Microsoft Teams Adds Policy to Block External Bots from Meetings
Microsoft is rolling out a new Microsoft Teams meeting security policy that allows administrators to automatically block detected external bots from joining Teams meetings.
The feature expands on a Teams policy introduced in June that improved bot protection by identifying suspected bots, labeling them in the meeting lobby, and requiring the organizer to approve them before they could join.
Under the new policy, identified external meeting bots are automatically denied access. Meeting organizers do not need to manually review or approve each bot before it is blocked.
“With this update, organizations can increase meeting security by configuring Teams policies to automatically block detected external meeting bots from joining meetings,” Microsoft said in a Microsoft 365 Message Center update published Friday.
“This gives administrators more control over how identified bots are handled, reducing risk for their organizations,” the company added.
The new Microsoft Teams bot-blocking policy is being rolled out through targeted release until the end of August. Microsoft expects the feature to become generally available worldwide by late September.
Administrators can find the setting in the Teams admin center under Meeting protection and Bot management. The policy is disabled by default, so organizations must enable and evaluate it before deploying it to users.
After activation, administrators can assign the policy to specific users or groups through their existing Teams meeting policy controls. Identified external meeting bots will then be blocked from joining meetings hosted by users covered by the policy.
The change is designed to prevent third-party bots from entering Teams meetings without the knowledge of organizers and attendees. These bots may provide legitimate services such as note-taking, transcription, and meeting automation, but they can also be abused by malicious applications and threat actors.
Microsoft has warned that cyberattacks targeting Teams are increasing. In April, the company said threat actors were using Teams and cross-tenant chat to impersonate IT or helpdesk employees, persuade victims to grant remote access, and steal sensitive data or gain access to enterprise networks.
Beginning in December, Microsoft will also allow administrators to block external Teams users through the Microsoft Defender portal. The control is intended to help prevent cybercriminal organizations, including ransomware groups, from using Teams-based social engineering attacks against employees.
Microsoft announced additional Teams security controls in June. Planned features include options to block all external bots, create allowlists for approved bots, generate administrative reports, audit bot detection and presence, and apply more granular meeting security requirements.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




