Skip to main content

Teams Is a Phishing Channel Now — External Access Settings to Lock Down

Media Teams Is a Phishing Channel Now — External Access Settings to Lock Down

 

Email is no longer the only place where phishing attacks begin.

Cybercriminals increasingly use Microsoft Teams to contact employees directly, impersonate suppliers, send fake technical-support messages and persuade users to open malicious links or approve fraudulent sign-in requests.

The attack works because Teams feels more trusted and immediate than email. An unexpected message in a collaboration app can appear to come from a colleague, customer, Microsoft support agent or external business partner. Employees may respond quickly because they assume anyone who can contact them through Teams has already passed some form of organisational security check.

That assumption is dangerous.

Microsoft Teams external access can allow authenticated users from other organisations—and, depending on configuration, unmanaged Teams accounts—to find and contact people in your business. Microsoft explicitly warns that although external access is useful for collaboration, attackers can also use it to contact users directly when they know an employee’s email address. 

This guide explains how Teams phishing works, the difference between external and guest access, and which Microsoft Teams settings businesses should review to reduce unsolicited external contact.

What Is Teams Phishing?

Teams phishing is the use of Microsoft Teams chats, meetings or calls to deceive users into taking an unsafe action.

An attacker may pretend to be:

  • A member of your IT department
  • Microsoft technical support
  • A senior manager
  • A customer or supplier
  • A recruitment agency
  • A cyber-insurance provider
  • A security researcher
  • A member of another company’s finance team

The attacker may ask the employee to:

  • Open a malicious link
  • Download remote-support software
  • Share their screen
  • Approve an MFA notification
  • Enter a device code
  • Scan a QR code
  • Open a fake invoice
  • Provide payment information
  • Move the conversation to WhatsApp or another platform
  • Reveal internal company information

The message does not need to contain malware. Social engineering alone may be enough to compromise the employee’s account or device.

Why Teams Has Become an Attractive Phishing Channel

Email users have learned to be cautious around unfamiliar senders, warning banners and suspicious attachments.

Teams messages often receive less scrutiny.

A Teams chat feels:

  • Immediate
  • Personal
  • Work-related
  • Connected to a known business platform
  • Less likely to be filtered
  • More urgent than an ordinary email

Attackers also benefit from the conversational format. Instead of sending one obvious phishing email, they can build trust gradually.

A typical conversation may begin with:

Hello, I am contacting you from your IT support provider. We have detected a problem with your Microsoft 365 account.

The attacker may then ask several harmless-looking questions before introducing the malicious link or remote-support request.

External Does Not Mean Trusted

Microsoft Teams now uses visual trust indicators to help users understand whether another person is internal, external, a guest or anonymous. These labels are intended to reduce accidental oversharing by making the person’s relationship to the organisation more visible. 

However, users may overlook these indicators.

An external user may still have:

  • A convincing display name
  • A realistic profile photograph
  • A company-sounding organisation name
  • A professional email address
  • A Teams account managed by another tenant

The external label tells you the person is outside your organisation. It does not prove that they are legitimate, authorised or trustworthy.

External Access vs. Guest Access

These two Microsoft Teams features are often confused.

They are different and should be reviewed separately.

External Access

External access—also called federation—allows your users to find, call and chat with authenticated Teams users outside your organisation.

The external person remains in their own organisation.

They do not normally become a member of your tenant or gain access to your teams, channels and files simply because external chat is allowed.

Microsoft allows administrators to control which external organisations can communicate with their users through Teams external-access settings. 

Guest Access

Guest access adds an external person to your organisation as a guest identity.

A guest may be invited into a team and, depending on permissions, may be able to:

  • Participate in team conversations
  • Attend meetings
  • Access channels
  • Collaborate on files
  • Use certain Teams applications

Microsoft notes that guests can receive many of the same Teams capabilities as internal members, making guest governance particularly important. 

Restricting external access does not automatically remove existing guest users, and restricting guest access does not necessarily stop federated external chats.

Both areas require review.

The Most Important External Access Question

Ask:

Does every user in our organisation genuinely need to receive direct Teams messages from any external Microsoft 365 organisation?

