Back to category

Week 12

Audit Microsoft Teams External Access and Sharing Settings

Beginner
Microsoft Security Engineer
Cloud Security Engineer
Microsoft Security Best Practices
Microsoft Teams Security
Collaboration Security

Client Background

The client has expanded use of Microsoft Teams for collaboration with external partners and is concerned about data leakage through guest access and external sharing. Review Teams external access, guest permissions, and meeting security settings.

Business Environment

Lattice Engineering Partners (480 employees) expanded Teams-based collaboration with 30+ external subcontractors and clients after moving to a project-delivery model. The tenant is M365 E5 with guest access enabled by default, and project files live in SharePoint sites linked to each Teams channel. A compliance officer flagged that guest retention and external-meeting policies had never been reviewed.

Security Incident

No incident; the engagement is a preventive audit. The trigger was the discovery that one external guest retained access to a confidential project site 90 days after the engagement ended, prompting a tenant-wide access-review request from the COO.

Scope

Microsoft Teams admin center external access, guest access, and meeting policy configuration.

Objectives

  • Review external access and federation settings
  • Evaluate guest access permissions within Teams
  • Assess meeting security policies (lobby, recording, presenter settings)
  • Identify overly permissive sharing configurations

Required Deliverables

Microsoft Teams Security Assessment Report
2 hrs estimated