Try BGBlur

Blur faces instantly with AI-powered face detection

Automatically detect and blur faces in your videos No need for tracking, masking, or in-depth workflows

Microsoft Teams Deepfake Report Button Guide [2026]

Microsoft has rolled out a 'Report' feature in Teams that lets meeting participants flag suspected deepfake impersonation, phishing, or scam activity in real time. This post breaks down exactly how the feature works, why Microsoft built it now, and the practical business risks — CEO impersonation fraud, fake job candidates, and vendor approval scams — it does not fully solve.

Deepfake SecurityMicrosoft TeamsCorporate Fraud PreventionVideo Conferencing SecurityEnterprise Privacy
By Yash Thakker
Featured image

You join a Teams call. Everyone looks and sounds exactly like the colleagues you expect — the CFO, a recruiter, a vendor contact. Then someone asks you to move money, share credentials, or approve an "urgent, confidential" request. Microsoft just built a button for the moment you realize something is wrong. But what happens to the recording after the call ends, once it's downloaded, forwarded, or shared outside the meeting?

Starting in August 2026, Microsoft is rolling out a Report feature inside Teams that lets any meeting participant flag suspected phishing, impersonation, scams, or social-engineering activity directly from a live call, with reports routed to the Microsoft Defender portal and Teams admin center for security teams to investigate. It's a meaningful step against a fraud category that cost businesses hundreds of millions of dollars in 2025 alone. It's also, by design, limited to what a person notices in real time during a live meeting — and it stops at the meeting's edge.

This article breaks down exactly what Microsoft shipped, why now, the real financial stakes for businesses, and — critically — the gap that remains once a meeting is recorded, exported, and starts circulating as a file that no "report" button can touch.

What Is Microsoft's New Teams Report Feature for Deepfakes?

Microsoft's new Report capability lets any participant in a Teams meeting flag suspicious, malicious, or potentially fraudulent activity — including suspected impersonation, phishing attempts, scams, and general social-engineering behavior — without leaving the call. The report is submitted from inside the meeting interface and routed for review rather than requiring the reporter to escalate through a separate ticket or email.

Organizations with Microsoft Defender for Office 365 Plan 1, Plan 2, or Microsoft Defender XDR can review the detailed submission in the Defender portal, alongside their existing phishing and threat data. IT admins also get visibility inside the Teams admin center, under Protection reports > User-reported security submissions, giving security teams a single place to triage meeting-based threats the same way they already triage reported emails. Microsoft's own Tech Community post on the rollout frames video calls as "the new front door" for attackers, reflecting a shift in how impersonation attempts reach employees — no longer just email, but live audio and video.

The important nuance: this is a reporting mechanism, not an automated deepfake detector. Nothing in Teams is scanning faces or voices in real time to flag a synthetic participant before a human notices. The system relies entirely on someone in the meeting recognizing that something feels off and manually pressing the button.

Why Is Microsoft Adding This Now?

Microsoft is responding to a sharp rise in impersonation and social-engineering attacks conducted live over video and voice calls, not just email. The FBI's Internet Crime Complaint Center (IC3) logged $893 million in losses tied to an AI descriptor in 2025 — the first year IC3 tracked AI-enabled fraud as its own category — out of $20.877 billion in total reported cybercrime losses that year, according to the 2025 IC3 Annual Report. Business email compromise, a category increasingly enabled by voice and video deepfakes rather than pure text phishing, accounted for over $3 billion of that total on its own.

The case that put deepfake video-call fraud on every CISO's radar is Arup, the UK engineering firm behind the Sydney Opera House. In January 2024, a Hong Kong finance employee joined a video call with people who looked and sounded exactly like the company's CFO and colleagues, discussing a confidential transaction. Every face and voice on that call was AI-generated from publicly available footage of real executives. The employee authorized transfers totaling $25.6 million before realizing the fraud, as first reported by CNN Business.

That case is not an outlier. Security researchers now estimate deepfake-driven CEO fraud attempts target hundreds of companies daily, and the average documented loss per incident exceeds $500,000. Microsoft's Report button is a direct, sensible response to that pattern — it gives employees an immediate, low-friction way to escalate a call that feels wrong, instead of hoping they remember to email IT security after the fact.

How Does the Teams Report Button Actually Work During a Meeting?

A participant who suspects impersonation, phishing, or a scam clicks Report from within the meeting controls, without needing to leave the call or wait until it ends. The submission captures relevant meeting context and forwards it to the organization's security stack — visible in the Defender portal for Defender for Office 365 and XDR customers, and logged in the Teams admin center's user-reported security submissions view.

This mirrors the model Microsoft already uses for reported phishing emails and suspicious Teams messages: a human flags it, security tooling ingests and triages it, and admins decide on follow-up (blocking a user, alerting finance, notifying legal). The value here is speed and a low bar to act — an employee doesn't need proof, just suspicion, and doesn't need to know which security team or channel to escalate to. That matters in a live fraud attempt, where every minute of hesitation is a minute closer to a wire transfer clearing.

What it does not do is analyze the call itself. There's no automated flag saying "this face doesn't match known biometric patterns" or "this voice shows synthesis artifacts." The entire mechanism depends on a human noticing — and as the Arup case showed, a convincing enough deepfake, delivered with social pressure and familiar faces, often doesn't get noticed until the damage is done.

What Happens After the Meeting Ends — Does Reporting Cover Recordings?

A recorded meeting video file being downloaded, emailed, and shared outside the original live call

No — Microsoft's Report feature is scoped to the live meeting session, not to what happens to a recording afterward. Once a Teams meeting is recorded and that file is downloaded, exported to a shared drive, emailed as an attachment, or forwarded to a third party, the in-app reporting mechanism no longer applies. There's no button inside a downloaded .mp4 file.

This is a meaningful blind spot for any organization that records meetings for compliance, training, board minutes, HR documentation, or later review — which is most mid-size and large businesses. A recorded meeting containing a deepfake participant, or one that gets manipulated after the fact, can sit in a shared drive or get forwarded externally with no built-in verification layer. If that footage is later used as evidence in a dispute, shared with auditors, or referenced in a legal proceeding, nobody has flagged what's actually in it.

This is where a detection-and-anonymization layer for recorded footage becomes the necessary complement to Microsoft's in-meeting tool, not a replacement for it. Businesses handling sensitive recorded meetings — legal depositions conducted over video, HR investigation interviews, vendor negotiation calls — increasingly need the same kind of AI-powered processing already used for KYC video verification and body camera and FOIA redaction workflows, applied to internal corporate meeting archives before that footage is stored, shared, or produced in discovery.

What Does a CEO-Impersonation Deepfake Scam Actually Look Like?

It typically starts with an email or message creating urgency — a "confidential" acquisition, a time-sensitive vendor payment, an unusual finance request — followed by a video call that appears to confirm it's legitimate. The employee sees familiar faces: a CFO, general counsel, sometimes several "colleagues" at once, all rendered from publicly available video and audio (earnings calls, conference talks, LinkedIn videos, press interviews).

In the Arup case, the targeted employee had initial doubts about a phishing-style email but set them aside once the video call reinforced the request with people who "looked and sounded" like colleagues he recognized. That's the core mechanic these scams exploit: video and voice carry disproportionate trust compared to text, and real-time deepfake rendering has gotten good enough to weaponize that trust at scale. We've covered the mechanics of these live-rendered filters — and the practical tests that can expose them — in our guide to detecting deepfake video call scams with the three-finger test, which remains one of the fastest ways for an individual employee to sanity-check a suspicious call in real time.

Are Deepfake Job Candidates and Vendor Approval Scams a Real Risk Too?

Yes — the same real-time face-and-voice rendering used in CEO fraud is showing up in remote job interviews and vendor/finance approval workflows, not just executive impersonation. The FBI and multiple security vendors have documented a rise in fraudulent job candidates using live deepfake filters to pass video interviews, often aiming to gain access to payroll systems, source code repositories, or company-issued hardware once hired.

Deepfake Job Candidates

A convincing deepfake filter mapped onto a stolen identity, combined with a stolen or fabricated resume, can pass a standard video screening interview — especially at companies doing high-volume remote hiring without in-person verification. Once hired, the fraudulent employee has legitimate system access, turning an interview-stage deepfake into an insider-threat problem.

Vendor and Finance Approval Scams

Attackers impersonate a known vendor contact or internal approver on a video call to authorize a fraudulent invoice change, new banking details, or an expedited payment. Because the request comes through a "verified" video call rather than cold email, it bypasses the skepticism finance teams have learned to apply to unsolicited messages.

How Can Businesses Verify a Video Call Participant's Identity Beyond a Report Button?

A shield and magnifying glass icon representing a detection and verification layer behind a video call

Reporting after the fact doesn't prevent the fraud — verification during and around the call does. A layered approach combines in-the-moment checks with process controls and, for anything recorded, a detection pass on the footage itself.

LayerWhat it catchesMicrosoft Report buttonBGBlur / recorded-footage layer
Live call anomalyHuman notices something offYes — manual flag to security teamNot applicable (live-only)
Automated real-time deepfake detectionSynthetic face/voice mid-callNoNot BGBlur's function (see FAQ)
Recorded meeting reviewManipulated footage in stored/shared filesNoYes — process before storage or sharing
Identity redaction for complianceExposure of faces/voices in archived recordingsNoYes — motion-tracked blur, voice anonymization

Practical steps that close the gap between "someone reports it" and "the fraud actually gets stopped":

  1. Verify high-stakes requests through a second channel. Any financial transfer, credential change, or vendor detail update requested on a call — even a video call with familiar faces — should be confirmed via a separate, previously established contact method before action is taken.
  2. Train employees on live detection tests. Simple challenges like asking a participant to turn their head to profile or pass a hand in front of their face can break a real-time filter, as detailed in our three-finger test guide.
  3. Process recorded meetings before they're archived or shared. Run sensitive recordings through a redaction or anonymization pass, similar to how businesses already handle GDPR-grade video anonymization, so improperly exposed identities or manipulated footage don't sit unflagged in shared drives.
  4. Apply the EU AI Act's disclosure logic internally. Even outside the EU, adopting the Article 50 disclosure standard for AI-generated content as an internal policy — flagging any synthetic media used in business communication — reduces ambiguity about what's real.
  5. Compare enterprise redaction tooling against your current stack. Many businesses still rely on manual, frame-by-frame review; our business video redaction software comparison breaks down where automated, browser-based tools outperform manual processes on cost and speed.

Who Needs This Most Right Now?

Finance and accounts payable teams: Anyone with wire authority is a direct target for CEO-impersonation scams; the Arup case specifically targeted a finance employee with transfer authority.

HR and recruiting teams: Remote hiring pipelines that rely solely on video screening are exposed to deepfake candidate fraud, particularly for technical roles with system access.

Legal and compliance teams: Recorded meetings used for depositions, investigations, or regulatory documentation need footage that can be trusted and, where required, properly redacted before archiving or production.

IT and security teams: The Defender portal and Teams admin center integration gives visibility into reported incidents, but building the response playbook (who gets notified, what gets frozen, how recordings get reviewed) is still work internal teams have to do themselves.

Pro Tips for Closing the Deepfake Gap

  1. Don't treat the Report button as detection. It's an escalation path, not a filter — pair it with employee training on live verification tests.
  2. Set a hard rule for financial requests made on any call. No transfer or credential change proceeds without a second-channel confirmation, regardless of who appears to be asking.
  3. Audit where your meeting recordings actually go. Map every place a downloaded Teams recording can end up (local drives, shared folders, email) and apply a redaction/verification step at that point, not just at the meeting level.
  4. Revisit hiring verification for remote roles. Add an in-person or live-camera-movement check for candidates who will get sensitive system access.

Moving From Reactive Reporting to Proactive Protection

Microsoft's Report button is a genuinely useful addition — it gives employees a fast, low-friction way to escalate a suspicious call to the people who can actually investigate it, and it plugs meeting-based threats into the same Defender workflow security teams already use for phishing. But it's built for the moment someone notices, during a live call, and it stops there. It does nothing for the recording that gets downloaded an hour later, the file that gets forwarded to a partner, or the archive that sits in a shared drive for years.

