Microsoft adds malicious link warnings to Teams private chats

Microsoft Teams

Microsoft Teams will automatically alert users when they send or receive a private message containing links that are tagged as malicious.

Microsoft will introduce these new warnings for messages containing URLs that have been flagged as spam, phishing, or malware, for all Microsoft Defender for Office 365 (MDO) and Microsoft Teams enterprise customers.

The new link protection feature will begin rolling out with a public preview for desktop, Android, web, and iOS users in September 2025 and is expected to reach general availability in November 2025, according to a recent Microsoft 365 roadmap entry.

“To help users stay protected from malicious content, we’re introducing message warnings in Microsoft Teams,” the company explained in an incident alert published in the Microsoft 365 message center on Wednesday.

“This new feature displays a warning banner on messages containing URLs flagged as Spam, Phish, or Malware—whether the message is internal or external. These warnings enhance user awareness and complement existing security protections like Safe Links and ZAP.”

Malicious URL warning in Teams
Malicious URL warning in Teams (Microsoft)

​Admins can opt in to enable this new feature in public preview by using the toggle available in the Teams Admin Center > Messaging settings.

Malicious URL warnings will be displayed directly on the message and will be enabled by default after the feature reaches general availability, with management options available via the Teams Admin Center or PowerShell (with the Teams module).

As Redmond explains, if at least one tenant has the feature enabled, the message warnings will be active across the entire tenant.

Microsoft also announced last month that it’s working to boost protection against dangerous file types and malicious URLs in Teams chats and channels.

Additionally, it noted that Teams will allow security administrators to block incoming communications from a list of blocked domains and delete existing chat messages from users in blocked domains through the Microsoft Defender portal.

Redmond announced at last year’s Enterprise Connect conference that Teams had reached over 320 million monthly active users across 181 markets.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

Leave a Comment