Microsoft Teams Admin Center to Feature New Security Detection Report
Microsoft is launching a new Security Detection Report in the Teams admin center to consolidate threat monitoring, offering admins a unified view of impersonation attempts, malicious URLs, and weaponizable files.

Microsoft is set to introduce a significant enhancement to its Teams administration tools with the upcoming Security Detection Report. This new feature, slated for general availability in late August 2026, aims to provide security administrators with a centralized dashboard for monitoring and responding to a range of messaging-based threats within the Teams platform. Previously, threat signals related to Teams were scattered across various Microsoft security portals, complicating the process of identifying and mitigating attacks. The Security Detection Report, tracked under Microsoft 365 Roadmap ID 560702, promises to consolidate these disparate alerts into a single, easily accessible location within the Teams admin center, under Analytics & Reports > Protection Reports > Security Detections.
The report will focus on three critical categories of threats: impersonation attempts, malicious URLs, and weaponizable file types. Administrators will be presented with a consolidated view, including a chart illustrating detection volumes over a selected period and a detailed table listing individual detections. Each entry in the table will provide essential context, such as sender and recipient information, the type of detection, and relevant thread identifiers, enabling security teams to conduct swift investigations and take appropriate action.
Beyond enhanced visibility, the new report will offer robust data export capabilities. Both summary charts and detailed detection tables can be downloaded as CSV files. This functionality is crucial for integrating Teams threat data into existing Security Information and Event Management (SIEM) systems, facilitating automated analysis and correlation with other security events. It also aids in compliance reporting and forensic investigations by providing a structured record of detected threats.
One of the practical benefits highlighted is the ability to directly block malicious external users from within the report itself, by navigating to External Access settings. This streamlined workflow significantly reduces the time between threat detection and containment, a critical factor in minimizing the impact of security incidents.
Microsoft's rollout timeline for this feature has seen several adjustments, indicating a careful approach to ensuring its stability and effectiveness. Originally anticipated for mid-July, then late June, the current projection for general availability is late August 2026, with a full global rollout expected by early September. These revisions suggest Microsoft is refining the underlying detection logic and reporting infrastructure before broad deployment.
Teams has increasingly become a target for attackers employing tactics similar to those used in email-based attacks, including phishing-style impersonation, malicious link distribution, and malware delivery via files. The absence of a dedicated, centralized reporting mechanism within the Teams admin center has been a notable gap for security teams, often forcing them to rely on broader Microsoft Defender portal reports. This new feature directly addresses that gap by bringing Teams-specific threat intelligence to the forefront of administrative management.
The Security Detection Report complements other recent security enhancements for Teams, such as the user-reported security signals feature, which allows end-users to flag suspicious messages. These user-submitted reports are now also feeding into the same Protection Reports section, creating a more comprehensive, community-assisted threat intelligence loop.
Security teams managing Microsoft Teams should prepare for this new capability by ensuring their messaging safety settings, including malicious link and file scanning, are properly configured. They should also update their incident response playbooks to incorporate Teams as a primary signal source once the report becomes generally available, leveraging it to proactively defend against evolving messaging-based threats.