Microsoft Teams Is a Phishing Channel Now — How to Lock Down External Access
For years, businesses have trained employees to be suspicious of phishing emails.
But attackers do not have to use email.
Microsoft Teams has become another route for social engineering because a Teams message often feels more immediate and trustworthy than an unexpected email.
An attacker can pose as:
your IT provider
Microsoft support
a customer
a supplier
an executive
somebody from finance
and then attempt to persuade an employee to:
open a malicious link
scan a QR code
approve an MFA request
enter credentials
install remote-support software
share their screen
disclose sensitive information
The key security lesson is simple:
A message arriving through Microsoft Teams is not proof that the sender is trusted.
Why Teams Phishing Works
People have become accustomed to:
phishing banners
suspicious email warnings
junk folders
sender checks
Teams feels different.
A chat feels personal.
The conversation may start innocently and develop over several messages.
An attacker might begin with:
> “Hi, I'm helping your IT team resolve an issue with your Microsoft 365 account.”
They can then gradually introduce:
fake troubleshooting steps
an authentication request
a malicious support link
remote-access software
That conversational approach can be much more convincing than a badly written phishing email.
External Does Not Mean Trusted
Teams can clearly identify somebody as:
External
or:
Guest
but those labels describe their relationship with your organisation.
They do not tell you whether the individual is trustworthy.
An attacker can still use:
realistic display names
convincing photographs
business-looking domains
compromised legitimate tenants
Employees should therefore treat unexpected external Teams contact in exactly the same way they would treat unexpected email.
Verify the person independently before performing a sensitive action.
External Access and Guest Access Are Different
These are frequently confused.
External Access
External access—also known as federation—lets users communicate with Teams users in other organisations.
Typically, external users can:
search for permitted users
chat
call
participate in meetings
They remain in their own tenant.
They do not automatically gain access to your:
Teams channels
SharePoint files
internal resources
Microsoft explicitly describes external access as the appropriate model when users simply need to find, call, chat with or meet people in another Microsoft 365 organisation.
Guest Access
Guest access creates an external identity in your Microsoft Entra tenant.
A guest can potentially be added to:
Teams
channels
SharePoint
groups
applications
depending on your configuration.
Because a B2B guest identity exists in Entra, you can apply controls such as:
MFA
Conditional Access
access reviews.
That distinction is important:
Restricting external federation does not automatically remove guest access.
And:
Removing guest access does not automatically stop federated Teams chats.
Review both.
The Most Important Question
Ask:
Does every employee genuinely need to receive Teams messages from every external Microsoft 365 organisation?
For many SMEs, the answer is no.
Different departments may have very different requirements.
For example:
Sales
May need broad communication with customers.
Recruitment
May regularly speak to external organisations.
Finance
May only need communication with a small number of known partners.
Internal operations
May need no external Teams chat at all.
Microsoft now supports external-access policies that can be targeted rather than relying only on one organisation-wide configuration.
That gives organisations much more flexibility than simply choosing:
Everyone open
or:
Everyone blocked.
Option 1: Allow All External Domains
This is the most permissive configuration.
Employees can communicate with Teams users in other permitted Microsoft 365 organisations unless a specific domain or sender is blocked.
It is convenient.
But it also gives attackers a much larger contact surface.
The business then relies more heavily on:
user awareness
detection
individual blocking
This may be necessary for some highly collaborative organisations.
It should not remain enabled simply because nobody has reviewed it.
Option 2: Block Specific Domains
This lets the organisation permit external access generally while blocking known unwanted domains.
Useful when:
a malicious tenant has been identified
one domain is abusing external Teams communication
But block lists are inherently reactive.
Attackers can move to:
another tenant
another domain
another compromised organisation
So block-only configuration provides flexibility, but not the strongest reduction in attack surface.
Option 3: Allow Only Approved Domains
For businesses with a predictable group of external partners, this can be considerably stronger.
Teams allows administrators to configure:
Allow only specific external domains
and explicitly approve trusted organisations.
For example:
customer.co.uk
supplier.com
legalpartner.co.uk
All other organisational domains are excluded from normal federation.
This does not guarantee approved partners are safe—legitimate organisations can still be compromised.
But it dramatically reduces unsolicited external contact.
Maintain the allow list properly.
Each domain should have:
business owner
reason for access
approval date
review date
removal process
Do not allow domains forever merely because somebody needed them once.
Option 4: Block External Federation Completely
Some organisations simply do not need external Teams chat.
In that case, block it.
But remember:
External access is not the same as meeting access.
Microsoft notes that meeting participation, guest access and anonymous meeting access have their own controls. Blocking federation alone does not necessarily prevent every external person from joining a permitted meeting.
Review:
external access
guest access
anonymous meetings
meeting lobby settings
separately.
Review Unmanaged Teams Accounts
Teams also supports communication with some unmanaged accounts such as Teams Free users.
Microsoft currently lets administrators decide:
whether organisational users can communicate with unmanaged Teams accounts
whether unmanaged users can initiate conversations with employees.
If the business does not need this:
turn it off.
If employees occasionally need to contact personal/unmanaged Teams users, consider disabling the setting that lets those unmanaged users initiate conversations.
That gives you a useful model:
employee intentionally initiates contact
rather than:
unknown account approaches employee.
Microsoft explicitly supports this behaviour.
Block Malicious Teams Senders Quickly
This is an important 2026 improvement.
Microsoft Defender for Office 365 now allows security teams to block malicious:
external domains
individual email addresses
for Teams through the Tenant Allow/Block List.
Microsoft says those blocks propagate into Teams external-access settings and can provide near-real-time protection against further communication.
