Microsoft is launching Collaboration Security for Microsoft Teams, a solution whose features include an enhancement of full end-to-end encryption.
The solution is among several Defender for Office 365 tools and applications being introduced to Teams as Microsoft, and its other features include enhanced visibility into attacks through end-user reporting and the new capability for IT admins and SecOps to auto-purge malicious messages and attachments after their delivery.
Initially announced in March 2023, Collaboration Security for Microsoft Teams is rolling out now, with full, email-style end-to-end encryption arguably its highlight addition.
Sehrish Khan, Product Marketing Manager at Microsoft, wrote in a blog post in March:
With 71 percent of companies admitting that sensitive and business-critical data is regularly shared via collaboration tools like Microsoft Teams, organizations are increasingly realizing the need to make collaboration security an integral part of their overall SOC strategy. That’s why we are bringing the full feature set that customers use to protect their email environments across prevention, detection, and response to Microsoft Teams."
Microsoft state that Collaboration Security for Microsoft Teams was catalysed by the growth of hybrid and remote working, with the risks to data protection, privacy and security inherent to working over UC and collaboration platforms.
"Attacks like phishing and ransomware that for decades have primarily used email as an entry point are now also targeting users on collaboration tools with growing frequency," Khan added.
Customers of Microsoft E5, Microsoft E5 Security, or Microsoft Defender for Office 365 can now leverage this update to improve their Teams security.
A Series of Welcome Features
As well as introducing full end-to-end encryption in Teams, Microsoft also adds capabilities to improve cybersecurity awareness and resilience for business users.
All collaboration security functions will be integrated with the unified security operations (SecOps) experience of Microsoft 365 Defender, Microsoft's Extended Detection and Response (XDR). As a result, all signals and alerts will be compiled across other domains, including endpoints, identities, email, DLP, and SaaS apps.
Microsoft now enables users to report suspicious messages directly in Teams, similar to how users can report suspicious emails in Outlook. The security team will be alerted whenever users report suspicious messages and can note them in the 365 Defender portal. This is an update of Microsoft's "Safe Links" feature, initially launched in 2021, which scanned URLs shared in Teams conversations, chats, or channels for possibly malicious content at time-of-click to prevent users from accessing malicious websites.
All user submissions will be compiled into an auto-generated investigation of suspicious URL clicks. This will streamline the experience of reviewing suspicious messages for SOC teams, allowing them to respond more quickly.
The automatic purging of potentially malicious messages and attachments is an intriguing capability. "For a faster response and automatic action, we are bringing zero auto purge (ZAP) to Teams, which protects end-users by analysing messages post-delivery and automatically quarantines messages that contain malicious content to stop the actor from compromising the account," Khan wrote.
Once a malicious message or attachment has been identified, the entire Teams ecosystem will be automatically scanned for the same sign of compromise before quarantining all other relevant messages at scale for better protection.




