Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisorypatch-regressiondetection-content-updatephishing-campaign-intelligence

Microsoft 365 message security changes: Teams user reporting expansion and Exchange Online false-positive quarantines

Updated 3mo agoFirst seen Feb 10, 20262 sources

Microsoft is expanding end-user reporting capabilities in Microsoft Teams by enabling Defender for Office 365 Plan 1 customers to report suspicious messages directly in Teams (Roadmap ID 531760), a capability previously limited to Plan 2. The feature is intended to strengthen collaboration-platform defenses by letting users classify messages as Security Risk (suspected phishing/malware/spam) or Not a Security Risk (false positives), providing additional signals to SOC workflows and improving detection for chat-based social engineering such as BEC-style lures delivered via Teams; the rollout is expected to complete by late March 2026 and requires administrative enablement.

Separately, Microsoft acknowledged an Exchange Online service issue in which legitimate emails were incorrectly marked as phishing/spam and quarantined, disrupting some users’ ability to send/receive email. Microsoft attributed the false positives to a new URL rule that misclassified certain legitimate URLs/domains as malicious due to evolving detection criteria; some previously quarantined messages may begin reappearing as mitigations roll out, but other emails may remain quarantined until the fix is fully deployed, and affected organizations are advised to review quarantine for missing legitimate mail.

Share:
Microsoft 365 message security changes: Teams user reporting expansion and Exchange Online false-positive quarantines
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 31, 20263mo ago

Microsoft targets late-March rollout completion for Teams reporting expansion

Microsoft said rollout of the expanded Teams malicious-message reporting capability for Defender for Office 365 Plan 1 users is expected to complete in late March 2026. Once deployed, organizations that enable the required Defender settings will be able to let users report suspicious Teams messages for review.

Feb 10, 20264mo ago

Microsoft begins remediating Exchange Online false-positive quarantines

By February 10, 2026, Microsoft said it was making progress fixing the Exchange Online false-positive issue, with some quarantined legitimate emails starting to return to inboxes while others remained in quarantine. Users were advised to review the Microsoft Defender Quarantine page and manually release valid messages pending full remediation.

Feb 9, 20265mo ago

Microsoft updates roadmap to expand Teams message reporting to Defender Plan 1

On February 9, 2026, Microsoft updated Microsoft 365 Roadmap item 531760 to extend suspicious Microsoft Teams message reporting to Microsoft Defender for Office 365 Plan 1 users, a capability previously limited to Plan 2. The opt-in feature lets users classify reported Teams messages as security risks or false positives and routes submissions for centralized triage.

Feb 5, 20265mo ago

Exchange Online starts misclassifying legitimate emails as phishing/spam

On February 5, 2026, a new Exchange Online URL rule began incorrectly flagging some legitimate emails as malicious, causing them to be quarantined and potentially missed by users. Microsoft attributed the issue to anti-phishing criteria that mistakenly classified certain legitimate URLs as unsafe.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Affected products
2 linked
Exchange OnlineWindows 10
Organizations
4 linked
Microsoft CorporationBleepingComputerZDNETiStock
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.