Skip to content

Microsoft Teams access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Microsoft Teams, Black Cat runs 12 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft Teams connector needs.

Checks (12)

severity: medium Guest Members in Team fix difficulty: medium #

Review Teams guest members and remove those who no longer require access

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team and review the member list
  3. Identify guest members and verify their access is still required
  4. Remove guests who no longer need access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Team Owners fix difficulty: easy #

Reduce Teams team owners to 2-3 by demoting unnecessary owners to member role

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team and review the owners list
  3. Demote unnecessary owners to member role
  4. Keep only 2-3 team owners for redundancy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Anonymous Meeting Join Enabled fix difficulty: easy #

Disable anonymous meeting join in Teams meeting policies to prevent unauthorized attendees

  1. Navigate to Teams Admin Center > Meetings > Meeting policies
  2. Select the relevant meeting policy
  3. Set Let anonymous people join a meeting to Off
  4. Save the policy changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Lobby Bypass for Everyone fix difficulty: easy #

Restrict Teams meeting lobby bypass to organization members or organizer only

  1. Navigate to Teams Admin Center > Meetings > Meeting policies
  2. Select the relevant meeting policy
  3. Change Who can bypass the lobby to a more restrictive setting
  4. Consider setting to People in my org or Organizer only

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Guest Access Overly Permissive fix difficulty: easy #

Restrict Teams guest access permissions by disabling calling, screen sharing, and video for guests

  1. Navigate to Teams Admin Center > Guest access
  2. Review the current guest access permissions
  3. Restrict guest calling, meeting, and messaging capabilities
  4. Disable screen sharing and video for guests if not required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Members Can Delete Channels fix difficulty: easy #

Restrict channel deletion to team owners to prevent accidental or malicious data loss

  1. Navigate to Teams Admin Center > Teams > Manage Teams
  2. Select the team and open its settings
  3. Under Member permissions, disable "Allow members to delete channels"
  4. Save the team settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Members Can Install Apps fix difficulty: easy #

Restrict app installation to team owners to maintain control over third-party integrations

  1. Navigate to Teams Admin Center > Teams > Manage Teams
  2. Select the team and open its settings
  3. Under Member permissions, disable "Allow members to add and remove apps"
  4. Save the team settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Guests Can Delete Channels fix difficulty: easy #

Disable guest channel deletion to prevent external users from removing team channels

  1. Navigate to Teams Admin Center > Teams > Manage Teams
  2. Select the team and open its settings
  3. Under Guest permissions, disable "Allow guests to delete channels"
  4. Save the team settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Guests Can Create and Update Channels fix difficulty: easy #

Disable guest channel creation and updates to limit external user impact on team structure

  1. Navigate to Teams Admin Center > Teams > Manage Teams
  2. Select the team and open its settings
  3. Under Guest permissions, disable "Allow guests to create and update channels"
  4. Save the team settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Single Team Owner fix difficulty: easy #

Add at least one additional owner to the team to ensure administrative redundancy

  1. Navigate to Teams Admin Center > Teams > Manage Teams
  2. Select the team with only one owner
  3. Click on Members and add at least one additional trusted member as an owner
  4. Verify the new owner can manage team settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Meeting Auto-Admits Everyone fix difficulty: easy #

Change the auto-admit setting to require lobby screening for external and anonymous participants

  1. Navigate to Teams Admin Center > Meetings > Meeting Policies
  2. Select the affected meeting policy
  3. Under "Participants and guests", change "Automatically admit people" from "Everyone" to "People in my organization" or "People in my organization and trusted organizations"
  4. Save the meeting policy

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium External Consumer Teams Access fix difficulty: easy #

Disable communication with personal Microsoft Teams consumer accounts to limit external exposure

  1. Navigate to Teams Admin Center > External Access
  2. Locate the "Teams accounts not managed by an organization" setting
  3. Toggle it to "Off" to block consumer account communication
  4. Save the external access settings

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Microsoft Teams checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial