Microsoft Purview | Insider risk management- Insider risk management for risky agents
Microsoft Purview Insider Risk Management will extend to detect and manage risky AI agent activities in enterprise environments. Features include integration with Copilot Studio and Azure AI Foundry, AI-specific risk policies, and governance of agent workflows. Public preview starts December 2025; general availability by December 2026.

We’re introducing an integration between Microsoft Teams and Microsoft Defender for Office 365 that allows security admins to manage blocked external users in Teams through the Tenant Allow/Block List (TABL) in the Microsoft Defender portal. This centralized approach enhances security and compliance by enabling organizations to control external user access across Microsoft 365 services.
This message is associated with Roadmap ID 542189.
When this will happen:
General Availability (Worldwide): Rollout begins early January 2026 and is expected to complete by mid-January 2026.
How this affects your organization:
Who is affected: Organizations using Microsoft Teams and Microsoft Defender for Office 365 Plan 1 or Plan 2.
What will happen:
- Security admins (with Teams admin permission) can add, delete, and view blocked external users and domains for Teams in the Microsoft Defender portal.
- Incoming communications (chats, channels, meetings, and calls) from blocked users will be prevented.
- Existing communications from blocked users will be automatically deleted.
- Audit logs will track actions taken to block users for compliance monitoring.
- Entry limits: Up to 4,000 blocked domains and 200 email addresses can be configured for Teams.
- This applies to all Teams clients and the Defender XDR web portal.
- Existing federation configurations and domain blocks in the Teams admin center remain unaffected.
Screenshot 1: Image showcasing the teams block sender and block domain list in Microsoft Teams
What you can do to prepare:
- Enable the setting “Block specific users from communicating with people in my organization” in the Teams admin center (default: Off).
- Enable the setting “Allow my security team to manage blocked domains and blocked users” in the Teams admin center (default: Off).
- Grant security team access to manage blocked domains and users in the Teams admin center.
- Review internal documentation and inform helpdesk staff about this change.
- Learn more: Tenant Allow/Block List documentation.
Screenshot 2: Image showing the teams toggle for blocking sender email addresses in Microsoft Teams
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.
Message ID: MC1200579

HANDS ON tek
M365 Admin


