Microsoft is rolling out a new Teams meeting policy that lets administrators automatically block identified external bots from joining calls.

The new setting gives organisations more control over third-party meeting participants. It can stop external bots before they enter a meeting, removing the need for organisers to approve or reject them individually.

Microsoft said the policy will begin reaching organisations through a targeted release in August. Worldwide availability is expected by late September.

New policy blocks detected bots automatically

Teams external bot blocking will be available through the Manage bots meeting protection settings in the Teams admin centre.

The feature will be disabled by default. Administrators must enable it and assign the policy to selected users or groups before it takes effect.

Once active, the policy will automatically block identified external meeting bots from any meeting covered by that assigned rule.

External bots can support legitimate tasks, including note-taking, transcription and other automated meeting functions. However, they can also create privacy and security concerns when participants do not know that a non-human attendee has joined.

The new control aims to reduce that risk by stopping detected external bots at the door.

Feature builds on earlier Teams protections

Microsoft introduced another bot-related meeting policy in June. That earlier update labels detected bots in the Teams lobby and requires organiser approval before they can join.

The latest option takes a stricter approach. Instead of waiting for an organiser to make a decision, Teams can deny entry automatically.

This may be useful for organisations that do not allow external meeting bots or want to limit their use to approved internal tools.

Microsoft said administrators can apply the setting through existing Teams meeting policy management. That allows different teams or groups to receive different levels of protection.

Teams remains a target for social engineering

The rollout arrives as attackers increasingly use Teams and other workplace communication tools in social engineering campaigns.

Threat actors have impersonated IT support and helpdesk staff in cross-tenant chats. They may then attempt to persuade employees to grant remote access or reveal credentials.

Microsoft has previously introduced controls that allow administrators to block external Teams users through the Defender portal. Those features are designed to reduce exposure to malicious contacts and unauthorised activity.

Meeting bots can create another route for unwanted access. A malicious or unapproved app could potentially enter a call without every attendee recognising its presence.

More bot controls are planned

Microsoft has also announced plans for additional administrator controls around Teams bots.

These may include policies that block external bots entirely, allow lists for approved bots, bot-detection reports and audit logs. The company also plans to introduce more granular settings for organisations with different security requirements.

For now, Teams external bot blocking gives administrators a direct way to prevent detected third-party bots from entering selected meetings.


0 responses to “Microsoft Teams Adds External Bot Blocking for Meetings”