Microsoft is expanding end-user reporting capabilities in Microsoft Teams by enabling Defender for Office 365 Plan 1 customers to report suspicious messages directly in Teams (Roadmap ID 531760), a capability previously limited to Plan 2. The feature is intended to strengthen collaboration-platform defenses by letting users classify messages as Security Risk (suspected phishing/malware/spam) or Not a Security Risk (false positives), providing additional signals to SOC workflows and improving detection for chat-based social engineering such as BEC-style lures delivered via Teams; the rollout is expected to complete by late March 2026 and requires administrative enablement.
Separately, Microsoft acknowledged an Exchange Online service issue in which legitimate emails were incorrectly marked as phishing/spam and quarantined, disrupting some users’ ability to send/receive email. Microsoft attributed the false positives to a new URL rule that misclassified certain legitimate URLs/domains as malicious due to evolving detection criteria; some previously quarantined messages may begin reappearing as mitigations roll out, but other emails may remain quarantined until the fix is fully deployed, and affected organizations are advised to review quarantine for missing legitimate mail.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said rollout of the expanded Teams malicious-message reporting capability for Defender for Office 365 Plan 1 users is expected to complete in late March 2026. Once deployed, organizations that enable the required Defender settings will be able to let users report suspicious Teams messages for review.
By February 10, 2026, Microsoft said it was making progress fixing the Exchange Online false-positive issue, with some quarantined legitimate emails starting to return to inboxes while others remained in quarantine. Users were advised to review the Microsoft Defender Quarantine page and manually release valid messages pending full remediation.
On February 9, 2026, Microsoft updated Microsoft 365 Roadmap item 531760 to extend suspicious Microsoft Teams message reporting to Microsoft Defender for Office 365 Plan 1 users, a capability previously limited to Plan 2. The opt-in feature lets users classify reported Teams messages as security risks or false positives and routes submissions for centralized triage.
On February 5, 2026, a new Exchange Online URL rule began incorrectly flagging some legitimate emails as malicious, causing them to be quarantined and potentially missed by users. Microsoft attributed the issue to anti-phishing criteria that mistakenly classified certain legitimate URLs as unsafe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.