For many businesses, the answer is no.

Sales, recruitment and account-management staff may need broad external communication. Other employees may need to communicate only with a known group of customers, suppliers or partners.

Allowing every external domain increases the number of identities capable of initiating contact with your employees.

A more restrictive model is usually safer.

Option 1: Allow All External Domains

This is the most open configuration.

Users can communicate with Teams users in any external Microsoft 365 organisation unless a particular domain has been blocked.

Advantages include:

  • Minimal administration
  • Easy customer and supplier collaboration
  • No need to maintain an allow list

Security disadvantages include:

  • A large external contact surface
  • Attackers can use newly created or compromised tenants
  • Blocking known malicious domains becomes reactive
  • Employees may receive unsolicited messages from unfamiliar organisations

This setting may be appropriate for certain highly collaborative organisations, but it should not remain enabled merely because it is convenient.

Option 2: Block Selected Domains

This model allows external communication generally but blocks known unwanted domains.

In the Teams admin centre, administrators can select Block only specific external domains and maintain a list of domains that should not communicate with users. 

This can help during an active incident involving a known malicious or compromised organisation.

However, it is weak as a primary security model because attackers can:

  • Register another domain
  • Use another Microsoft 365 tenant
  • Compromise a legitimate supplier
  • Use an unmanaged personal Teams account

A block list is always chasing known threats.

Option 3: Allow Only Approved External Domains

For many security-conscious businesses, this is the better approach.

Microsoft Teams allows administrators to select Allow only specific external domains and then add trusted partner domains to the approved list. 

For example, the business may allow:

important-customer.com

legal-partner.co.uk

approved-supplier.net

All other external organisational domains are blocked from federated Teams communication.

This significantly reduces unsolicited external contact.

The allow list should have:

  • A named owner
  • A business justification for every domain
  • An approval process
  • A regular review date
  • A removal process when the relationship ends

Do not approve an entire domain simply because one employee received a legitimate message from it.

Confirm that the organisation and domain are genuine.

Option 4: Block All External Domains

Organisations that do not need external Teams chat can block all external organisational domains.

This does not necessarily prevent outside participants from joining meetings through other permitted methods. Microsoft notes that users from blocked domains may still be able to join meetings anonymously when anonymous meeting access is enabled. 

That distinction is important:

  • External chat
  • Guest access
  • Meeting access
  • Anonymous participation

are separate controls.

Blocking external federation does not automatically close every external collaboration route.

Review Communication With Unmanaged Teams Accounts

Microsoft Teams can support communication with accounts that are not managed by a Microsoft 365 organisation, including some personal or unmanaged Teams accounts.

This creates another route through which unknown people may contact employees.

Microsoft provides settings controlling whether:

  • People in your organisation can communicate with unmanaged Teams accounts
  • Unmanaged external users can initiate conversations with people in your organisation

If your business does not require this feature, disable it.

Microsoft’s guidance states that disallowing chat with unmanaged users prevents employees from starting chats with non-Microsoft 365 users through that feature, although federation and other external collaboration features remain separate. 

This setting is particularly important because an attacker may not need to operate a full business tenant to contact users when unmanaged-account communication is permitted.

Stop Unmanaged Users Starting Conversations

There may be a legitimate reason for employees to contact a personal Teams user, but that does not necessarily mean the personal user should be able to initiate contact with employees.

Where available in your Teams settings, turn off the option that allows unmanaged external Teams users to start conversations with people in your organisation.

This creates a more controlled model:

  • Your employee deliberately starts the conversation.
  • Unknown personal accounts cannot approach employees directly.

It does not eliminate every threat, but it reduces unsolicited contact.

Allow Your Security Team to Block Teams Senders

Microsoft Defender can support blocking Teams domains and individual external addresses through the Tenant Allow/Block List where the relevant settings and licensing are available.

Microsoft’s documentation indicates that Teams external-access settings must permit the appropriate external-domain model before the security team can manage blocks through Defender. 

