Microsoft Teams now allows admins to prevent external bots from joining meetings

Microsoft Teams now allows admins to prevent external bots from joining meetings

Microsoft is introducing a new policy for Teams meetings that enables administrators to automatically prevent all recognized external bots from participating in Teams meetings.

This feature enhances a previous Teams policy launched in June, which implemented more intelligent bot protection by ensuring that all identified bots are marked in the lobby and need organizer approval prior to entry.

The latest policy takes it a step further by automatically blocking external bots from joining Teams meetings, eliminating the need for explicit organizer consent for their admission.

According to a Microsoft 365 Message Center update released on Friday, “With this update, organizations can enhance meeting security by configuring Teams policies to automatically block detected external meeting bots from joining meetings. This provides administrators with greater control over the management of identified bots and can help mitigate organizational risk.”

This new administrative policy is being rolled out as part of a targeted release until the end of August and is expected to be generally available worldwide by late September.

It will be accessible under the “Manage bots” meeting protection settings in the Teams admin center, will be disabled by default, and will require activation and assessment by administrators before implementation.

Once activated, the policy can be assigned to specific users or groups through the existing Teams meeting policy management, ensuring that all recognized external meeting bots are barred from joining meetings governed by the newly assigned policy.

This change guarantees that third-party bots (which can serve various functions, from note-taking and transcription to other automated tasks) and harmful applications controlled by malicious actors cannot enter Teams meetings without the knowledge of attendees and organizers regarding the presence of a non-human participant.

As Microsoft cautioned in April, there has been a rise in attacks exploiting Teams for access and lateral movement within enterprise networks, with threat actors impersonating IT or helpdesk personnel to reach out to employees via cross-tenant chats and deceive them into granting remote access to steal data.

Since December, administrators have also been able to block external Teams users through the Defender portal to combat cybercrime groups (including ransomware gangs) attempting to misuse Teams in social engineering attacks targeting employees.

As announced in June, Microsoft is also planning to introduce further administrative controls, including policies to completely block external bots, allow lists for approved bots, admin reports and audit logs on bot detection and presence, and more detailed controls for varying security needs.

Once attackers possess valid credentials, only 37% of their actions are obstructed. Overall prevention metrics can obscure what occurs after initial access. Once attackers are operating with valid credentials, prevention effectiveness declines significantly.

The Blue Report 2026 evaluates defense techniques on a case-by-case basis across 338 million simulations conducted in customer production environments.

Get the report

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top