SecurityMicrosoft 3659 min read

Who can see your Microsoft Teams messages?

Your manager can't casually read your chats, and yet your deleted messages probably still exist. Both of those are true at once, and the mechanism behind them is worth understanding before you type anything else into Teams.

Published by 1Security TeamAugust 31, 2026
Who can see Microsoft Teams messages and how visibility works

If you've ever hovered over the send button in Teams wondering whether someone in IT reads these, here's the honest version: your manager has no button that opens your chats. There's no dashboard where supervisors scroll through direct messages. And at the same time, every message you send on a work account is company property, stored in a place you can't see, and recoverable long after you've deleted it.

Both halves are true, and most explanations only give you one of them.

Here's the part worth knowing first, because almost nobody outside Microsoft 365 administration does. Teams doesn't really store your chats in Teams. A compliance copy of every chat message is written into a hidden folder inside an Exchange Online mailbox: yours and each recipient's for private chats, the team's group mailbox for channel posts. You can't open that folder from Outlook. It doesn't show up in any client. It exists so that compliance tools can search your messages without ever touching the Teams app, and it's the reason "I deleted it" means much less than people think.

The short answers

QuestionAnswer
Can my manager read my private chats?Not directly. There's no built-in way for a manager to browse chats.
Can anyone at my company read them?Yes, people holding specific compliance roles can search them, and each search is logged.
Are deleted messages really gone?Usually not. The compliance copy survives until retention policy lets it expire.
Do edited messages hide the original?No. Prior versions are kept for compliance search.
Can IT see who I talk to and how much?Yes. Usage reports show activity counts, though not content.
Are my calls recorded?Only when someone records, and Teams announces it to everyone in the call.
Does this apply to my personal Teams account?No. A personal Microsoft account on your own device is outside your employer's tenant.

The rest of this post is the mechanism behind those answers, because the mechanism is what tells you which ones to actually worry about.

Where your messages physically live

When you send a chat message, Teams delivers it through its own service, and a copy lands in a hidden folder of each participant's Exchange mailbox. Microsoft built it this way on purpose. Legal and compliance requirements existed long before Teams did, and Exchange already had the machinery for holds, retention and search. So rather than build all of that again, Teams writes compliance copies into mailboxes and lets the existing machinery do its job.

Channel messages work the same way, except the copy goes to the mailbox that belongs to the team itself rather than to individuals.

Two consequences follow from this design, and they're the two that matter.

First, your messages are searchable by tools that never open Teams. Microsoft Purview's content search and eDiscovery query those hidden folders directly. A search for a keyword across the whole organisation's chats is a routine operation for someone with the right role.

Second, deleting a message in Teams deletes it from the conversation view. The compliance copy in the hidden folder is governed by your organisation's retention policy, not by your delete button. If the policy says chat messages are kept for a year, your deleted message exists for a year. If there's a legal hold on your mailbox, it exists for as long as the hold does.

The same goes for edits. Edit a message and the new version replaces the old one on screen, while the prior version is preserved where compliance search can find it.

So can your manager actually read your chats?

Here's where the anxiety usually outruns the reality.

Reading someone's messages requires a Purview compliance role such as eDiscovery Manager. Those roles aren't handed to line managers. In most organisations they're held by a small number of people in legal, compliance or security, and using them means running a formal search: creating a case, defining a query, exporting results.

And this is the detail that protects you more than any policy document: the search itself is an audited event. When someone runs a content search or opens an eDiscovery case, Microsoft 365 writes that action into the audit log, with the who and the when attached. A compliance officer quietly reading a colleague's messages out of curiosity would be leaving a trail pointed straight at themselves. That doesn't make misuse impossible. It makes it detectable, which changes the incentive entirely.

What a manager can request, through proper channels, is an investigation. HR disputes, harassment complaints and legal proceedings are the situations where chat content actually gets read, and in those situations it will be, thoroughly, including the messages you deleted.

Some organisations also run communication compliance policies, which scan messages automatically for specific categories like harassment or the sharing of sensitive data, and raise flagged items to designated reviewers. If your employer is in a regulated industry, assume something like this exists. It reviews what a policy flagged, though, and isn't a feed of your conversations.

What IT sees without reading anything

Separate from content, Microsoft 365 produces a lot of metadata, and this layer is visible to administrators as part of ordinary operations:

  • Usage reports showing how many messages each person sent, meetings attended and calls made.
  • The unified audit log, recording sign-ins, file access, membership changes and administrative actions, with timestamps, devices and network locations.
  • Message counts and activity patterns per team and channel.

