Microsoft Teams Adds Synthetic Audio and Video Detection to Fight Deepfake Meeting Attacks
Microsoft Teams will surface third-party synthetic audio and video detection, with rollout planned from November 2026.
Microsoft lists Teams roadmap item 573451 as in development for Desktop, Mac, and Web in its worldwide multi-tenant cloud, with rollout planned to start in November 2026. Teams will not scan media itself; certified providers will check meeting audio and video for generated or altered content and return signals for in-meeting controls. The entry does not name vendors, pricing, accuracy, or how providers handle meeting data. A separate impersonation feature will warn about suspicious organizers and participants.
- Roadmap ID 573451 begins rollout in November 2026 on desktop, Mac, and web.
- Certified third parties detect synthetic media; Teams only surfaces their signals.
- Vendors, licensing, accuracy, and meeting-data handling are not disclosed.
- A separate control will warn about possible meeting identity impersonation.
Full article505 words · extracted from cybersecuritynews.com · click to collapse
Microsoft Teams is preparing to support synthetic audio and video detection to help organizations spot deepfake attacks. The feature will connect Teams with certified third-party providers that check meeting media for signs of manipulation.
Microsoft lists the update as in development, with rollout scheduled to begin in November 2026. According to the Microsoft 365 roadmap entry, tracked as ID 573451, the update covers Desktop, Mac, and Web in the Worldwide Standard Multi-Tenant cloud.
Its release phases include Targeted Release and General Availability. The November date marks the start of a planned rollout, but it does not confirm that every organization will have access.
Microsoft Teams Deepfake Detection
The key detail is who performs the analysis. Microsoft Teams will not carry out synthetic media detection itself under this feature. Instead, a certified provider will examine meeting audio and video, look for signs of generated or altered content, and send detection signals back to Teams.
Teams will provide the integration needed to surface those signals and support in-meeting experiences and controls. This separates the detection engine from the meeting platform: the provider evaluates the media, while Teams makes the results available within the meeting experience. The roadmap does not describe the interface or response options.
That distinction matters for security planning. The announcement should not be read as a promise that every Teams meeting will automatically receive deepfake scanning. The published entry does not name supported vendors, explain licensing costs, disclose detection accuracy, or outline how providers will handle meeting data. Those details remain important before deployment.
Attackers already use fake faces and voices to make online conversations appear trustworthy. Cybersecurity News reported a deepfake phishing campaign using Zoom or Microsoft Teams calls to target cryptocurrency users.
Victims received invitations through Telegram and saw an AI-generated version of a familiar contact during the call. The attackers then claimed that an audio problem required a plugin or update. That request pushed victims to install malicious software that could steal wallets, credentials, and Telegram accounts.
The attack shows how a convincing video feed can support social engineering without exploiting a flaw in the meeting application.
Microsoft is also developing separate meeting impersonation protection, which will surface warnings and risk indicators when Teams detects possible identity deception.
That feature addresses suspicious organizers and participants, while third-party synthetic media detection focuses on manipulated audio and video. The two protections target related, but different, sources of meeting risk.
For organizations, the update offers another security signal, not proof that a participant is genuine. Teams deepfake detection may help expose manipulated media, but requests to install software, share credentials, or approve payments still deserve independent verification.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.