8.2.2 Ensure communication with unmanaged Teams users is disabled

Information

This policy setting controls chats and meetings initiated through the external access channel with unmanaged Teams users (those not managed by an organization, such as Microsoft Teams (free)). This does not govern anonymous meeting join via shared link, which is controlled separately.

The recommended state is: People in my org can chat and have meetings with external users who have unmanaged Microsoft accounts set to Off.

Allowing users to communicate with unmanaged Teams users presents a potential security threat as little effort is required by threat actors to gain access to a trial or free Microsoft Teams account.

Real-world attacks and exploits delivered via Teams over external access channels include:

- DarkGate malware
- Social engineering / Phishing attacks by "Midnight Blizzard"
- GIFShell
- Username enumeration

Solution

Note: Configuring this setting at the organization level in Organization settings to Off is also a compliant remediation for this control.

To remediate using the UI:

- Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com/.
- Expand External collaboration and select External access.
- Open the Policies tab.
- Click on the Global (Org-wide default) settings policy.
- Set People in my org can chat and have meetings with external users who have unmanaged Microsoft accounts to Off.
- Click Save.

To remediate using PowerShell:

- Connect to Teams PowerShell using Connect-MicrosoftTeams
- Run the following command:

Set-CsExternalAccessPolicy -Identity Global -EnableTeamsConsumerAccess $false

Impact:

Users will be unable to communicate with Teams users who are not managed by an organization.

Organizations may choose to create additional policies for specific groups needing to communicate with unmanaged external users.

Note: The settings that govern chats and meetings with external unmanaged Teams users aren't available in GCC, GCC High, or DOD deployments, or in private cloud environments.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-6, 800-53|CM-7, 800-53|MP-2

Plugin: microsoft_azure

Control ID: e64b384190f22d0885967c218c75210597a454616990f517e0c747e443161750