Original Article Text

Click to Toggle View

Microsoft adds malicious link warnings to Teams private chats. Microsoft Teams will automatically alert users when they send or receive a private message containing links that are tagged as malicious. Microsoft will introduce these new warnings for messages containing URLs that have been flagged as spam, phishing, or malware, for all Microsoft Defender for Office 365 (MDO) and Microsoft Teams enterprise customers. The new link protection feature will begin rolling out with a public preview for desktop, Android, web, and iOS users in September 2025 and is expected to reach general availability in November 2025, according to a recent Microsoft 365 roadmap entry. "To help users stay protected from malicious content, we're introducing message warnings in Microsoft Teams," the company explained in an incident alert published in the Microsoft 365 message center on Wednesday. "This new feature displays a warning banner on messages containing URLs flagged as Spam, Phish, or Malware—whether the message is internal or external. These warnings enhance user awareness and complement existing security protections like Safe Links and ZAP." ​Admins can opt in to enable this new feature in public preview by using the toggle available in the Teams Admin Center > Messaging settings. Malicious URL warnings will be displayed directly on the message and will be enabled by default after the feature reaches general availability, with management options available via the Teams Admin Center or PowerShell (with the Teams module). As Redmond explains, if at least one tenant has the feature enabled, the message warnings will be active across the entire tenant. Microsoft also announced last month that it's working to boost protection against dangerous file types and malicious URLs in Teams chats and channels. Additionally, it noted that Teams will allow security administrators to block incoming communications from a list of blocked domains and delete existing chat messages from users in blocked domains through the Microsoft Defender portal. Redmond announced at last year's Enterprise Connect conference that Teams had reached over 320 million monthly active users across 181 markets. Picus Blue Report 2025 is Here: 2X increase in password cracking 46% of environments had passwords cracked, nearly doubling from 25% last year. Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

Daily Brief Summary

VULNERABILITIES // Microsoft Teams Introduces Malicious Link Warnings for Enhanced Security

Microsoft Teams will soon alert users to potentially harmful links in private messages, targeting spam, phishing, and malware threats within the platform.

The feature will be available to Microsoft Defender for Office 365 and Teams enterprise customers, enhancing existing security measures like Safe Links and ZAP.

A public preview will be rolled out in September 2025 for desktop, Android, web, and iOS users, with general availability expected by November 2025.

Administrators can activate the feature during the public preview through the Teams Admin Center, with default activation planned upon general release.

Microsoft aims to bolster user awareness by displaying warning banners on messages containing flagged URLs, applicable to both internal and external communications.

The new security measure complements recent efforts to block dangerous file types and manage communications from blocked domains within Teams.

With over 320 million monthly active users, this initiative reflects Microsoft's commitment to maintaining robust security across its widespread user base.