Microsoft Defender for Office 365 URL click alerts will now include Microsoft Teams, enabling detection of malicious link clicks in Teams messages. This feature, rolling out from February to May 2026, enhances alert visibility and investigation in the Defender portal for licensed organizations, with no user workflow changes.
Introduction
We’re extending Microsoft Defender for Office 365 (MDO) URL click alerting to Microsoft Teams, giving security teams greater visibility into potentially malicious activity beyond email. By surfacing alerts when users click malicious or suspicious links in Teams messages, organizations can detect threats earlier, investigate faster, and respond more effectively—all from the Microsoft Defender portal.
This message is associated with Microsoft Roadmap ID 557549.
When this will happen:
How this affects your organization:
Who is affected:
What will happen:
What you can do to prepare:
Learn more:
Alert policies in the Microsoft Defender portal | Microsoft Learn (will be updated before rollout)
Compliance considerations:
| Question | Explanation |
|---|---|
| Does the change alter how existing customer data is processed, stored, or accessed? | Microsoft Teams message data is accessed and surfaced as evidence within Microsoft Defender for Office 365 alerts and incidents when users click malicious or suspicious URLs. |
| Does the change alter how admins can monitor, report on, or demonstrate compliance activities? | Security admins gain additional alerting and investigation signals related to Microsoft Teams URL clicks within the Microsoft Defender portal, enhancing monitoring and incident correlation. |