Microsoft Teams data sharing & exposure security checks
External sharing, public links, guest access, retention and data-protection settings that quietly push company data outside the tenant.
On Microsoft Teams, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft Teams connector needs.
Checks (4)
severity: high Public Team fix difficulty: easy #
Change Teams team visibility from Public to Private to restrict unauthorized membership
- Navigate to Teams Admin Center > Teams > Manage teams
- Select the team and click Edit
- Change Visibility from Public to Private
- Confirm the change
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high External Shared Channel fix difficulty: medium #
Remove or restrict external sharing on Teams channels to approved organizations only
- Navigate to Teams Admin Center > Teams > Manage teams
- Select the team containing the shared channel
- Review the external sharing configuration
- Remove external sharing or restrict to approved organizations
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: medium External Messaging Enabled fix difficulty: easy #
Disable or restrict external messaging capabilities in Teams messaging policies
- Navigate to Teams Admin Center > Messaging policies
- Select the relevant messaging policy
- Disable or restrict external messaging capabilities
- Save the policy changes
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11
severity: high Unrestricted External Federation fix difficulty: medium #
Restrict Teams external federation to an approved domain allow list instead of all external domains
- Navigate to Teams Admin Center > External access
- Review the current external federation settings
- Change from Allow all external domains to Allow only specific domains
- Add only trusted partner domains to the allow list
Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.1 NIST CSF 2.0 PR.DS-01 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11