Data Management - Ensure External Domains Are Not Allowed in Skype or Teams

 







Summary

The default for Teams external communications is now set to 'People in my organization can communicate with Teams users whose accounts aren't managed by an organization' since December 2021, which also means that the users can communicate with personal Microsoft accounts (e.g. Hotmail, Outlook, etc.) that may lead to data loss/phishing/social engineering risks.

Note: Skype for business is deprecated as of July 31, 2021 although these settings may still be valid for a period of time.  

Reason

Users should not be allowed to communicate with Skype or Teams users outside an organization. This may also lead to potential security threats as all those external users can easily interact with an organization's users over Skype for Business or Teams making the users more prone to data loss/phishing/social engineering attacks via Teams.

What If?

This change's impact highly depends on current practices in the tenant. If users do not regularly communicate with external parties via Skype or Teams channels, then, the impact is minimal, however, if they do communicate, then, potentially significant impacts could occur and users should be contacted, or an alternate mechanism should be identified to continue this communication before disabling external access to Teams and Skype.

How to?

To prohibit user communication with external Teams organizations, use the Microsoft 365 Admin Center:
  1. Select Admin centers and Teams.
  2. Under Users pick External access.
  3. Under Teams and Skype for Business users in external organizations select Block all external domains. Note- If organizational policy allows select any allowed external domains.
  4. Under Teams accounts not managed by an organization move the slider to Off.
  5. Now, under Skype users move the slider to Off.
  6. Finally, Save.

Monitor:

To review user communication with external Teams organizations, use the Microsoft 365 Admin Center:
  1. Select Admin centers and Teams.
  2. Under Users pick External access.
  3. Under Teams and Skype for Business users in external organizations select Block all external domains. Note- If organizational policy allows select any allowed external domains.
  4. Under Teams accounts not managed by an organization ensure the slider is set to Off.
  5. Now, under Skype users ensure the slider is set to Off.











































































Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements