ReferenceCheck catalog
Microsoft Teams
All 17 Microsoft Teams checks - what each one checks, why, and the access used to evaluate it.
17 checks. Column "Access used" lists the application permissions and collected data sources this check's evaluation reads; "None" means Watchtower reads no tenant data for it.
| Check | Severity | What it checks | Why it matters | Access used |
|---|---|---|---|---|
App permission policies are configuredwt.teams.app-permission-policies-configured | MEDIUM | Checks that Teams app permission policies are configured to restrict which Microsoft, third-party, and custom apps users can install, rather than allowing all apps by default. | Unrestricted Teams app permissions allow users to install third-party and custom apps that can access meeting content, chat messages, and files in Teams channels. Malicious or compromised apps represent a supply-chain threat for data exfiltration and credential theft within the collaboration platform. | None - no tenant data read (not automatable via API, reported as a manual/indeterminate result) |
Users can't send emails to a channel email addresswt.teams.channel-email-disabled | MEDIUM | Checks that the ability to send email directly to a Teams channel email address is disabled, preventing external parties from injecting content into channels via email. | Channel email addresses allow anyone who knows the address to post messages and attachments directly into Teams channels, bypassing Teams access controls and message filtering. Attackers can use this to deliver phishing content or malicious attachments to channel members who may trust content appearing in Teams. | Organization.Read.All - via teamsClientConfiguration |
External domains are restricted in the Teams admin centerwt.teams.external-access-restricted | MEDIUM | Checks that Teams external access is not configured to allow communication with all external Teams domains, and that only approved domains are permitted. | Unrestricted Teams external access allows users to communicate with any Teams user in any external organisation, including adversarial or compromised tenants. Restricting to an approved domain list limits social engineering, data leakage through unsanctioned external chats, and phishing originating from external Teams federated users. | Organization.Read.All - via teamsExternalAccessPolicy, teamsFederationConfiguration |
External file sharing in Teams is enabled for only approved cloud storage serviceswt.teams.external-file-sharing-restricted | MEDIUM | Checks that third-party cloud storage integrations (Dropbox, Box, Google Drive, ShareFile, Egnyte) are disabled in Teams, preventing users from sharing files from unmanaged external storage services. | Third-party cloud storage in Teams bypasses DLP policies, audit logging, and data governance controls, allowing sensitive corporate files to be shared from and stored in services outside corporate oversight. This creates an unaudited data exfiltration path that is invisible to Microsoft Purview. | Organization.Read.All - via teamsClientConfiguration |
Anonymous users can't join a meetingwt.teams.meeting.anonymous-join-disabled | MEDIUM | Checks that Teams meeting policies prevent anonymous users (those without an authenticated identity) from joining meetings. | Anonymous meeting access allows anyone with a meeting link to join without signing in, making it impossible to verify participant identity or apply access controls. Attackers can join sensitive meetings, record proprietary discussions, and exfiltrate shared content without leaving an auditable identity trail. | Organization.Read.All - via teamsMeetingPolicy |
Anonymous users and dial-in callers can't start a meetingwt.teams.meeting.anonymous-start-disabled | MEDIUM | Checks that Teams meeting policies prevent anonymous users and dial-in callers from starting meetings before an authenticated organiser has joined. | If anonymous users can start meetings, an attacker who obtains a meeting link can begin the session before the legitimate organiser, potentially recording the meeting or social-engineering late-arriving participants into disclosing sensitive information before they realise they are in an unsecured session. | Organization.Read.All - via teamsMeetingPolicy |
Meeting chat does not allow anonymous userswt.teams.meeting.chat-no-anonymous | MEDIUM | Checks that Teams meeting chat is configured to exclude anonymous participants, preventing unidentified users from sending messages or sharing links in meeting chats. | Meeting chat messages are visible to all participants and can contain links, files, and sensitive discussion content. Anonymous participants in meeting chat can distribute malicious links or social-engineer authenticated participants into clicking them, without any identity accountability. | Organization.Read.All - via teamsMeetingPolicy |
Users dialing in can't bypass the lobbywt.teams.meeting.dialin-lobby-bypass-disabled | MEDIUM | Checks that PSTN (dial-in phone) participants are required to wait in the lobby rather than bypassing it to join meetings directly. | Dial-in participants who bypass the lobby cannot be identified or verified by the meeting organiser before joining. This allows anonymous external parties to listen to sensitive meeting content before the organiser notices their presence, enabling eavesdropping on confidential discussions. | Organization.Read.All - via teamsMeetingPolicy |
