Skip to content

Microsoft Teams data sharing & exposure security checks

External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.

On Microsoft Teams, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft Teams connector needs.

Checks (4)

severity: high Public Team fix difficulty: easy #

Change Teams team visibility from Public to Private to restrict unauthorized membership

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team and click Edit
  3. Change Visibility from Public to Private
  4. Confirm the change

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high External Shared Channel fix difficulty: medium #

Remove or restrict external sharing on Teams channels to approved organizations only

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team containing the shared channel
  3. Review the external sharing configuration
  4. Remove external sharing or restrict to approved organizations

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: medium External Messaging Enabled fix difficulty: easy #

Disable or restrict external messaging capabilities in Teams messaging policies

  1. Navigate to Teams Admin Center > Messaging policies
  2. Select the relevant messaging policy
  3. Disable or restrict external messaging capabilities
  4. Save the policy changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Unrestricted External Federation fix difficulty: medium #

Restrict Teams external federation to an approved domain allow list instead of all external domains

  1. Navigate to Teams Admin Center > External access
  2. Review the current external federation settings
  3. Change from Allow all external domains to Allow only specific domains
  4. Add only trusted partner domains to the allow list

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

More Microsoft Teams checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial