Skip to main content

Microsoft Teams Is a Phishing Channel Now — How to Lock Down External Access

Media Teams Is a Phishing Channel Now — External Access Settings to Lock Down

 

For years, businesses have trained employees to be suspicious of phishing emails.

But attackers do not have to use email.

Microsoft Teams has become another route for social engineering because a Teams message often feels more immediate and trustworthy than an unexpected email.

An attacker can pose as:

your IT provider

Microsoft support

a customer

a supplier

an executive

somebody from finance


and then attempt to persuade an employee to:

open a malicious link

scan a QR code

approve an MFA request

enter credentials

install remote-support software

share their screen

disclose sensitive information


The key security lesson is simple:

A message arriving through Microsoft Teams is not proof that the sender is trusted.

Why Teams Phishing Works

People have become accustomed to:

phishing banners

suspicious email warnings

junk folders

sender checks


Teams feels different.

A chat feels personal.

The conversation may start innocently and develop over several messages.

An attacker might begin with:

> “Hi, I'm helping your IT team resolve an issue with your Microsoft 365 account.”

 

They can then gradually introduce:

fake troubleshooting steps

an authentication request

a malicious support link

remote-access software


That conversational approach can be much more convincing than a badly written phishing email.

External Does Not Mean Trusted

Teams can clearly identify somebody as:

External

or:

Guest

but those labels describe their relationship with your organisation.

They do not tell you whether the individual is trustworthy.

An attacker can still use:

realistic display names

convincing photographs

business-looking domains

compromised legitimate tenants


Employees should therefore treat unexpected external Teams contact in exactly the same way they would treat unexpected email.

Verify the person independently before performing a sensitive action.

External Access and Guest Access Are Different

These are frequently confused.

External Access

External access—also known as federation—lets users communicate with Teams users in other organisations.

Typically, external users can:

search for permitted users

chat

call

participate in meetings


They remain in their own tenant.

They do not automatically gain access to your:

Teams channels

SharePoint files

internal resources


Microsoft explicitly describes external access as the appropriate model when users simply need to find, call, chat with or meet people in another Microsoft 365 organisation.

Guest Access

Guest access creates an external identity in your Microsoft Entra tenant.

A guest can potentially be added to:

Teams

channels

SharePoint

groups

applications


depending on your configuration.

Because a B2B guest identity exists in Entra, you can apply controls such as:

MFA

Conditional Access

access reviews.


That distinction is important:

Restricting external federation does not automatically remove guest access.

And:

Removing guest access does not automatically stop federated Teams chats.

Review both.

The Most Important Question

Ask:

Does every employee genuinely need to receive Teams messages from every external Microsoft 365 organisation?

For many SMEs, the answer is no.

Different departments may have very different requirements.

For example:

Sales

May need broad communication with customers.

Recruitment

May regularly speak to external organisations.

Finance

May only need communication with a small number of known partners.

Internal operations

May need no external Teams chat at all.

Microsoft now supports external-access policies that can be targeted rather than relying only on one organisation-wide configuration.

That gives organisations much more flexibility than simply choosing:

Everyone open

or:

Everyone blocked.

Option 1: Allow All External Domains

This is the most permissive configuration.

Employees can communicate with Teams users in other permitted Microsoft 365 organisations unless a specific domain or sender is blocked.

It is convenient.

But it also gives attackers a much larger contact surface.

The business then relies more heavily on:

user awareness

detection

individual blocking


This may be necessary for some highly collaborative organisations.

It should not remain enabled simply because nobody has reviewed it.

Option 2: Block Specific Domains

This lets the organisation permit external access generally while blocking known unwanted domains.

Useful when:

a malicious tenant has been identified

one domain is abusing external Teams communication


But block lists are inherently reactive.

Attackers can move to:

another tenant

another domain

another compromised organisation


So block-only configuration provides flexibility, but not the strongest reduction in attack surface.

Option 3: Allow Only Approved Domains

For businesses with a predictable group of external partners, this can be considerably stronger.

Teams allows administrators to configure:

Allow only specific external domains

and explicitly approve trusted organisations.

For example:

customer.co.uk

supplier.com

legalpartner.co.uk

All other organisational domains are excluded from normal federation.

This does not guarantee approved partners are safe—legitimate organisations can still be compromised.

But it dramatically reduces unsolicited external contact.

Maintain the allow list properly.

Each domain should have:

business owner

reason for access

approval date

review date

removal process


Do not allow domains forever merely because somebody needed them once.

Option 4: Block External Federation Completely

Some organisations simply do not need external Teams chat.

In that case, block it.

But remember:

External access is not the same as meeting access.

Microsoft notes that meeting participation, guest access and anonymous meeting access have their own controls. Blocking federation alone does not necessarily prevent every external person from joining a permitted meeting.

Review:

external access

guest access

anonymous meetings

meeting lobby settings


separately.

Review Unmanaged Teams Accounts

Teams also supports communication with some unmanaged accounts such as Teams Free users.

Microsoft currently lets administrators decide:

whether organisational users can communicate with unmanaged Teams accounts

whether unmanaged users can initiate conversations with employees.


If the business does not need this:

turn it off.

If employees occasionally need to contact personal/unmanaged Teams users, consider disabling the setting that lets those unmanaged users initiate conversations.

That gives you a useful model:

employee intentionally initiates contact

rather than:

unknown account approaches employee.

Microsoft explicitly supports this behaviour.

Block Malicious Teams Senders Quickly

This is an important 2026 improvement.

Microsoft Defender for Office 365 now allows security teams to block malicious:

external domains

individual email addresses


for Teams through the Tenant Allow/Block List.

