logo
search
Security Policy Errors

How to Customize Microsoft Defender User-Reported Message Emails

Maira MehtabMaira Mehtab Sep 22, 2026 868 views

Question details

An administrator needs to customize the automated results emails for user-reported messages in Microsoft Defender for Office, specifically looking to clarify the configuration of the email body, footer, header, and text formatting limitations.

Product
Microsoft Defender for Office 365
Device & OS
not provided
Scenario
Configuring customized email notifications to end-users after they report suspicious emails.
Observed behavior
The administrator requires guidance on supported customization fields, tenant-specific behavior, and formatting limits for HTML or plain text.
Before you start

Ensure you have the required Global Administrator or Security Administrator permissions in your Microsoft 365 tenant to access and modify threat policies.

Solution 1Recommended

Configure User-Reported Message Settings in Microsoft 365 Defender

Use the Microsoft 365 Defender portal to adjust the notification email text and verify your tenant's formatting support.

Microsoft Defender allows administrators to customize the results email sent to users who report suspicious messages. Because body and footer fields may have specific length and HTML formatting limitations depending on the tenant, it is critical to test the markup directly in the portal.

1
Access the Microsoft 365 Defender Portal

Navigate to the Microsoft 365 Defender portal (security.microsoft.com) and log in using your administrator credentials.

2
Navigate to Threat Policies

Go to Policies & rules > Threat policies from the left-hand navigation menu.

3
Open User Reported Settings

Click on 'User reported message settings' to access the configuration for reported emails.

4
Customize Email Notifications

Scroll down to the 'Email notifications' section. Here you can edit the text for the header, body, and footer of the results email. Check the official Microsoft Defender documentation to confirm which HTML tags or text markup formats are currently supported for your specific subscription.

5
Seek Advanced Support if Needed

If you experience tenant-specific behavior where text formatting is not saving or rendering correctly, open a support ticket or ask Microsoft security experts in the Tech Community.

Formatting Limitations: Complex HTML elements may be stripped out for security reasons. Stick to basic formatting tags and always send a test email to verify the output.
Free Microsoft Office alternative

Looking for a Lightweight and Free Office Suite?

While enterprise tools like Microsoft Defender handle advanced security policies, day-to-day document creation requires an efficient, user-friendly office suite. WPS Office is a lightweight, highly compatible alternative to Microsoft Office that is perfect for everyday productivity.

  1. 1. Download WPS Office: Visit the official WPS website and download the installer for your Windows, Mac, or Linux operating system.
  2. 2. Install the Application: Run the setup file and follow the on-screen instructions to install the suite in minutes.
  3. 3. Start Creating: Open WPS Office to instantly view, edit, or create documents, spreadsheets, and presentations with high compatibility.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight application that uses minimal system resources and runs smoothly on all devices.Familiar tabbed interface that makes switching from Microsoft Office completely seamless.Free to download and use, avoiding complicated enterprise licensing and subscriptions.
microsoft office alternative - wps office

Frequently Asked Questions

Can I use HTML formatting in the Microsoft Defender custom email body?

Yes, basic HTML formatting is generally supported for customizing the header, body, and footer of the user-reported message emails. However, advanced scripts and certain complex tags will be restricted. It is best to test the formatting after applying changes.

What permissions are required to change user-reported message settings?

You must be assigned the Global Administrator or Security Administrator role in your Microsoft Entra ID (formerly Azure AD) to modify threat policies and customize these notifications in the Defender portal.

Why aren't my customized Defender email footers showing up for users?

If your customizations are not appearing, ensure the policy is saved and explicitly enabled in the portal. Also, check if your entered text exceeded the character limit for that specific field, or if the recipient's email client is blocking the applied formatting.