8.2.3 Ensure external Teams users cannot initiate conversations

Information

This setting prevents external users who are not managed by an organization from initiating contact with users in the protected organization.

The recommended state is to uncheck People in my org can chat and have meetings with external users who have unmanaged Microsoft accounts.

Note: Disabling this setting is used as an additional stop gap for the parent setting which disables communication with unmanaged Teams users entirely. If an organization chooses to have an exception to Ensure communication with unmanaged Teams users is disabled they can do so while also disabling the ability for the same group of users to initiate contact. Disabling communication entirely will also disable the ability for unmanaged users to initiate contact.

Allowing users to communicate with unmanaged Teams users presents a potential security threat as little effort is required by threat actors to gain access to a trial or free Microsoft Teams account.

Real-world attacks and exploits delivered via Teams over external access channels include:

- DarkGate malware
- Social engineering / Phishing attacks by "Midnight Blizzard"
- GIFShell
- Username enumeration

Solution

Note: Configuring this setting at the organization level in Organization settings to Off is also a compliant remediation for this control.

To remediate using the UI:

- Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com/.
- Expand External collaboration and select External access.
- Open the Policies tab.
- Click on the Global (Org-wide default) settings policy.
- Locate the parent setting People in my org can chat and have meetings with external users who have unmanaged Microsoft accounts.
- Uncheck People in my org can join external meetings and receive new chats from users who have unmanaged Microsoft accounts.
- Click Save.

To remediate using PowerShell:

- Connect to Teams PowerShell using Connect-MicrosoftTeams
- Run the following command:

Set-CsExternalAccessPolicy -Identity Global -EnableTeamsConsumerInbound $false

Impact:

Unmanaged Teams users (those using personal Microsoft accounts or free Teams) will be unable to initiate new chats or meeting invitations with members of the organization. Organization members may still be able to join externally-initiated meetings depending on the configuration of the parent setting.

Organizations that need to allow inbound contact from specific external users can assign a custom external access policy to those users that has EnableTeamsConsumerInbound enabled.

Note: Chats and meetings with external unmanaged Teams users isn't available in GCC, GCC High, or DOD deployments, or in private cloud environments.

See Also

https://workbench.cisecurity.org/benchmarks/24620

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|CM-6, 800-53|CM-7, 800-53|MP-2

Plugin: microsoft_azure

Control ID: 979231ca0548d70b04e8b8400df950879d65e2c8dd4ff4df90cbaba075e85acf