External meeting chat is offwt.teams.meeting.external-chat-disabled | MEDIUM | Checks that Teams meeting policies prevent external (non-trusted) participants from sending messages in meeting chat, limiting chat participation to authenticated organisational members. | External participants in meeting chat can share malicious links or sensitive information with all meeting attendees. Disabling external chat participation in non-trusted meetings reduces the risk of phishing link distribution and data exfiltration through the meeting chat channel. | Organization.Read.All - via teamsMeetingPolicy |
External participants can't give or request controlwt.teams.meeting.external-control-disabled | MEDIUM | Checks that external meeting participants are prevented from giving or requesting desktop or application sharing control during Teams meetings. | Granting screen-sharing control to external participants effectively gives them remote control over the sharer's desktop or application. A malicious external user could exploit this to install software, access files, or capture sensitive information displayed during the session. | Organization.Read.All - via teamsMeetingPolicy |
Only people in my org can bypass the lobbywt.teams.meeting.lobby-bypass-restricted | MEDIUM | Checks that Teams meeting lobby bypass is restricted to organisational members or invited users only, requiring external and anonymous participants to wait for explicit admission. | When lobby bypass is set to allow everyone, any external user who obtains a meeting link can enter the meeting without the organiser's explicit approval. This enables eavesdropping on sensitive meetings, bypasses the organiser's ability to screen participants, and allows attacker-in-the-meeting scenarios. | Organization.Read.All - via teamsMeetingPolicy |
Only organizers and co-organizers can presentwt.teams.meeting.presenter-restricted | MEDIUM | Checks that Teams meeting presenter permissions are restricted to organizers and co-organizers by default, requiring explicit promotion before other participants can share screen or manage meeting content. | When all participants are presenters by default, external attendees and guests can share their screens, remove other participants, and take control of meeting content. Restricting presenter rights reduces the ability of malicious or compromised meeting participants to disrupt sessions or share inappropriate content. | Organization.Read.All - via teamsMeetingPolicy |
Meeting recording is off by defaultwt.teams.meeting.recording-off-by-default | MEDIUM | Checks that Teams cloud recording is disabled by default in meeting policies, ensuring recordings are only enabled deliberately rather than automatically for all meetings. | When recording is enabled by default, every Teams meeting - including sensitive executive discussions, HR matters, and legal proceedings - is recorded and stored, creating a large repository of sensitive content that becomes a high-value target for data exfiltration. Disabling by default limits recording to explicitly authorised sessions. | Organization.Read.All - via teamsMeetingPolicy |
Users can report security concerns in Teamswt.teams.security-reporting-enabled | MEDIUM | Checks that the security concern reporting feature is enabled in Teams, allowing users to flag suspicious messages and content for security team review. | Enabling in-product security reporting lowers the barrier for users to report phishing attempts, social engineering, and malicious content shared in Teams. Early reporting accelerates incident detection and response, reducing the time between initial compromise attempt and security team awareness. | Organization.Read.All - via teamsMessagingPolicy |
Organization cannot communicate with accounts in trial Teams tenantswt.teams.trial-tenant-communication-blocked | MEDIUM | Checks that communication with accounts in Microsoft Teams trial tenants is blocked, preventing federation with temporary or unverified organisations. | Trial Teams tenants are frequently created by attackers as low-friction infrastructure for social engineering campaigns. By federating with your organisation, accounts in trial tenants can initiate chats and calls that appear as legitimate external Teams contacts, facilitating targeted phishing and business relationship impersonation. | Organization.Read.All - via teamsFederationConfiguration |
External Teams users cannot initiate conversationswt.teams.unmanaged-inbound-disabled | MEDIUM | Checks that external Teams users from other organisations cannot initiate new conversations with internal users, limiting unsolicited inbound contact from unknown external parties. | Allowing any external Teams user to initiate conversations with internal users creates a direct channel for social engineering, phishing link delivery, and unsolicited contact from threat actors. Disabling inbound contact from non-trusted external users reduces the attack surface for Teams-based social engineering. | Organization.Read.All - via teamsExternalAccessPolicy, teamsFederationConfiguration |
Communication with unmanaged Teams users is disabledwt.teams.unmanaged-user-access-disabled | MEDIUM | Checks that communication with unmanaged Teams users (those using Teams with a personal Microsoft account rather than a work or school account) is disabled. | Unmanaged Teams users are not subject to organisational governance, MFA policies, or identity verification. Allowing communication with these users provides attackers with a pathway to reach corporate users from personal accounts that cannot be screened or audited through enterprise identity controls. | Organization.Read.All - via teamsExternalAccessPolicy, teamsFederationConfiguration |