Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Overview
The User reported security submissions report in the Microsoft Teams admin center helps you review security-related reports submitted by users in your organization. You can export these reports to a CSV file for further analysis.
These user-submitted reports help you identify suspicious activity and strengthen your organization’s security posture by using feedback collected directly from Teams experiences. You can view and export reports for:
- Calling: Calls that users reported for a security concern.
- Chats and channels: Chat and channel messages that users reported for a security concern.
- User: External users that users reported for a security concern.
Prerequisites
Reported interactions appear in the User reported security submissions reports only after users submit reports.
Users can submit reports only when the required reporting settings are enabled in the Teams admin center.
- For calls, the Report a call setting must be turned on in the user's calling policy.
- For chat and channel messages and external users, the Report a security concern setting must be turned on in the user's messaging policy.
View the User reported security submissions report
To view the User reported security submissions report:
In the left navigation of the Teams admin center, go to Analytics & reports > Protection reports.
On the View reports tab, under Report, select User reported security submissions.
Under Report category, choose one of the following categories:
- Calling
- Chats and channels
- User
Under Date range, select a predefined time range. For example, Last 24 hours, Last 7 days, or Last 30 days.
Select Run report.
Interpret the User reported security submissions report
Use the information in the following tables to interpret the data in the Calling, Chats and channels, and User reports.
Calling
| Item | Description |
|---|---|
| Date and time | Date and time when the report was submitted. |
| Reporter name | Name of the user who submitted the report, with a link to their user detail page. |
| Caller name | Number of the caller whose call is being reported. Could be an empty value. |
| Caller phone number | Phone number of the call that's being reported. |
| Call start time | Time stamp when the call began. |
| Submission ID1 | Unique identifier of the submission. |
| Call ID1 | Unique identifier of the reported call. |
| Call duration1 | Length of the call that's reported. |
| Participant list1 | List of participants in the call. |
| Caller ID1 | Microsoft Resource Identifier (MRI) of the caller. Admins can use this identifier when blocking the caller on the External Access page of the Teams admin center. |
| Caller tenant ID1 | Unique identifier of the tenant of the caller that's reported. |
| Caller domain name1 | Domain name of the tenant where the call is reported. |
| Reporter phone number1 | Phone number of the user who submitted the report. |
| Reporter user ID1 | User ID of the user who submitted the report. |
| Reporter display name1 | Display name of the user who submitted the report. |
| Reporter tenant ID1 | Unique identifier of the tenant where the reporter user belongs to. |
| Reporter comments1 | Optional comments that the reporter user sent along with the report, if any. |
1Available only in the exported CSV file.
Chats and channels
| Item | Description |
|---|---|
| Date and time | Date and time when the report was submitted. |
| Reporter name | Name of the user who submitted the report, with a link to their user detail page. |
| Sent from | Sender of the reported message, including their display name and email address, if available. If the sender uses a consumer account, their email address might not be available depending on their privacy setting. |
| Message sent date | Date and time when the reported message was sent. |
| Submission ID1 | Unique identifier of the submission. |
| Reported message1 | Unique identifier of the reported message. |
| Conversation ID1 | Unique identifier of the conversation thread that contains the reported message. |
| Conversation name1 | Name of the conversation thread that contains the reported message, if any. |
| Message last edited1 | Date and time when the reported message was last edited. |
| Participant list1 | List of participants in the conversation, including their display name, email address, and Microsoft Resource Identifier (MRI). Maximum 20 entries: up to 10 entries from the reporter's tenant and up to 10 entries from non-reporter tenants. |
| Participant count1 | Count of the participants in the conversation. |
| Sender user ID1 | Microsoft Resource Identifier (MRI) of the sender. Admins can use this identifier when blocking the sender on the External Access page of the Teams admin center. |
| Sender tenant ID1 | Unique identifier of the tenant where the sender belongs to. This field might be blank if the sender uses a consumer account. |
| Sender domain name1 | Domain of the sender. This field might be blank if the sender uses a consumer account, depending on their privacy setting. |
| Is external1 | Whether the sender is an external user. |
| Reporter user ID1 | User ID of the user who submitted the report. |
| Reporter display name1 | Display name of the user who submitted the report. |
| Reporter email address1 | Email address of the user who submitted the report. |
| Reporter tenant ID1 | Unique identifier of the tenant where the reporter user belongs to. |
| Reporter comments1 | Optional comments that the reporter user sent along with the report, if any. |
1Available only in the exported CSV file.
User
| Item | Description |
|---|---|
| Date and time | Date and time when the report was submitted. |
| Reporter name | Name of the user who submitted the report, with a link to their user detail page. |
| Reported user name | Reported user's display name and email address, if available. If the reported user uses a consumer account, their email address might not be available depending on their privacy setting. |
| First contact date and time | If the user was reported from a 1:1 chat invitation, this field shows the date and time when the first invitation message was sent. This field might be blank if the report was submitted from a group chat invitation or a user's profile card. |
| Submission ID1 | Unique identifier of the submission. |
| Conversation ID1 | Unique identifier of the conversation thread where the user was reported from. This field might be blank if the user was reported from their profile card and not from a conversation. |
| Conversation name1 | Name of the conversation thread where the user was reported from, if any. |
| Reported user ID1 | Microsoft Resource Identifier (MRI) of the reported user. Admins can use this identifier when blocking the user on the External Access page of the Teams admin center. |
| Reported user tenant ID1 | Unique identifier of the tenant where the reported user belongs to. This field might be blank if the reported user uses a consumer account. |
| Reported user domain name1 | Domain of the reported user. This field might be blank if the reported user uses a consumer account, depending on their privacy setting. |
| Reporter user ID1 | User ID of the user who submitted the report. |
| Reporter display name1 | Display name of the user who submitted the report. |
| Reporter email address1 | Email address of the user who submitted the report. |
| Reporter tenant ID1 | Unique identifier of the tenant where the reporter user belongs to. |
| Reporter comments1 | Optional comments that the reporter user sent along with the report, if any. |
| Report submitted from1 | Location where the user was reported from. Possible values include "A/B screen", which refers to the Accept/Block screen for 1:1 and group chat invitations, and "Profile card", which refers to the reported user's profile card. A profile card can be opened by hovering over a user's profile picture anywhere in Teams and isn't necessarily associated with a chat conversation. |
1Available only in the exported CSV file.