Microsoft Teams governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On Microsoft Teams, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft Teams connector needs.
Checks (5)
severity: low Team Without Description fix difficulty: easy #
Add a meaningful description to Teams teams that lack one to improve governance visibility
- Navigate to Teams Admin Center > Teams > Manage teams
- Select the team and click Edit
- Add a meaningful description explaining the team's purpose
- Save the changes
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Large Team Without Moderation fix difficulty: medium #
Enable channel moderation and assign moderators to large Teams teams without governance controls
- Navigate to Teams Admin Center > Teams > Manage teams
- Select the large team and go to Settings
- Enable channel moderation for general and key channels
- Assign moderators to manage content and membership
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: medium Channel Without Moderation fix difficulty: easy #
Enable channel moderation and configure posting restrictions for unmoderated Teams channels
- Navigate to Teams Admin Center > Teams > Manage teams
- Select the team and navigate to the channel settings
- Enable channel moderation
- Configure who can post new messages and reply
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Meeting Recording Disabled fix difficulty: easy #
Enable cloud recording in Teams meeting policies and configure retention settings
- Navigate to Teams Admin Center > Meetings > Meeting policies
- Select the relevant meeting policy
- Enable Cloud recording for meetings
- Configure recording storage and retention settings
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b
severity: low Message Edit Delete Unrestricted fix difficulty: easy #
Restrict message editing and deletion in Teams messaging policies to preserve audit trails
- Navigate to Teams Admin Center > Messaging policies
- Select the relevant messaging policy
- Configure message editing and deletion restrictions
- Consider disabling Delete sent messages or Edit sent messages
Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4