Businesses serious about closing that gap need a layer that works on the recorded file itself: identity verification, redaction, and anonymization applied before sensitive meeting footage leaves controlled storage. BGBlur processes video entirely in-browser — no upload to a third-party server — with motion-tracked face blur, voice anonymization, and object removal, deleting source files within 24 hours. It won't replace Microsoft's live reporting tool, and it isn't a real-time deepfake classifier, but it's exactly the kind of complementary control that turns "someone reported it" into "the footage was properly handled" once the meeting is over. Try BGBlur on your next recorded meeting export and see how quickly identity protection can be applied without adding friction to your existing workflow.

Frequently Asked Questions

It's an in-meeting reporting feature, rolling out from August 2026, that lets any participant flag suspected phishing, impersonation, scam, or social-engineering activity directly from a Teams call. The report gets routed to the Microsoft Defender portal and to the Teams admin center under Protection reports > User-reported security submissions, where security teams can investigate. It works alongside Microsoft Defender for Office 365 Plan 1, Plan 2, or Defender XDR — it is a reporting and triage tool, not an automated deepfake detector.

No. The feature depends on a human participant noticing something is wrong and manually flagging it during or after the call. It does not run real-time facial or voice analysis to catch a deepfake before someone acts on what they saw. That gap matters because in documented cases like the Arup engineering firm's $25.6 million loss, every person on the call looked and sounded convincing enough that no one flagged anything until after the money was gone.

The Report feature is scoped to live meetings — once a recording is downloaded, forwarded by email, or shared to a drive outside Teams, in-app reporting no longer applies. That recorded file can circulate internally or externally with no easy way for a viewer to flag or verify what's in it. Businesses that record meetings for compliance, training, or later review need a separate layer to detect or redact manipulated faces and voices in the exported file itself.

The FBI's Internet Crime Complaint Center logged $893 million in fraud losses tied to an AI descriptor in 2025, the first year IC3 tracked AI as its own category, out of $20.877 billion in total reported cybercrime losses. Business email compromise alone accounted for over $3 billion. Individual incidents can be far larger: UK engineering firm Arup lost $25.6 million after a Hong Kong employee was fooled by a video call where every other 'colleague,' including the CFO, was an AI-generated deepfake.

Typically, a finance or operations employee is invited to a video call that appears to include senior executives — a CFO, CEO, or outside counsel — discussing a confidential, urgent transaction. The faces and voices are synthesized from publicly available earnings calls, interviews, or LinkedIn videos. The urgency and social pressure of seeing familiar 'colleagues' overrides normal verification steps, and the employee authorizes a wire transfer or credential change before anyone double-checks through a separate channel.

Yes. Security researchers and the FBI have both flagged a rise in fraudulent remote job candidates using real-time face-swap filters and stolen identities to pass video interviews, often to gain access to sensitive systems, payroll data, or company laptops once hired. The same real-time rendering techniques used in CEO-impersonation scams apply directly to interview fraud, and a single report button inside the interview platform does little if the interviewer doesn't recognize the red flags in the moment.

Layer manual verification tests (like asking a participant to turn their head in profile or pass a hand in front of their face) with a policy that any financial or credential request made on a call is confirmed through a second, separate channel before action is taken. For recorded meetings, run exported footage through a detection or anonymization tool such as BGBlur before it's archived, shared, or relied on as evidence, so manipulated faces and voices don't sit unflagged in company storage.

BGBlur is an AI-powered, browser-based video privacy tool built for motion-tracked face blur, background blur, license plate blur, object removal, and voice anonymization — it's a detection-adjacent and anonymization layer, not a real-time deepfake classifier. Its relevance here is in the recorded-meeting gap: when a Teams call is downloaded, exported, or shared outside the live session, BGBlur lets security and compliance teams process that footage locally in-browser to redact, verify against known personnel footage, or anonymize identity before the file leaves controlled storage, without uploading sensitive recordings to a third-party server.