Breaking
SecurityDeveloping Story

Teams Adds Deepfake Detection to Calls

Microsoft says third-party deepfake detection and impersonation warnings will hit Teams meetings worldwide in November.

··2 hours ago·6 min read
A man sitting at a desk in front of a computer
Photo by Vitaly Gariev on Unsplash

Microsoft is preparing to hand Teams meeting security over to outside specialists, adding support for third-party deepfake detection and a built-in impersonation warning system. Both features are listed as in development on the Microsoft 365 Roadmap and are slated to reach general availability in November following a worldwide rollout.

The move targets a gap that meeting platforms have struggled to close: verifying that the person on screen is actually who their name tag claims. Deepfakes built from synthetic audio and video have become a practical tool for fraud, and Microsoft's answer is to let certified vendors do the detection work rather than build everything in-house.

Third-party detection plugs into Teams

According to the roadmap entries, Microsoft will provide Teams integration and experiences designed to surface and act on deepfake detection signals triggered by supported providers. The company said organizations will be able to enhance meeting security with synthetic audio and video detection solutions supplied by certified third-party providers.

In practice, that means detection vendors analyze the media flowing through a meeting and flag signs of synthetic or manipulated audio and video. Those signals are then sent to Teams, where they drive integrated in-meeting experiences and controls.

"Organizations can enhance meeting security with synthetic audio and video detection solutions provided by certified third-party providers," Microsoft said.

The framing is notable for what it does not promise. Microsoft is not claiming its own models will catch every fake; it is building a pipeline for certified providers to feed detection results into the meeting client, where attendees and admins can see and act on them.

That architecture leaves the hard problem — distinguishing a real participant from a generated one — with the third parties, while Microsoft owns the integration layer and the user experience.

Impersonation warnings arrive in-meeting

The second addition is a new impersonation protection security feature that lets users detect deceptive meeting organizers and participants. According to Microsoft, when Teams detects a potential impersonation attempt it surfaces warnings and risk indicators to help users recognize suspicious identities and make more informed decisions when joining or participating in a meeting.

That is a meaningfully different approach from blocking. Rather than silently ejecting a suspected fraudster, the system pushes context to the person about to join a call — a design choice that puts the final judgment in the user's hands.

It also reflects the reality of modern meeting-based social engineering, where attackers rely on a plausible name, a familiar company logo, and a calendar invite to get past a target's defenses. A warning badge does not stop the call, but it can interrupt the reflex to trust a screen name.

A broader Teams security push

Both roadmap entries sit inside a wider effort to harden Teams against abuse. In December, Microsoft announced that admins would be able to lock external users via the Defender portal starting in January, a change aimed at thwarting cybercrime groups — including ransomware gangs — that abuse Teams in social engineering attacks targeting their victims' employees.

Those attacks have followed a recognizable pattern: an attacker poses as IT support or a colleague, initiates contact through Teams, and uses that trusted channel to move a victim toward malware or credential theft.

Last month, Microsoft added that Teams will blur QR codes sent by external senders, providing additional protection against phishing and fraud attempts. QR codes have become a common vehicle for pushing users toward malicious pages from within chat threads.

Bots, guests, and the November timeline

Microsoft also began rolling out a new Teams meeting protection policy in August that lets admins block all identified external bots automatically from joining meetings. The policy was a direct response to the problem of automated accounts slipping into calls.

More recently, in September, the company announced it will let users report suspicious guest invitations directly from Teams starting in November, to help security teams identify and block phishing attempts and other attacks abusing guest invitations.

That November date now covers a cluster of changes: deepfake detection support, impersonation protection, and guest-invitation reporting all land in the same window. For administrators, that means a single month in which several new controls become available at once.

  • November: general availability for third-party deepfake detection and impersonation protection in Teams meetings, following a worldwide rollout.
  • December: Microsoft announced admins would be able to lock external users via the Defender portal.
  • January: the external-user locking capability was set to begin.
  • August: Microsoft began rolling out a Teams meeting protection policy letting admins automatically block identified external bots.
  • September: Microsoft announced users could report suspicious guest invitations from Teams.

What certified providers actually do

The roadmap language describes detection solutions that analyze meeting media for signs of synthetic or manipulated audio and video, then send detection signals to Teams. The word certified matters here — Microsoft is not opening the integration to any vendor that wants in, but to providers that meet its requirements.

For organizations, that creates a procurement question alongside the technical one. Enabling deepfake detection in Teams will likely mean selecting a supported provider, configuring the integration, and deciding how signals should be handled inside meetings.

It also raises the question of what happens to meeting media when it leaves the platform for analysis, a detail Microsoft's roadmap entries do not address.

Why warnings beat silent blocking

Impersonation protection takes the opposite tack from many security controls. Instead of removing a suspected attacker without explanation, it surfaces warnings and risk indicators so users can recognize suspicious identities themselves.

That choice has tradeoffs. A visible warning can prevent a victim from sharing credentials or approving a payment, but it also depends on the user noticing and understanding the alert at the moment they are joining a call.

For security teams, the feature's value may lie as much in the data it generates as in the warnings it displays. Repeated impersonation flags on the same external account could point to an active campaign against the organization.

What admins should watch

The two roadmap entries are currently listed as in development. Neither Microsoft's announcement nor the roadmap text describes pricing, which providers will be certified, or whether detection works in all meeting types.

Administrators tracking the rollout will want to confirm the November general availability date as it approaches, since roadmaps can shift. They will also need to decide whether impersonation warnings should be enabled by default across the tenant or tuned to specific meeting policies.

The guest-invitation reporting feature arriving in the same month adds another lever: end users flagging suspicious invites, with security teams acting on the reports.

The stakes for meeting security

Video calls have become a normal place to conduct sensitive business — payroll approvals, vendor onboarding, executive instructions — which makes them an attractive target for anyone who can convincingly pretend to be someone else. A deepfake that mimics a voice or face can turn a routine call into a fraud attempt.

By integrating third-party detection rather than building a proprietary system, Microsoft could give organizations more choice and let specialists compete on detection accuracy. The tradeoff is complexity: more vendors, more configuration, and more signals for a security team to triage.

The impersonation warnings may prove the more immediately useful change, because they target the same social engineering dynamics that ransomware crews have already exploited through Teams. If a warning appears when an unfamiliar account tries to join a meeting under a trusted name, it could interrupt an attack at the exact moment it depends on a victim's confidence.

For businesses, the practical takeaway is to treat the November window as a planning deadline rather than a headline. Review which external users and guests can reach employees, decide how deepfake signals should be handled, and make sure staff know what an impersonation warning looks like before one appears. The controls are coming; the policy work around them is still the organization's job.

#microsoft teams#deepfake detection#impersonation protection#video conferencing security#microsoft 365

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories