Microsoft Teams Deepfake Report Button Guide [2026]
Microsoft has rolled out a 'Report' feature in Teams that lets meeting participants flag suspected deepfake impersonation, phishing, or scam activity in real time. This post breaks down exactly how the feature works, why Microsoft built it now, and the practical business risks — CEO impersonation fraud, fake job candidates, and vendor approval scams — it does not fully solve.

You join a Teams call. Everyone looks and sounds exactly like the colleagues you expect — the CFO, a recruiter, a vendor contact. Then someone asks you to move money, share credentials, or approve an "urgent, confidential" request. Microsoft just built a button for the moment you realize something is wrong. But what happens to the recording after the call ends, once it's downloaded, forwarded, or shared outside the meeting?
Starting in August 2026, Microsoft is rolling out a Report feature inside Teams that lets any meeting participant flag suspected phishing, impersonation, scams, or social-engineering activity directly from a live call, with reports routed to the Microsoft Defender portal and Teams admin center for security teams to investigate. It's a meaningful step against a fraud category that cost businesses hundreds of millions of dollars in 2025 alone. It's also, by design, limited to what a person notices in real time during a live meeting — and it stops at the meeting's edge.
This article breaks down exactly what Microsoft shipped, why now, the real financial stakes for businesses, and — critically — the gap that remains once a meeting is recorded, exported, and starts circulating as a file that no "report" button can touch.
What Is Microsoft's New Teams Report Feature for Deepfakes?
Microsoft's new Report capability lets any participant in a Teams meeting flag suspicious, malicious, or potentially fraudulent activity — including suspected impersonation, phishing attempts, scams, and general social-engineering behavior — without leaving the call. The report is submitted from inside the meeting interface and routed for review rather than requiring the reporter to escalate through a separate ticket or email.
Organizations with Microsoft Defender for Office 365 Plan 1, Plan 2, or Microsoft Defender XDR can review the detailed submission in the Defender portal, alongside their existing phishing and threat data. IT admins also get visibility inside the Teams admin center, under Protection reports > User-reported security submissions, giving security teams a single place to triage meeting-based threats the same way they already triage reported emails. Microsoft's own Tech Community post on the rollout frames video calls as "the new front door" for attackers, reflecting a shift in how impersonation attempts reach employees — no longer just email, but live audio and video.
The important nuance: this is a reporting mechanism, not an automated deepfake detector. Nothing in Teams is scanning faces or voices in real time to flag a synthetic participant before a human notices. The system relies entirely on someone in the meeting recognizing that something feels off and manually pressing the button.
Why Is Microsoft Adding This Now?
Microsoft is responding to a sharp rise in impersonation and social-engineering attacks conducted live over video and voice calls, not just email. The FBI's Internet Crime Complaint Center (IC3) logged $893 million in losses tied to an AI descriptor in 2025 — the first year IC3 tracked AI-enabled fraud as its own category — out of $20.877 billion in total reported cybercrime losses that year, according to the 2025 IC3 Annual Report. Business email compromise, a category increasingly enabled by voice and video deepfakes rather than pure text phishing, accounted for over $3 billion of that total on its own.
The case that put deepfake video-call fraud on every CISO's radar is Arup, the UK engineering firm behind the Sydney Opera House. In January 2024, a Hong Kong finance employee joined a video call with people who looked and sounded exactly like the company's CFO and colleagues, discussing a confidential transaction. Every face and voice on that call was AI-generated from publicly available footage of real executives. The employee authorized transfers totaling $25.6 million before realizing the fraud, as first reported by CNN Business.
That case is not an outlier. Security researchers now estimate deepfake-driven CEO fraud attempts target hundreds of companies daily, and the average documented loss per incident exceeds $500,000. Microsoft's Report button is a direct, sensible response to that pattern — it gives employees an immediate, low-friction way to escalate a call that feels wrong, instead of hoping they remember to email IT security after the fact.
How Does the Teams Report Button Actually Work During a Meeting?
A participant who suspects impersonation, phishing, or a scam clicks Report from within the meeting controls, without needing to leave the call or wait until it ends. The submission captures relevant meeting context and forwards it to the organization's security stack — visible in the Defender portal for Defender for Office 365 and XDR customers, and logged in the Teams admin center's user-reported security submissions view.
