Microsoft Rolls Out Policy to Auto-Block External Bots in Teams Meetings

Microsoft is introducing a new Teams meeting policy that automatically blocks all detected external bots from joining, eliminating the need for organizer approval. The feature builds on an earlier lobby-based policy and is disabled by default, requiring administrators to actively enable and assign it via the Teams admin center. The rollout begins with a targeted release this month and will reach general availability worldwide by late September.

The policy aims to prevent both legitimate third-party bots and malicious applications from participating in meetings unnoticed. This move follows a surge in Teams-based social engineering attacks where threat actors impersonate IT staff to gain remote access and steal data. Administrators can already block external Teams users through the Defender portal, and Microsoft plans to add allow lists, audit logs, and more granular controls in the future. The new policy strengthens meeting security by automatically blocking bots without explicit organizer confirmation, reducing organizational risk. Organizations are encouraged to evaluate and activate the policy based on their security needs.

Read more...

Read More

Got Something To Say?

Your email address will not be published.