Microsoft is rolling out a new Teams security capability that lets end users report suspicious or unwanted one-to-one voice calls as potential scams or phishing attempts. The feature adds a “Report a Call” option in call history (via the More options menu) on Windows, macOS, and web, addressing a visibility gap where organizations previously had limited user-driven reporting for voice-based social engineering attempts.
When a call is reported, Microsoft says only limited call metadata is shared with the organization and Microsoft—such as timestamps, call duration, caller ID (if available), and participant Teams IDs—without indicating that call audio is collected. Reports can be reviewed in the Teams Admin Center and, for organizations with Defender for Office 365 (Plan 1/Plan 2) or Microsoft Defender XDR, in the Microsoft Defender portal; the feature is enabled by default but can be disabled by admins in Teams calling settings. Microsoft indicated a phased rollout beginning with targeted release in mid-March and broader availability thereafter.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the Teams 'Report a Call' feature is expected to reach worldwide general availability in mid-to-late April 2026. Organizations with Defender for Office 365 or Defender XDR will be able to review reports in the Microsoft Defender portal, while others will see basic data in the Teams Admin Center.
Microsoft said the new Teams call-reporting feature is scheduled to start rolling out to Targeted Release customers in mid-March 2026, with completion expected later that month. The feature will be available in call history on Teams for Windows, Mac, and the web.
Microsoft announced it will add a new 'Report a Call' capability to Microsoft Teams so users can flag suspicious, scam, phishing, or unwanted one-to-one calls. The feature is enabled by default and shares limited call metadata with organizations and Microsoft for investigation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.