This is useful during active incidents because the security team may be able to block:

  • A malicious external domain
  • A specific external sender
  • An address involved in repeated phishing attempts

The process should be documented so administrators know where to block a sender and how quickly that change takes effect.

Use Individual Sender Blocking Carefully

Blocking one known malicious account may be appropriate when:

  • A single identity is sending phishing messages
  • The wider domain is legitimate
  • Blocking the entire customer or supplier domain would disrupt business

Microsoft Teams supports blocking specific external users in some external-access configurations, and Microsoft Defender may also provide sender-management options. 

However, individual blocking is reactive.

If several malicious accounts appear from the same unfamiliar domain, investigate whether the entire domain should be blocked.

Configure User Reporting in Teams

Employees need a quick way to report suspicious Teams content.

Microsoft supports user reporting for Teams messages in:

  • Chats
  • Channels
  • Meeting conversations

Users can also report suspicious or scam calls from their Teams call history. Administrators can then review the reported items through Microsoft Defender where supported. 

Review your user-reported settings and confirm:

  • Reporting is enabled.
  • Employees know where the option is.
  • Reports reach a monitored security queue.
  • Someone owns the investigation process.
  • Response times are defined.
  • Malicious senders can be blocked quickly.

Training users to take screenshots and email them to IT is slower and may omit useful technical evidence.

Microsoft Defender for Office 365 and Teams

Microsoft Defender for Office 365 now includes security capabilities for Teams, depending on the organisation’s licence and configuration.

Microsoft documents capabilities that can help investigate and remediate malicious Teams activity, including removing users from chats during an attack. 

Confirm whether your current Microsoft 365 plan includes the Teams protection features you expect.

Do not assume email protection automatically provides identical coverage for Teams messages, files, calls and chat participants.

Review Guest Access Separately

External access controls direct chat and calling between organisations.

Guest access controls people who have been invited into your tenant.

Audit existing guests for:

  • Former suppliers
  • Completed projects
  • Expired contractors
  • Previous customers
  • Duplicate guest identities
  • Guests with no recent sign-in activity
  • Guests assigned to sensitive teams
  • Guests with access to confidential SharePoint sites

Every guest should have:

  • A business sponsor
  • A defined reason for access
  • Appropriate group and team membership
  • A review or expiry date
  • Suitable Conditional Access protection

Remove guest access promptly when the business relationship ends.

Require Strong Authentication for Guests

Conditional Access can require an appropriate MFA authentication strength for external and guest users accessing your resources.

Microsoft specifically supports policies requiring phishing-resistant authentication for selected external users and sensitive applications where the configuration and licensing support it. 

Possible controls include:

  • Require MFA for all guests
  • Require stronger authentication for sensitive applications
  • Require a compliant device where practical
  • Restrict sessions from unmanaged devices
  • Block access from high-risk locations
  • Limit access to selected applications

The organisation should decide when to trust an external user’s home-tenant MFA and when to require stronger controls.

Lock Down Meeting Access

Teams phishing and social engineering can also occur in meetings.

Review settings controlling:

  • Anonymous meeting join
  • Who can bypass the lobby
  • Who can present
  • Meeting chat
  • Dial-in participants
  • External attendees
  • Guest access
  • Recording and transcription
  • External application use

Microsoft distinguishes among several types of external meeting participants and provides different controls for anonymous, guest and external attendees. 

For sensitive meetings:

  • Require invited users to authenticate.
  • Do not allow everyone to bypass the lobby.
  • Restrict presenting rights.
  • Review unfamiliar attendees before admission.
  • Disable anonymous access where it is not needed.
  • Avoid sharing confidential material until identities are confirmed.

Explain Trust Indicators to Employees

Microsoft Teams displays labels and indicators for people outside the organisation.

Train staff to recognise:

  • External users
  • Guest users
  • Anonymous participants
  • Unverified or unfamiliar contacts

Microsoft created these trust indicators specifically to help users understand the identity relationship and reduce accidental oversharing. 