Microsoft says those blocks propagate into Teams external-access settings and can provide near-real-time protection against further communication.

That means a Teams phishing response process should include:

identify sender → block sender/domain → search for other recipients → investigate user interaction.

Do not rely only on telling one employee to ignore the message.

Enable Teams User Reporting

Employees should be able to report suspicious Teams content directly.

Microsoft currently supports reporting malicious:

chat messages

channel messages

meeting conversation messages

one-to-one calls


where the relevant Teams/Defender configuration and licensing are available.

Users can choose:

More options > Report this message

and identify it as a security risk.

For supported call reporting, users can report suspicious or scam calls from their Teams call history.

Administrators should verify that:

reporting is enabled in Teams

reporting is configured in Defender

reports go somewhere monitored

somebody owns investigation


Microsoft notes that both Teams and Defender settings can matter for correct reporting behaviour.

Defender for Office 365 Protection Has Improved

During 2026 Microsoft expanded several Teams security features.

These include broader Teams user reporting and post-delivery protection such as Zero-hour Auto Purge for supported Defender for Office 365 plans. Microsoft also added direct sender/domain blocking through Defender.

That makes Teams security increasingly similar to modern email security:

detect → report → investigate → remove → block.

Businesses already paying for Defender for Office 365 should make sure these capabilities are actually enabled and operational.

Guest Access Needs Its Own Governance

Guest users can potentially access much more than federated external users.

Review existing guest identities for:

old suppliers

completed projects

former contractors

duplicated guest accounts

guests who no longer have a business sponsor


Microsoft recommends using Microsoft Entra access reviews to periodically confirm whether guests still require access to applications, groups or Teams.

For guest access, consider:

MFA

Conditional Access

appropriate group membership

access expiry/review

restrictions on sensitive resources


Conditional Access Does Not Fix Federation

This is an important correction to make explicit.

You can apply Conditional Access to guest/B2B identities because they exist in Microsoft Entra.

Ordinary Teams external-access users do not become B2B identities in your tenant, so Conditional Access does not apply to federation in the same way. Microsoft documents this directly.

So:

“We require MFA through Conditional Access”

does not mean:

“Every federated external Teams user is covered by our Conditional Access policy.”

External federation security needs to be handled through the Teams external-access controls.

Review Meetings Separately

Attackers can also use meetings for social engineering.

Review:

anonymous meeting join

lobby bypass

who can present

external attendees

meeting chat

recording

transcription


For sensitive meetings, avoid automatically letting anonymous users bypass the lobby.

A meeting link is not proof of identity either.

Teach Employees One Critical Rule

The most important user-training message is:

IT support should not ask you to approve an unexplained MFA prompt.

A common Teams social-engineering pattern is:

> “We're fixing your account. You'll receive an authentication notification—please approve it.”

 

The correct response is:

1. Do not approve it.


2. Stop the conversation.


3. Contact IT using the normal helpdesk number or portal.


4. Report the Teams message.


5. Preserve the conversation.

 

The same applies to requests to install remote-support software.

An unexpected external Teams message should never be treated as sufficient authorisation for somebody to control a business computer.

If Somebody Already Interacted With the Attacker

Blocking the sender is not enough.

If the employee:

entered a password

approved MFA

installed remote access

shared their screen

provided sensitive information


treat it as a potential compromise.

Investigate:

active sessions

recent sign-ins

authentication methods

suspicious OAuth/application consent

mailbox rules

endpoint activity

installed remote-access software


Potential containment may include:

password reset

session revocation

account restriction

endpoint isolation

removal of unknown MFA methods


Do not close the incident merely because the Teams sender has been blocked.

A Practical Teams Security Configuration

For many SMEs, I would aim for:

External domains
Allow only approved domains where practical.

Unmanaged Teams users
Disable unless there is a genuine business requirement.

Unmanaged users initiating conversations
Disable where possible.

Malicious senders
Use Defender/Tenant Allow/Block List for rapid blocking.

User reporting
Enable and monitor it.

Guests
Require sponsorship and regular access reviews.

Conditional Access
Apply to guest/B2B users and sensitive applications.

Meetings
Review anonymous access, lobby and presenter settings.

Employees
Train them to distrust unexpected Teams support requests.

The exact balance depends on the organisation.

A business speaking with thousands of customers has different requirements from a professional-services firm collaborating with ten known partners.

Quarterly Teams Security Review

Every few months, review:

allowed external domains

blocked domains/senders

unmanaged-account settings

guest accounts

inactive guests

guest Teams membership

anonymous meeting policy

Teams security reports

Defender Teams alerts

external phishing incidents


External collaboration should evolve as business relationships change.

Otherwise temporary access becomes permanent exposure.

The Most Common Teams Security Mistakes

The ones I see as most important are:

assuming a Teams user is verified because they are on Teams

allowing unrestricted external federation without reviewing whether it is needed

confusing external access with guest access

leaving unmanaged-user communication open unnecessarily

having no Teams reporting process

relying solely on email phishing controls

blocking only one sender without checking whether others were contacted

failing to investigate the device after remote-support software was installed


The central principle is:

Teams is a communication channel—not an identity-verification system.

How Hamilton Group Can Help

Hamilton Group can help businesses review and secure Microsoft Teams collaboration.

We can assist with:

Teams external access

approved-domain allow lists

unmanaged Teams account restrictions

guest-access reviews

Microsoft Entra Conditional Access

Defender for Office 365

Teams phishing reporting

Microsoft 365 security

incident investigation

staff security awareness


The goal is not necessarily to stop external collaboration.

It is to make it deliberate, controlled and monitored.

Visit hgmssp.com or call 0330 043 0069 to discuss Microsoft Teams and Microsoft 365 security.