That means a Teams phishing response process should include:
identify sender → block sender/domain → search for other recipients → investigate user interaction.
Do not rely only on telling one employee to ignore the message.
Enable Teams User Reporting
Employees should be able to report suspicious Teams content directly.
Microsoft currently supports reporting malicious:
chat messages
channel messages
meeting conversation messages
one-to-one calls
where the relevant Teams/Defender configuration and licensing are available.
Users can choose:
More options > Report this message
and identify it as a security risk.
For supported call reporting, users can report suspicious or scam calls from their Teams call history.
Administrators should verify that:
reporting is enabled in Teams
reporting is configured in Defender
reports go somewhere monitored
somebody owns investigation
Microsoft notes that both Teams and Defender settings can matter for correct reporting behaviour.
Defender for Office 365 Protection Has Improved
During 2026 Microsoft expanded several Teams security features.
These include broader Teams user reporting and post-delivery protection such as Zero-hour Auto Purge for supported Defender for Office 365 plans. Microsoft also added direct sender/domain blocking through Defender.
That makes Teams security increasingly similar to modern email security:
detect → report → investigate → remove → block.
Businesses already paying for Defender for Office 365 should make sure these capabilities are actually enabled and operational.
Guest Access Needs Its Own Governance
Guest users can potentially access much more than federated external users.
Review existing guest identities for:
old suppliers
completed projects
former contractors
duplicated guest accounts
guests who no longer have a business sponsor
Microsoft recommends using Microsoft Entra access reviews to periodically confirm whether guests still require access to applications, groups or Teams.
For guest access, consider:
MFA
Conditional Access
appropriate group membership
access expiry/review
restrictions on sensitive resources
Conditional Access Does Not Fix Federation
This is an important correction to make explicit.
You can apply Conditional Access to guest/B2B identities because they exist in Microsoft Entra.
Ordinary Teams external-access users do not become B2B identities in your tenant, so Conditional Access does not apply to federation in the same way. Microsoft documents this directly.
So:
“We require MFA through Conditional Access”
does not mean:
“Every federated external Teams user is covered by our Conditional Access policy.”
External federation security needs to be handled through the Teams external-access controls.
Review Meetings Separately
Attackers can also use meetings for social engineering.
Review:
anonymous meeting join
lobby bypass
who can present
external attendees
meeting chat
recording
transcription
For sensitive meetings, avoid automatically letting anonymous users bypass the lobby.
A meeting link is not proof of identity either.
Teach Employees One Critical Rule
The most important user-training message is:
IT support should not ask you to approve an unexplained MFA prompt.
A common Teams social-engineering pattern is:
> “We're fixing your account. You'll receive an authentication notification—please approve it.”
The correct response is:
1. Do not approve it.
2. Stop the conversation.
3. Contact IT using the normal helpdesk number or portal.
4. Report the Teams message.
5. Preserve the conversation.
The same applies to requests to install remote-support software.
An unexpected external Teams message should never be treated as sufficient authorisation for somebody to control a business computer.
If Somebody Already Interacted With the Attacker
Blocking the sender is not enough.
If the employee:
entered a password
approved MFA
installed remote access
shared their screen
provided sensitive information
treat it as a potential compromise.
Investigate:
active sessions
recent sign-ins
authentication methods
suspicious OAuth/application consent
mailbox rules
endpoint activity
installed remote-access software
Potential containment may include:
password reset
session revocation
account restriction
endpoint isolation
removal of unknown MFA methods
Do not close the incident merely because the Teams sender has been blocked.
A Practical Teams Security Configuration
For many SMEs, I would aim for:
External domains
Allow only approved domains where practical.
Unmanaged Teams users
Disable unless there is a genuine business requirement.
Unmanaged users initiating conversations
Disable where possible.
Malicious senders
Use Defender/Tenant Allow/Block List for rapid blocking.
User reporting
Enable and monitor it.
Guests
Require sponsorship and regular access reviews.
Conditional Access
Apply to guest/B2B users and sensitive applications.
Meetings
Review anonymous access, lobby and presenter settings.
Employees
Train them to distrust unexpected Teams support requests.
The exact balance depends on the organisation.
A business speaking with thousands of customers has different requirements from a professional-services firm collaborating with ten known partners.
Quarterly Teams Security Review
Every few months, review:
allowed external domains
blocked domains/senders
unmanaged-account settings
guest accounts
inactive guests
guest Teams membership
anonymous meeting policy
Teams security reports
Defender Teams alerts
external phishing incidents
External collaboration should evolve as business relationships change.
Otherwise temporary access becomes permanent exposure.
The Most Common Teams Security Mistakes
The ones I see as most important are:
assuming a Teams user is verified because they are on Teams
allowing unrestricted external federation without reviewing whether it is needed
confusing external access with guest access
leaving unmanaged-user communication open unnecessarily
having no Teams reporting process
relying solely on email phishing controls
blocking only one sender without checking whether others were contacted
failing to investigate the device after remote-support software was installed
The central principle is:
Teams is a communication channel—not an identity-verification system.
How Hamilton Group Can Help
Hamilton Group can help businesses review and secure Microsoft Teams collaboration.
We can assist with:
Teams external access
approved-domain allow lists
unmanaged Teams account restrictions
guest-access reviews
Microsoft Entra Conditional Access
Defender for Office 365
Teams phishing reporting
Microsoft 365 security
incident investigation
staff security awareness
The goal is not necessarily to stop external collaboration.
It is to make it deliberate, controlled and monitored.
Visit hgmssp.com or call 0330 043 0069 to discuss Microsoft Teams and Microsoft 365 security.