8.5.2 (L1) Ensure anonymous users and dial-in callers can't start a meeting

Information

This policy setting controls if an anonymous participant can start a Microsoft Teams meeting without someone in attendance. Anonymous users and dial-in callers must wait in the lobby until the meeting is started by someone in the organization or an external user from a trusted organization.

Anonymous participants are classified as:

- Participants who are not logged in to Teams with a work or school account.
- Participants from non-trusted organizations (as configured in external access).
- Participants from organizations where there is not mutual trust.

Note: This setting only applies when Who can bypass the lobby is set to Everyone If the anonymous users can join a meeting organization-level setting or meeting policy is Off this setting only applies to dial-in callers.

Not allowing anonymous participants to automatically join a meeting reduces the risk of meeting spamming.

Solution

To remediate using the UI:

- Navigate to Microsoft Teams admin center

https://admin.teams.microsoft.com

.
- Click to expand Meetings select Meeting policies
- Click Global (Org-wide default)
- Under meeting join & lobby set Anonymous users and dial-in callers can start a meeting to Off

To remediate using PowerShell:

- Connect to Teams PowerShell using Connect-MicrosoftTeams
- Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -AllowAnonymousUsersToStartMeeting $false

Impact:

Anonymous participants will not be able to start a Microsoft Teams meeting.

See Also

https://workbench.cisecurity.org/benchmarks/17682

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2

Plugin: microsoft_azure

Control ID: 1d75b5bb58f352c7a5561a5d20fcc96c915b79323ad2cbfda3339c6c6e5bde28