Microsoft 365Detection & ResponseRetrospectives

Detecting Teams External Chat Phishing: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2023, written in 2026 with the benefit of hindsight.

Teams chat phishing arrives outside email defenses. These detections help spot suspicious external chats and their consequences.

Signals worth watching

  • First-time external chats from newly created tenants or onmicrosoft.com domains.
  • External sender display names containing "security," "support," "help desk," "Microsoft" or "IT."
  • External chats to many users from the same sender in a short time.
  • MFA approvals or new MFA registrations shortly after an external chat.
  • User-reported Teams messages.

Where the data lives

  • Defender XDR advanced hunting: Teams message events (with Defender for Office 365 Plan 2) and CloudAppEvents.
  • Unified audit log: Teams chat creation events (ChatCreated, MessageSent with external participants, depending on licensing).
  • Entra ID sign-in and audit logs for subsequent MFA activity.

A starting approach

Use the Teams-related advanced hunting tables available in your tenant to list external senders contacting many internal users, then filter by display names that impersonate IT or security. Correlate recipients with sign-in logs for successful sign-ins or MFA registrations within an hour of the chat.

Example correlation pattern (adapt table names to what's available):

CloudAppEvents
| where Application == "Microsoft Teams" and ActionType == "ChatCreated"
| extend Raw = tostring(RawEventData)
| where Raw has "onmicrosoft.com"
| project Timestamp, AccountDisplayName, Raw

Response

  1. Block the external domain in Teams.
  2. Contact recipients to confirm whether they responded.
  3. For users who approved prompts, revoke sessions and reset credentials.
  4. Report the tenant to Microsoft.
detect teams external chat phishingMidnight Blizzard Teams phishing2023

More on this story