Why this matters
Teams holds chats, files and meetings that often include sensitive business information. Default settings can allow anyone outside your organisation to message staff or join meetings. Tightening a few admin settings reduces phishing and data leaks through Teams.
What you'll need
- Teams administrator or Global administrator access
- A list of partner organisations you collaborate with
Step-by-step instructions
Step 1
Open the Teams admin center
Go to admin.teams.microsoft.com and sign in with an admin account.
Step 2
Restrict external access
Go to Users, then External access. Allow only the domains you work with rather than all external organisations, and block communication with unmanaged Teams accounts unless needed.
Step 3
Review guest access
Under Users, Guest access, decide whether guests are allowed. If they are, limit what they can do in meetings and chats.
Step 4
Use the meeting lobby
Under Meetings, Meeting policies, set "Who can bypass the lobby" to people in your organisation, so external attendees wait to be admitted.
Step 5
Control who can create teams
Limit team creation to a group of approved staff to avoid sprawl and orphaned teams containing data.
Step 6
Review apps
Under Teams apps, Manage apps, block third-party apps you have not approved.
Summary
Allow-listing external domains, using the lobby and controlling guests keep Teams useful without opening a back door into your business.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.