None of this includes what you wrote. It does include the shape of your activity: that you were signed in at 2 AM from a new country, that you downloaded three hundred files on your last day, that an unfamiliar device touched your account. For security teams, this layer is where the real work happens, and it's genuinely more useful to them than your messages ever would be.

Calls and meetings

Teams calls aren't recorded by default. When recording starts, every participant gets a banner, the recording is stored where participants can access it, and transcription is similarly announced. Meeting organisers can see attendance reports: who joined, when, and for how long.

Presence is the one thing colleagues see constantly. Your status, your calendar-driven availability and whether you're in a call are visible organisation-wide by design.

The misconceptions worth retiring

"I deleted the chat, so it's gone." The conversation disappeared from your view. The compliance copies sit in every participant's mailbox under retention. Also, the other person still has their copy on screen.

"IT reads messages when they're bored." Reading content requires roles most IT staff don't have, a formal search process, and it generates audit records. The realistic risk isn't casual snooping; it's that everything becomes readable the moment there's a formal reason.

"Private channels are private from the company." Private channels restrict which colleagues see the content. Compliance search reaches them all the same.

"If I use the web version, there's no trace." The storage happens server-side. The client you use changes nothing about retention or discoverability.

"My personal account is safe on my work laptop." The account is outside your employer's tenant, true. The device may be managed, and network traffic on corporate infrastructure can be subject to monitoring under your employer's policies. Keep truly personal conversations on personal devices.

What employers actually do

Having spent a lot of time around Microsoft 365 tenants, the honest pattern is this: almost no one is reading employee messages day to day. Companies don't have the staff for it, the roles are restricted, and the legal exposure of undisclosed monitoring is worse than whatever they'd find.

What organisations do instead is keep the capability for when something goes wrong. A departing salesperson suspected of taking customer lists. A harassment complaint. A regulator's request. At that point the machinery described above switches on, and it works backwards through history very effectively.

So the practical advice for an employee is boring and real: treat work chat like email you'd be comfortable having read back to you in a meeting, use personal channels for personal things, and don't mistake deletion for erasure.

How organisations get visibility without reading messages

The flip side of this question is the one administrators sit with: how do you oversee a tenant responsibly without becoming the person who reads chats?

The answer that respects both sides is to work at the activity layer, not the content layer. Who signed in, from where, on which device. Who accessed which files, who shared what outside the organisation, which accounts suddenly behave unlike themselves. That's the layer where security problems actually announce themselves, and it doesn't require opening anyone's conversations.

That's also, deliberately, where 1Security operates. It builds its picture from the unified audit log and the permission graph: actors, actions, resources, devices and locations, retained for up to three years so an incident discovered in November can be traced back to March. It does not read Teams messages. Chat content never enters the platform at all, and file and email content is only ever analysed transiently for sensitive-data detection, never stored. The result is that a security team can answer "did this account do anything unusual" in minutes, while the content of everyone's conversations stays exactly where Microsoft's compliance boundary keeps it: reachable only through roles, process and an audit trail.

Visibility and surveillance aren't the same thing, and the healthiest tenants are the ones that know the difference.

Frequently asked questions

Can my employer see Teams messages I send from my phone? If you're signed into your work account, yes, the same storage and retention applies. The device doesn't matter; the account does.

How long are Teams messages kept? Whatever your organisation's retention policy says. There's no universal default you can rely on. Some keep chat for thirty days, some for seven years, and legal holds override deletion entirely.

Can I find out if my messages were searched? Not as an end user. The audit trail of searches exists, but it's visible to administrators and compliance staff, not to the person whose messages were searched.

Do reactions and GIFs get stored too? Message content, including edits and attachments' references, is captured by the compliance machinery. Assume anything you post travels with the message.

Is Teams different from Slack here? The details differ, the principle doesn't. Enterprise messaging platforms are built for organisational ownership of data, with retention and legal discovery as first-class features. If it's a work account, the employer holds the keys.


SecurityMicrosoft 365

Latest Blog Posts

Discover more insights about Microsoft 365 security, governance, and compliance.

View all posts

Take control of Microsoft 365 access today

Stop guessing who has access to your sensitive data. With 1Security, you gain the visibility, automations, and confidence needed to protect your Microsoft 365 environment.