Security1 publisherNot yet confirmed elsewhere2 min readPublished
Teams meetings will take deepfake signals from certified outside detectors in November
Microsoft will open Teams meetings to certified third-party deepfake detectors and add built-in impersonation warnings, both due in November. Deepfake coverage will depend on buying a certified outside detector.
The Watch · Security desk
What happened
- Teams' impersonation protection is aimed at deceptive meeting organizers as well as deceptive participants.
- Both features sit on the Microsoft 365 Roadmap as in development and will roll out worldwide before reaching general availability.
- In December Microsoft said admins could lock external users through the Defender portal from January, citing ransomware gangs that use Teams to social-engineer employees.
- A meeting protection policy rolled out in August lets admins automatically block all identified external bots from joining meetings.
- Last month Microsoft said Teams will blur QR codes sent by external senders to cut down phishing and fraud.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Deepfake coverage in Teams meetings will be a purchase from a certified vendor, so organizations that want it at launch have to run vendor evaluation alongside the November rollout.
- constraint Impersonation protection, as Microsoft describes it, informs the employee's choice to join and does not make it for them, so training still has to cover what the risk indicator means.
- exposure Until the deepfake integration ships, synthetic audio and video inside a live meeting fall outside every Teams control Microsoft has announced in this series.
Microsoft is splitting the job in two. For the media, "Organizations can enhance meeting security with synthetic audio and video detection solutions provided by certified third-party providers," Microsoft said [4]. Those vendor tools "analyze meeting media for signs of synthetic or manipulated audio and video and send detection signals to Teams, enabling integrated in-meeting experiences and controls," the company said [5]. Teams supplies the integration that surfaces the signals and lets users act on them [3]. Detection itself stays with the vendor [5].
Identity checks run inside Teams. "When Teams detects a potential impersonation attempt, it surfaces warnings and risk indicators to help users recognize suspicious identities and make more informed decisions when joining or participating in a meeting," Microsoft said [7]. Users get a warning and a risk indicator. Whether to join or stay is still the employee's call [7].
In an executive-impersonation call, the two layers act at different points. An identity warning can appear as the target joins or during the meeting [7]. A synthetic voice or face is checked only once it is in the meeting media, and only where the organization has deployed a certified detector [4][5]. Without that purchase, Teams offers the identity check alone [3][6].
November gives security teams a date to plan meeting controls around, according to the Microsoft 365 Roadmap entries [2]. Picking a detector before then is harder. The roadmap entries, as BleepingComputer reported them, do not name the certified providers or describe the in-meeting controls. Vendor evaluation can start against Microsoft's description of what the tools must do, but the final choice depends on whom Microsoft certifies [4][5].
Each earlier Teams control in the reporting screens something arriving from outside: external accounts, bots, QR codes, guest invitations [13]. The deepfake integration is the first in that series to inspect a meeting's audio and video [13]. Guest-invitation reporting, announced in September, also starts in November [11]. That puts three Teams changes in the same month [12].
What to watch
- Microsoft publishing the list of certified deepfake detection providers and the criteria for certification.
- Whether the in-meeting controls tied to detection signals go beyond warnings, such as removing or muting a flagged participant.
- Any change to the November general-availability date on the Microsoft 365 Roadmap entries.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft will introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings.
ReportedView cited source - [2]
According to new entries on the Microsoft 365 Roadmap, both changes are in development and will reach general availability in November after a worldwide rollout.
ReportedView cited source - [3]
Microsoft says it will provide Teams integration and experiences to surface and act on deepfake detection signals triggered by supported providers.
ReportedView cited source - [4]
"Organizations can enhance meeting security with synthetic audio and video detection solutions provided by certified third-party providers," Microsoft said.
- [5]
"Third-party detection solutions analyze meeting media for signs of synthetic or manipulated audio and video and send detection signals to Teams, enabling integrated in-meeting experiences and controls."
- [6]
Teams will let users detect deceptive meeting organizers and participants through a new impersonation protection security feature.
ReportedView cited source - [7]
"When Teams detects a potential impersonation attempt, it surfaces warnings and risk indicators to help users recognize suspicious identities and make more informed decisions when joining or participating in a meeting,"
- [8]
In December Microsoft announced that admins would be able to lock external users via the Defender portal starting in January, to thwart cybercrime groups including ransomware gangs abusing Teams in social engineering attacks targeting their victims' employees.
ReportedView cited source - [9]
Last month Microsoft said Teams will blur QR codes sent by external senders to provide additional protection against phishing and fraud attempts.
ReportedView cited source - [10]
Microsoft began rolling out a Teams meeting protection policy in August that lets admins block all identified external bots automatically from joining meetings.
ReportedView cited source - [11]
In September Microsoft announced it will let users report suspicious guest invitations directly from Teams starting in November.
ReportedView cited source - [12]
Three Teams changes are dated November in the reporting: third-party deepfake detection support, impersonation protection, and guest-invitation reporting.
Derived - [13]
The earlier Teams controls in the reporting screen external users, external bots, QR codes from external senders and guest invitations; the deepfake integration is the only one of them that inspects meeting audio and video.
Derived
Sources
1 independent publisher whose own reporting we read for this story.
- bleepingcomputer.comMicrosoft Teams to get support for third-party deepfake detection tools
2 articles · October 8, 2026