This mirrors the model Microsoft already uses for reported phishing emails and suspicious Teams messages: a human flags it, security tooling ingests and triages it, and admins decide on follow-up (blocking a user, alerting finance, notifying legal). The value here is speed and a low bar to act — an employee doesn't need proof, just suspicion, and doesn't need to know which security team or channel to escalate to. That matters in a live fraud attempt, where every minute of hesitation is a minute closer to a wire transfer clearing.
What it does not do is analyze the call itself. There's no automated flag saying "this face doesn't match known biometric patterns" or "this voice shows synthesis artifacts." The entire mechanism depends on a human noticing — and as the Arup case showed, a convincing enough deepfake, delivered with social pressure and familiar faces, often doesn't get noticed until the damage is done.
What Happens After the Meeting Ends — Does Reporting Cover Recordings?

No — Microsoft's Report feature is scoped to the live meeting session, not to what happens to a recording afterward. Once a Teams meeting is recorded and that file is downloaded, exported to a shared drive, emailed as an attachment, or forwarded to a third party, the in-app reporting mechanism no longer applies. There's no button inside a downloaded .mp4 file.
This is a meaningful blind spot for any organization that records meetings for compliance, training, board minutes, HR documentation, or later review — which is most mid-size and large businesses. A recorded meeting containing a deepfake participant, or one that gets manipulated after the fact, can sit in a shared drive or get forwarded externally with no built-in verification layer. If that footage is later used as evidence in a dispute, shared with auditors, or referenced in a legal proceeding, nobody has flagged what's actually in it.
This is where a detection-and-anonymization layer for recorded footage becomes the necessary complement to Microsoft's in-meeting tool, not a replacement for it. Businesses handling sensitive recorded meetings — legal depositions conducted over video, HR investigation interviews, vendor negotiation calls — increasingly need the same kind of AI-powered processing already used for KYC video verification and body camera and FOIA redaction workflows, applied to internal corporate meeting archives before that footage is stored, shared, or produced in discovery.
What Does a CEO-Impersonation Deepfake Scam Actually Look Like?
It typically starts with an email or message creating urgency — a "confidential" acquisition, a time-sensitive vendor payment, an unusual finance request — followed by a video call that appears to confirm it's legitimate. The employee sees familiar faces: a CFO, general counsel, sometimes several "colleagues" at once, all rendered from publicly available video and audio (earnings calls, conference talks, LinkedIn videos, press interviews).
In the Arup case, the targeted employee had initial doubts about a phishing-style email but set them aside once the video call reinforced the request with people who "looked and sounded" like colleagues he recognized. That's the core mechanic these scams exploit: video and voice carry disproportionate trust compared to text, and real-time deepfake rendering has gotten good enough to weaponize that trust at scale. We've covered the mechanics of these live-rendered filters — and the practical tests that can expose them — in our guide to detecting deepfake video call scams with the three-finger test, which remains one of the fastest ways for an individual employee to sanity-check a suspicious call in real time.
Are Deepfake Job Candidates and Vendor Approval Scams a Real Risk Too?
Yes — the same real-time face-and-voice rendering used in CEO fraud is showing up in remote job interviews and vendor/finance approval workflows, not just executive impersonation. The FBI and multiple security vendors have documented a rise in fraudulent job candidates using live deepfake filters to pass video interviews, often aiming to gain access to payroll systems, source code repositories, or company-issued hardware once hired.
Deepfake Job Candidates
A convincing deepfake filter mapped onto a stolen identity, combined with a stolen or fabricated resume, can pass a standard video screening interview — especially at companies doing high-volume remote hiring without in-person verification. Once hired, the fraudulent employee has legitimate system access, turning an interview-stage deepfake into an insider-threat problem.
Vendor and Finance Approval Scams
Attackers impersonate a known vendor contact or internal approver on a video call to authorize a fraudulent invoice change, new banking details, or an expedited payment. Because the request comes through a "verified" video call rather than cold email, it bypasses the skepticism finance teams have learned to apply to unsolicited messages.
How Can Businesses Verify a Video Call Participant's Identity Beyond a Report Button?

