Microsoft Teams
8 checks · 2 sub-categories
Teams is open to the outside world by default. External federation, Skype consumer contact and guest access are all switched on in a new tenant, which means an attacker can start a chat with your staff from a lookalike domain without ever sending an email.
External and guest access
External (federated) communication defaults
Whether anyone on any Teams tenant in the world can message your staff, or whether federation is limited to an allow-list of partners.
Skype consumer communication disabled
Contact from personal Skype accounts serves no business purpose in almost every SMB and is a clean social-engineering channel.
Guest access settings
Reports whether guests can be added to Teams, and what they can do once inside — chat, screen share, delete messages.
- CIS 3.3
Guest lifecycle and access reviews
Identifies guests still holding access to Teams and channels long after the project ended.
- Privacy Act — access control
Meetings and content
Meeting lobby and anonymous join settings
Controls whether anonymous participants can join directly or bypass the lobby, and who can present.
Recording and transcription policy
Who can record, where recordings are stored and how long they're kept — relevant to both privacy obligations and eDiscovery.
- Privacy Act — collection and retention
Teams file sharing inherits SharePoint controls
Every file in a Team lives in SharePoint, so we cross-check that Teams isn't creating a sharing gap around your SharePoint policy.
Third-party app and bot permissions in Teams
Which apps staff can install into Teams themselves, and what data those apps can reach.
- Essential Eight — Application control
Want to know where you actually stand?
Every one of these checks is run as part of a single point-in-time audit, delivered as a plain-English, risk-prioritised report.