DMC 30 Years in Business Logo
(419) 535-2900

New Security Enhancement Coming to Microsoft Defender for Office 365: Zero-Hour Auto-Purge (ZAP) for Microsoft Teams

Organizations relying on Microsoft 365 continue to face an evolving landscape of phishing attempts, malware links, and increasingly sophisticated social engineering threats. Microsoft is rolling out another important layer of protection, and if your organization uses Microsoft Defender for Office 365 Plan 1, this upgrade is coming your way automatically.

Beginning January 6, 2026, Microsoft will enable Zero-Hour Auto-Purge (ZAP) protection for Microsoft Teams by default for all tenants with Defender for Office 365 Plan 1. This updated functionality is designed to automatically remove malicious messages after they’ve been delivered, providing an essential safety net for content shared within Teams chats and channels.

Whether you already have Defender for Office 365 or are evaluating the right security stack for your organization, here’s what this means for you.

What Is Zero-Hour Auto-Purge (ZAP)?

Zero-Hour Auto-Purge automatically detects and removes phishing and malware content—even after delivery. Until now, ZAP has mainly applied to email. With this new release, it will extend into Microsoft Teams, providing similar real-time remediation by moving unsafe messages into admin quarantine within the Microsoft 365 Security portal.

This allows security administrators to review, release, or delete malicious content without exposing end users to harmful links or files.

What’s Changing?

Starting early January 2026, the following updates will roll out globally:

✔ ZAP Protection for Teams Will Be Turned On by Default

All Defender for Office 365 Plan 1 customers will automatically gain ZAP protections for internal Teams chats and channels.

✔ Malicious Teams Content Will Move to Admin Quarantine

Any internal Teams message identified as phishing or carrying malware will be removed from users’ chats and placed into the Security Portal → Quarantine → Teams section.

✔ No End-User Impact

Users won’t see quarantined messages or alerts. All review and release actions will occur on the admin side.

✔ No Policy Changes Required

Your current ZAP configuration settings will carry over automatically. You only need to take action if you plan to opt out.

This enhancement is associated with Microsoft 365 Roadmap ID 529816.

Who This Impacts

  • All organizations using Microsoft Defender for Office 365 Plan 1 with Microsoft Teams.
  • Administrators responsible for Teams security, incident response, and message quarantine review.

Why This Matters

Microsoft Teams has become a central hub for internal communication—and attackers have taken notice. The addition of ZAP to Teams:

  • Strengthens your protection against phishing links shared in chats
  • Reduces the window of exposure to malicious content
  • Gives IT admins more visibility and control over quarantined Teams messages
  • Ensures ongoing protection without requiring manual policy updates

If you already use Defender for Office 365 Plan 1, this is a significant security upgrade with no additional cost.

If you're not using Defender for Office 365 yet, this is another strong reason to consider adding it to your Microsoft 365 environment.

Key Dates

  • December 6, 2025 – January 5, 2026
    Window to opt out of the default-on ZAP setting.
  • January 6, 2026
    ZAP for Teams becomes default-on for all Defender for Office 365 Plan 1 tenants.
  • Early–Mid January 2026
    Worldwide rollout completes.

What Your Organization Should Do Now

1. Review your ZAP settings

Verify your current configurations in the Microsoft 365 Security portal.

2. Communicate with internal IT teams

Helpdesk and IT support should understand how quarantined Teams messages will be handled.

3. Decide whether you want to opt out

Microsoft gives a short window (Dec 6, 2025 – Jan 5, 2026) to disable the auto-enable behavior. Most organizations will want to keep ZAP enabled.

4. Prepare for new monitoring workflows

Admins can manage Teams quarantined messages via the Microsoft Defender portal. Familiarizing yourself with these views now can help streamline incident response later.

Do You Already Have Defender for Office 365?

Great news—this upgrade is included and will be activated automatically. No action is needed unless you prefer to opt out.

Not Using Defender for Office 365 Yet?

Now is a great time to consider it. Defender brings advanced protection layers—including Safe Links, Safe Attachments, threat investigation tools, and now expanded ZAP coverage—to help secure your Microsoft 365 environment.

If you're unsure what plan you have or want to understand whether Plan 1 or Plan 2 is right for you, we’re here to help.

Let’s Talk About the Right Protection for Your Organization

Our team can help you:

  • Determine whether you already have Defender for Office 365
  • Review your current security posture
  • Recommend the best-fit protection for Microsoft 365 environments
  • Enable and optimize ZAP and threat management features

If you’d like to discuss Defender for Office 365 or need support preparing for these upcoming changes, reach out to DMC Technology Group, Toledo’s IT Pros, anytime.

Jason Hood

President, DMC Technology Group

Jason Hood brings over 30 years of IT leadership to DMC, having successfully guided companies through transformative business initiatives across a range of industries.

7657 king's point rd.

toledo, ohio 43617

Copyright © 2026 | All Rights Reserved |
magnifiercross linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram