicious group call

For both meeting and group calls, when a report is submitted, relevant meeting or call metadata and limited contextual information are collected to support investigation and remediation.

Security administrators can investigate reported meetings and calls in the Defender security portal at Investigation & Response > Submissions > User reported, and act according to their organization’s own security processes and policies. The meeting reports are not yet available.

User reported security submissions
User reported security submissions

Also, a Teams administrator now finds these submissions in the Teams admin center as a report under Analytics & Reports > Protection reports > User reported security submissions, currently in preview. Meeting reports are not yet available. The report can be exported to obtain more details about the submission.

User reported security submission report (preview) in the Teams admin center
User reported security submission report (preview) in the Teams admin center


Reminder:
User-reported submissions for Teams must be enabled in the Defender admin portal and in the Teams admin center. Read the documentation on how to configure it: User reported settings in Teams – Microsoft Defender for Office 365 | Microsoft Learn

Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Comment