Microsoft adds Teams message snippets to Defender threat hunting

The MessageContents table will expose content and metadata to authorized analysts, forcing administrators to revisit who can read collaboration data.

By · Published

Primary source: MS Message Center

Why it matters

Teams investigations have relied heavily on URLs, verdicts and message metadata. Queryable snippets give analysts crucial context, while making least-privilege access to employee communications a more urgent administrative requirement.

A cybersecurity analyst intently observes dynamic data visualizations on multiple screens in a dimly lit security operations center.

Microsoft will add Teams message snippets to Defender XDR's Advanced Hunting service, giving authorized security analysts content-level data they can correlate with alerts, identities and other evidence during an investigation.

The new MessageContents table will begin rolling out worldwide in late September and is expected to reach all eligible customers by mid-October, according to Microsoft 365 Message Center notice MC1474106, published September 18th. Microsoft says users will need both Advanced Hunting access and message preview permissions to query the table.

The change moves Microsoft Defender's Teams investigations beyond the largely metadata- and URL-focused records currently available to threat hunters. Analysts will gain snippets of the messages surrounding suspicious activity, providing context that sender addresses, timestamps, threat verdicts and links cannot supply on their own.

From message metadata to message content

Microsoft's existing Teams security documentation directs analysts to three Advanced Hunting tables: MessageEvents, MessagePostDeliveryEvents and MessageUrlInfo. Those tables cover message delivery, post-delivery security events and URLs shared through Teams.

The current MessageEvents schema includes fields such as the sender, recipients, thread, message format, threat type, detection method and delivery action. Microsoft says the table surfaces metadata for all messages from external conversations and for internal messages containing URLs.

MessageContents adds part of the communication itself to that dataset. Microsoft says the initial coverage follows the underlying Teams message metadata source and includes messages containing URLs and federated messages, which are conversations involving users outside an organization's tenant.

That scope makes the table useful for phishing and social-engineering investigations where the text surrounding a link can explain the attack. An analyst could use message context alongside account, device and URL telemetry to reconstruct how a recipient was approached and whether similar language appeared elsewhere in an incident.

Advanced Hunting uses Kusto Query Language, allowing security teams to join records across Defender data sources. Microsoft also lets organizations turn suitable Advanced Hunting queries into custom detection rules that generate alerts and trigger response actions. The Message Center notice, however, describes MessageContents as an investigation capability and does not specify its use in automated detections.

Access becomes the administrative issue

Microsoft expects no direct end-user impact. The administrative consequences are more substantial because the new table places employee communication snippets inside a query interface used by security operations teams.

Microsoft is telling administrators to review existing role assignments, decide which analysts require message-content access and update investigation procedures where necessary. Organizations that do not plan to use the table do not need to take action.

Microsoft's unified role-based access control documentation already separates basic security data, collaboration metadata and collaboration content into distinct read permissions. That separation gives administrators a way to let analysts hunt across incidents and metadata without automatically granting access to message content.

The practical task is to verify that broad security roles have not accumulated content permissions beyond what each analyst needs. Teams chats can contain personnel discussions, customer information and internal operational details that are irrelevant to most investigations. Queryable snippets increase investigative visibility while widening the consequences of an overly broad role assignment.

Microsoft's current product matrix places Advanced Hunting for Teams under Microsoft 365 E5 and Defender for Office 365 Plan 2. The rollout therefore targets security teams already using Microsoft's higher-tier collaboration defenses, including Safe Links, message quarantine, post-delivery cleanup and Teams remediation tools.

For those teams, MessageContents fills a clear gap. Defender could already identify a suspicious Teams message, expose its participants and URLs, and support remediation. Analysts will now be able to inspect part of what the sender actually said, provided administrators deliberately grant that access.

Reader comments

Conversation for this story loads after sign-in.