Users should pause whenever an external contact:

  • Claims to be internal IT
  • Requests urgent technical action
  • Asks for MFA approval
  • Requests screen sharing
  • Asks the user to install remote-access software
  • Sends an unexpected link or QR code
  • Requests sensitive files
  • Moves the conversation away from official channels

Teach Users That IT Should Not Ask for MFA Approval

A common Teams attack involves an external person pretending to be technical support.

The attacker may say:

We are repairing your account. You will receive an authentication prompt. Please approve it.

Employees should understand that legitimate IT staff should not ask them to approve an unexplained sign-in request.

The correct response is:

  1. Stop the conversation.
  2. Do not approve the prompt.
  3. Contact IT through the known help-desk number or portal.
  4. Report the Teams message.
  5. Preserve the conversation for investigation.

Remote-Support Software Is a Major Warning Sign

Attackers may use Teams to persuade employees to install legitimate tools such as remote-support or screen-sharing software.

The software itself may not be malicious, but it can give the attacker control over the computer.

Employees should not install remote-access tools unless:

  • The request was initiated through the official support process.
  • The technician’s identity is verified.
  • The software is company approved.
  • The employee understands what access is being granted.

External Teams messages should never be accepted as sufficient authorisation.

Do Not Let External Users Share Sensitive Files Casually

A Teams conversation may move quickly from chat to file exchange.

Users should not send an external contact:

  • Passwords
  • Recovery codes
  • Security keys
  • Customer lists
  • Payroll data
  • Confidential contracts
  • Internal network details
  • Screenshots of administrative portals
  • Sign-in logs containing sensitive data

External labels do not prevent oversharing.

Use approved guest collaboration and controlled SharePoint permissions when files genuinely need to be shared.

Investigating a Suspicious Teams Message

When an employee reports a suspicious message:

Preserve the Evidence

Record:

  • Sender display name
  • Sender address or identity
  • Claimed organisation
  • Message content
  • Links
  • Attachments
  • Time
  • Affected user
  • Chat or meeting context

Confirm Whether Anyone Interacted

Ask whether the user:

  • Opened a link
  • Downloaded a file
  • Scanned a QR code
  • Approved MFA
  • Entered a device code
  • Shared their screen
  • Installed software
  • Provided credentials
  • Sent files

Review Microsoft Entra Sign-In Logs

Look for:

  • Unexpected sign-ins
  • Unfamiliar devices
  • Unusual countries or IP addresses
  • Device code flow
  • New MFA registrations
  • Risk detections
  • Suspicious applications

Review Endpoint Security

Check for:

  • Remote-access tools
  • Browser downloads
  • Malware alerts
  • New processes
  • Persistence
  • Credential theft
  • Unapproved software

Block the Sender or Domain

Use Teams admin or Defender controls appropriate to your environment.

Search for Other Recipients

Determine whether the same external identity contacted additional employees.

Remove Malicious Content

Use Microsoft Defender remediation capabilities where available.

What to Do When the User Approved Something

When the employee approved MFA, entered credentials or installed remote-access software, treat the event as a potential account compromise.

Actions may include:

  • Disable or restrict the account
  • Revoke active sessions
  • Reset the password
  • Review authentication methods
  • Remove unfamiliar MFA registrations
  • Revoke suspicious application consent
  • Isolate the device
  • Review mailbox rules
  • Review files and messages accessed
  • Preserve evidence
  • Notify affected contacts

Do not simply block the Teams sender and close the incident.

The attacker may already have established access through another route.

Recommended External Access Configuration

A practical security-focused configuration may include:

  • Allow only approved external organisational domains.
  • Block communication with unmanaged Teams accounts unless required.
  • Prevent unmanaged external users from initiating conversations.
  • Enable Defender-based sender and domain blocking where licensed.
  • Enable user reporting for Teams messages and calls.
  • Maintain a documented partner-domain approval process.
  • Review approved domains quarterly.
  • Review guest identities regularly.
  • Apply Conditional Access to guests and sensitive resources.
  • Restrict anonymous meeting participation where unnecessary.
  • Train users to recognise external trust indicators.

The exact configuration depends on how your organisation collaborates.

A sales business communicating with hundreds of customers may need a different model from a legal firm working with five established partners.

