Microsoft Teams to add deepfake, impersonation alerts

Microsoft Teams to add deepfake, impersonation alerts

Microsoft is preparing two new security features for Teams meetings: support for deepfake detection tools built by third-party vendors and a built-in impersonation protection capability.

Both features appear as new entries on the Microsoft 365 Roadmap, the company's public list of upcoming product changes. They are listed as in development and are scheduled to reach general availability in November, following a worldwide rollout.

Third-party tools will feed signals into Teams

Microsoft will not build the deepfake detection engine itself. Certified third-party providers will analyze audio and video during meetings, and Teams will display and act on the alerts they generate.

"Organizations can enhance meeting security with synthetic audio and video detection solutions provided by certified third-party providers," Microsoft said.

The company explained how the integration works: "Third-party detection solutions analyze meeting media for signs of synthetic or manipulated audio and video and send detection signals to Teams, enabling integrated in-meeting experiences and controls."

Teams will provide the integration and the user-facing experience, so detection signals from supported providers can be surfaced inside a meeting and acted on there. Microsoft has not named the providers or said how vendors will be certified.

Warnings about suspicious organizers and participants

The second feature targets people who pose as someone else in a meeting, whether they organize it or join it. Teams will flag deceptive identities through a new impersonation protection feature.

"When Teams detects a potential impersonation attempt, it surfaces warnings and risk indicators to help users recognize suspicious identities and make more informed decisions when joining or participating in a meeting," Microsoft said.

The company has not said which signals Teams will use to decide that an identity looks suspicious.

Part of a wider push to lock down Teams

The new features follow a series of Teams security changes Microsoft announced over the past year.

In December, Microsoft said admins would be able to lock external users through the Defender portal starting in January. The goal was to stop cybercrime groups, including ransomware gangs, that abuse Teams in social engineering attacks aimed at their victims' employees.

In August, Microsoft started rolling out a Teams meeting protection policy that lets admins automatically block all identified external bots from joining meetings.

In September, the company announced that users will be able to report suspicious guest invitations directly from Teams starting in November. The reports are meant to help security teams spot and block phishing and other attacks that abuse guest invitations.

Last month, Microsoft also said Teams will blur QR codes sent by external senders, as an extra layer of protection against phishing and fraud.

Taken together, these changes cover several stages of an attack: who can contact users, who can join meetings, what content they can send, and now whether the person on screen is who they claim to be.

Our Take

Teams is no longer just a chat and meeting tool. For many attackers, it has become a way in. The earlier measures described above, from locking external users to blurring QR codes, show that Microsoft treats the platform as an attack surface in its own right. Ransomware gangs and other cybercrime groups have used it to reach employees directly and talk them into handing over access.

Deepfake detection is the logical next step. Social engineering that relies on a fake IT helpdesk message is one thing. A live video call with a convincing synthetic voice or face is harder to question, and most users have no reliable way to tell the difference on their own. Moving the check into the meeting itself, instead of relying on staff to spot clues, suggests Microsoft sees manipulated media as a practical threat and not a distant one.

Relying on certified third-party vendors is an interesting choice. It lets Microsoft offer the capability quickly, but it also means organizations will likely need to license and evaluate a separate product before the feature does anything for them. It is worth watching which vendors join the program, how accurate their detection proves in real meetings, and how often legitimate participants get flagged by mistake.

The impersonation protection feature may end up having a broader impact, since it does not appear to depend on an outside provider. How well it works will depend on the identity signals behind it, which Microsoft has not yet described.

For defenders, the practical advice stays the same. Teams hardening should sit alongside email controls such as Microsoft's plan to block MSIX attachments in Outlook, and alongside processes that let staff report and triage phishing quickly. Detection tools can raise a warning, but verification procedures for sensitive requests, such as callbacks over a known channel, will remain important once the November rollout begins.