Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1150984

Microsoft Defender for Office 365: Message Warnings for Messages with Malicious URLs in Teams

Plan for Change

Message ID

MC1150984
View in Admin Center

Roadmap ID

502879
View in Roadmap

Services

Microsoft Defender XDR

Affected Platforms

AndroidDesktopiOSWeb

Summary

Microsoft Defender for Office 365 will introduce message warnings in Microsoft Teams for messages containing URLs flagged as Spam, Phish, or Malware. Starting with a public preview in September 2025 and general availability in November 2025, warnings will appear for both recipients and senders, enabled by default and manageable via Teams Admin Center.

Details

Introduction

To help users stay protected from malicious content, we’re introducing message warnings in Microsoft Teams. This new feature displays a warning banner on messages containing URLs flagged as Spam, Phish, or Malware—whether the message is internal or external. These warnings enhance user awareness and complement existing security protections like Safe Links and ZAP.

This post is associated with Roadmap ID 502879.

This message center post was created in collaboration with Microsoft Teams and is related to the Teams post MC1148539.

Figure i. Recipient View: Users will find a warning banner on messages containing malicious URLs.

user settings

Figure ii. Sender View: Senders will also be notified if their message includes a flagged URL.

user settings

When this will happen:

  • Public Preview (Worldwide): Begins early September 2025 and completes by mid-September 2025.
  • General Availability (Worldwide): Begins early November 2025 and completes by mid-November 2025.

How this affects your organization:

  • Who is affected: All Microsoft Defender for Office 365 (MDO) customers and Microsoft Teams enterprise customers.
  • What will happen:
    • Message warnings will appear in two scenarios:
      • Known Malicious URLs: If a URL is already identified as malicious, the message will be delivered with a warning.
      • Post-Delivery URLs: If a URL becomes malicious after delivery, a warning will be added retroactively for up to 48 hours.
    • Recipient View: Users will see a warning banner on messages containing malicious URLs.
    • Sender View: Senders will also be notified if their message includes a flagged URL.
    • The feature will be enabled by default at General Availability.
    • Admins can manage the feature via Teams Admin Center > Messaging settings.
    • If at least one tenant has the feature enabled, message warnings will be active across the tenant.
    • Message warnings work alongside existing protections:
      • Safe Links: Continues to provide time-of-click protection in Teams.
      • ZAP message blocking: If ZAP is enabled, ZAP blocks take precedence over message warnings.

What you can do to prepare:

  • Review and configure settings in Teams Admin Center > Messaging settings.
  • Communicate this change to helpdesk and support teams.
  • Update internal documentation to reflect new message warning behavior.
  • For Public Preview, opt-in via the toggle in Teams Admin Center > Messaging settings.
  • Learn more:
    • Malicious URL Protection in Microsoft Teams
    • Microsoft Defender for Office 365 support for Microsoft Teams

Compliance considerations:

Compliance AreaExplanation
New data storageURLs flagged as malicious may be stored temporarily.
Data processing changesMessages are re-evaluated post-delivery for URL verdict changes, altering how message content is processed.
AI/ML capabilitiesURL verdicts are determined using Microsoft Defender’s threat intelligence and ML-based detection.
Admin controlAdmins can enable/disable the feature via Teams Admin Center.
Entra ID group controlFeature settings can be scoped using Entra ID group membership.

Timeline

📅
Published
Sep 10, 2025
Message published to Message Center
✏️
Updated
Sep 10, 2025
Message content updated
🏁
End Date
Dec 17, 2025
Message timeline ends

Tags

#New feature#User impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1187837●

Microsoft Defender for Office 365 Zero-hour auto-purge (ZAP) Teams protection capabilities to Defender for Office Plan 1

Nov 18, 2025
MC1147984

Microsoft Teams: User reporting for incorrectly identified security concerns

Sep 4, 2025
MC1133508

Microsoft Teams Integration with Microsoft Defender for Office Tenant Allow/Block List for blocking domains

Aug 11, 2025
MC1013453●

Upcoming Changes for M365 Copilot Chat with Link Safety

Feb 21, 2025
MC708505

Unified RBAC provides centralized role-based administration controls for Microsoft Defender for Office 365

Jan 20, 2024