External Domain Allow-List Process

When a department requests a new external domain, collect:

  • External organisation name
  • Domain
  • Business sponsor
  • Reason for Teams access
  • Expected users
  • Start date
  • Review date
  • End date where applicable
  • Data to be shared
  • Risk owner

Verify the domain independently.

Do not rely solely on information in the external Teams message.

Quarterly Teams Security Review

Every quarter, review:

  • Allowed external domains
  • Blocked domains and users
  • Unmanaged-user communication
  • Guest accounts
  • Guest team membership
  • Anonymous meeting settings
  • User-reported Teams messages
  • External phishing incidents
  • Teams-related Defender alerts
  • Conditional Access for external users
  • Teams applications available to guests
  • Staff awareness and reporting rates

Remove settings, domains and guest identities that are no longer required.

Common Teams Security Mistakes

Assuming Teams Contacts Are Verified

A user being on Teams does not mean they are trusted.

Allowing Every External Domain

This gives attackers more opportunities to contact employees directly.

Blocking Email Phishing but Ignoring Chat

Attackers choose the channel with weaker controls.

Confusing External and Guest Access

Changing one does not necessarily secure the other.

Allowing Unmanaged Accounts Without a Business Need

Personal accounts increase unsolicited-contact risk.

Leaving Anonymous Meetings Wide Open

Unknown participants may join, observe or socially engineer attendees.

Having No Reporting Process

Users delete suspicious messages without security teams seeing the campaign.

Blocking Only the Sender

The attacker may use another identity from the same tenant or domain.

Failing to Investigate the Endpoint

The user may already have installed remote-support software.

Trusting a Familiar Display Name

Names and profile photographs can be copied.

Teams External Access Checklist

External Organisations

  • Decide whether all domains should be allowed.
  • Prefer an allow list when practical.
  • Document approved domains.
  • Review domains quarterly.
  • Block malicious domains quickly.

Unmanaged Accounts

  • Disable unmanaged communication when unnecessary.
  • Prevent unmanaged users initiating contact.
  • Review any exceptions.
  • Train affected users.

Guest Access

  • Assign every guest a sponsor.
  • Review inactive guests.
  • Remove completed contractors.
  • Restrict sensitive teams.
  • Apply MFA and Conditional Access.

Meetings

  • Review anonymous access.
  • Configure lobby bypass.
  • Restrict presenters.
  • Verify external attendees.
  • Protect meeting chat and recordings.

Detection and Response

  • Enable Teams user reporting.
  • Monitor Defender alerts.
  • Document sender-blocking procedures.
  • Review sign-in logs.
  • Investigate user interaction.
  • Revoke sessions after compromise.

Final Thoughts

Microsoft Teams is now an important business communication platform—and that makes it an attractive phishing channel.

Attackers know employees may trust a Teams message more readily than an email. External access, unmanaged accounts, guest identities and open meeting settings can all increase the number of people capable of contacting your workforce.

The solution is not necessarily to block every form of external collaboration.

It is to make external communication deliberate.

Allow only the domains your business genuinely needs where practical. Disable unmanaged-user communication when it serves no purpose. Prevent unknown users from initiating conversations. Review guests, tighten meeting access, enable user reporting and make sure your security team can block malicious senders quickly.

Most importantly, train employees to treat unexpected external Teams messages with the same caution they would apply to suspicious email.

A Teams chat is a communication channel—not proof of identity.

Worried About Phishing Through Microsoft Teams?

Hamilton Group can help you review and secure Microsoft Teams external collaboration.

Our experts can help you:

  • Audit external-access settings
  • Create an approved-domain allow list
  • Restrict unmanaged Teams accounts
  • Review guest identities and team access
  • Secure external meetings
  • Configure user reporting
  • Review Microsoft Defender protections for Teams
  • Configure Conditional Access for external users
  • Investigate suspicious Teams messages
  • Build a Teams phishing response process
  • Train employees to recognise collaboration-platform attacks

Visit hgmssp.com, call Hamilton Group on 0330 043 0069, or book a meeting with one of our experts to strengthen your Microsoft Teams security.