3.3 Ensure external domains are not allowed in Skype or Teams

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

As of December 2021 the default for Teams external communication is set to 'People in my organization can communicate with Teams users whose accounts aren't managed by an organization.' This means that users can communicate with personal Microsoft accounts (e.g. Hotmail, Outlook etc.), which presents data loss / phishing / social engineering risks.

NOTE: Skype for business is deprecated as of July 31, 2021 although these settings may still be valid for a period of time. See the link in the reference for more information.

Rationale:

You should not allow your users to communicate with Skype or Teams users outside your organization. While there are legitimate, productivity-improving scenarios for this, it also represents a potential security threat because those external users will be able to interact with your users over Skype for Business or Teams. Users are prone to data loss / phishing / social engineering attacks via Teams.

Impact:

Impact associated with this change is highly dependent upon current practices in the tenant. If users do not regularly communicate with external parties using Skype or Teams channels, then minimal impact is likely. However, if users do regularly utilize Teams and Skype for client communication, potentially significant impacts could occur, and users should be contacts, and if necessary, alternate mechanisms to continue this communication should be identified prior to disabling external access to Teams and Skype.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To prohibit user communication with external Teams organizations, use the Microsoft 365 Admin Center:

Select Admin Centers and Teams.

Under Users select External access

Under Teams and Skype for Business users in external organizations Select Block all external domains

Note: If organizational policy allows select any allowed external domains.

Under Teams accounts not managed by an organization move the slider to Off.

Under Skype users move the slider is to Off.

Click Save.

Default Value:

On

See Also

https://workbench.cisecurity.org/files/4073