Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderM365 ReportPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderM365 ReportPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1187837

Microsoft Defender for Office 365 Zero-hour auto-purge (ZAP) Teams protection capabilities to Defender for Office Plan 1

Plan for Change
Major Change

Message ID

MC1187837
View in Admin Center

Roadmap ID

529816
View in Roadmap

Services

Microsoft Defender XDR

Affected Platforms

AndroidDesktopiOSLinuxMacWeb

Summary

Starting January 6, 2026, Zero-hour auto-purge (ZAP) will be enabled by default in Microsoft Defender for Office 365 Plan 1, automatically moving malicious Teams messages to admin quarantine. Tenants can opt out before January 6, 2026, and admins manage quarantined content via the Security portal.

Details

Introduction

Starting January 6, 2026, Zero-hour auto-purge (ZAP)—a feature that moves malicious messages from internal Microsoft Teams chats and channels to admin quarantine—will be turned on by default for Microsoft Defender for Office 365 Plan 1. This enhancement helps protect your organization by removing phishing or malware URLs from Teams conversations and placing them in the admin quarantine within the Microsoft 365 Security portal. For details on managing quarantined Teams messages, refer to Use the Microsoft Defender portal to manage Microsoft Teams quarantined messages.

Screenshot: Example of Admin quarantine showcasing all quarantined Teams messages

user settings

This message is associated with Microsoft 365 Roadmap ID 529816.

When this will happen:

  • General Availability (Worldwide): Rollout begins early January 2026 and will complete by mid-January 2026.
  • Default ON setting effective January 6, 2026, unless your tenant opts out before that.

How this affects your organization:

Who is affected:

  • All tenants using Microsoft Defender for Office 365 Plan 1 with Microsoft Teams.

What will happen:

  • ZAP will automatically move internal Teams messages detected as phishing or malware to the admin quarantine tab in the Security portal.
  • By default, ZAP protection for Teams will be ON for all tenants.
  • Existing ZAP settings apply; no policy changes are required unless you choose to opt out.
  • End users will not see quarantined messages in Teams; admins can review and manage quarantined content in the Security portal.

What you can do to prepare:

  • Review ZAP settings in the Microsoft 365 Security portal before January 6, 2026.
  • If you want to opt out of the default ON setting, do so via ZAP settings in the Security portal between December 6, 2025, and January 5, 2026.
  • Communicate this change to your helpdesk and update internal documentation as needed.

Learn more:

  • Configure ZAP for Teams protection in Defender for Office 365
  • Use the Microsoft Defender portal to manage Microsoft Teams quarantined messages

Compliance considerations:

No compliance considerations identified; review as appropriate for your organization.

Feedback:

We value your input. Please leave feedback directly from this Message Center post by selecting Thumbs up or Thumbs down, and adding a comment. (Optional) Include your email address in the text box so the responsible team can follow up if needed.

Timeline

Published
Nov 18, 2025
Message published to Message Center
Updated
Nov 18, 2025
Message content updated
End Date
Feb 20, 2026
Message timeline ends

Tags

#New feature#User impact#Admin impact

Category

Plan for Change

Related Messages

Similar updates

MC1279093●

Microsoft Defender for Office 365: Enhancing how we handle promotional mail

Apr 13, 2026
MC1239187●

Defender for Office 365 URL click alerts now include Microsoft Teams

Feb 26, 2026
MC1192257●

Microsoft Defender Threat Intelligence: Convergence with Microsoft Defender and Microsoft Sentinel

Dec 5, 2025
MC1191616

Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint

Dec 3, 2025
MC1187672

Get ready for security agents: Microsoft Security Copilot will be included in Microsoft 365 E5

Nov 18, 2025