Reporting after the fact doesn't prevent the fraud — verification during and around the call does. A layered approach combines in-the-moment checks with process controls and, for anything recorded, a detection pass on the footage itself.
| Layer | What it catches | Microsoft Report button | BGBlur / recorded-footage layer |
|---|---|---|---|
| Live call anomaly | Human notices something off | Yes — manual flag to security team | Not applicable (live-only) |
| Automated real-time deepfake detection | Synthetic face/voice mid-call | No | Not BGBlur's function (see FAQ) |
| Recorded meeting review | Manipulated footage in stored/shared files | No | Yes — process before storage or sharing |
| Identity redaction for compliance | Exposure of faces/voices in archived recordings | No | Yes — motion-tracked blur, voice anonymization |
Practical steps that close the gap between "someone reports it" and "the fraud actually gets stopped":
- Verify high-stakes requests through a second channel. Any financial transfer, credential change, or vendor detail update requested on a call — even a video call with familiar faces — should be confirmed via a separate, previously established contact method before action is taken.
- Train employees on live detection tests. Simple challenges like asking a participant to turn their head to profile or pass a hand in front of their face can break a real-time filter, as detailed in our three-finger test guide.
- Process recorded meetings before they're archived or shared. Run sensitive recordings through a redaction or anonymization pass, similar to how businesses already handle GDPR-grade video anonymization, so improperly exposed identities or manipulated footage don't sit unflagged in shared drives.
- Apply the EU AI Act's disclosure logic internally. Even outside the EU, adopting the Article 50 disclosure standard for AI-generated content as an internal policy — flagging any synthetic media used in business communication — reduces ambiguity about what's real.
- Compare enterprise redaction tooling against your current stack. Many businesses still rely on manual, frame-by-frame review; our business video redaction software comparison breaks down where automated, browser-based tools outperform manual processes on cost and speed.
Who Needs This Most Right Now?
Finance and accounts payable teams: Anyone with wire authority is a direct target for CEO-impersonation scams; the Arup case specifically targeted a finance employee with transfer authority.
HR and recruiting teams: Remote hiring pipelines that rely solely on video screening are exposed to deepfake candidate fraud, particularly for technical roles with system access.
Legal and compliance teams: Recorded meetings used for depositions, investigations, or regulatory documentation need footage that can be trusted and, where required, properly redacted before archiving or production.
IT and security teams: The Defender portal and Teams admin center integration gives visibility into reported incidents, but building the response playbook (who gets notified, what gets frozen, how recordings get reviewed) is still work internal teams have to do themselves.
Pro Tips for Closing the Deepfake Gap
- Don't treat the Report button as detection. It's an escalation path, not a filter — pair it with employee training on live verification tests.
- Set a hard rule for financial requests made on any call. No transfer or credential change proceeds without a second-channel confirmation, regardless of who appears to be asking.
- Audit where your meeting recordings actually go. Map every place a downloaded Teams recording can end up (local drives, shared folders, email) and apply a redaction/verification step at that point, not just at the meeting level.
- Revisit hiring verification for remote roles. Add an in-person or live-camera-movement check for candidates who will get sensitive system access.
Moving From Reactive Reporting to Proactive Protection
Microsoft's Report button is a genuinely useful addition — it gives employees a fast, low-friction way to escalate a suspicious call to the people who can actually investigate it, and it plugs meeting-based threats into the same Defender workflow security teams already use for phishing. But it's built for the moment someone notices, during a live call, and it stops there. It does nothing for the recording that gets downloaded an hour later, the file that gets forwarded to a partner, or the archive that sits in a shared drive for years.
Businesses serious about closing that gap need a layer that works on the recorded file itself: identity verification, redaction, and anonymization applied before sensitive meeting footage leaves controlled storage. BGBlur processes video entirely in-browser — no upload to a third-party server — with motion-tracked face blur, voice anonymization, and object removal, deleting source files within 24 hours. It won't replace Microsoft's live reporting tool, and it isn't a real-time deepfake classifier, but it's exactly the kind of complementary control that turns "someone reported it" into "the footage was properly handled" once the meeting is over. Try BGBlur on your next recorded meeting export and see how quickly identity protection can be applied without adding friction to your existing workflow.