TL;DR:
- Microsoft Teams is now actively used by attackers to deliver phishing links, malicious files, and social engineering — particularly targeting employees via external guest messages that look like internal communications
- The most important settings to review are external access (federation), guest access, and who can create new teams — most small businesses have these too permissive by default
- Users need to know about the green “External” label in Teams — it indicates someone outside your organisation, and seeing it on a “helpdesk” or “Microsoft support” message should immediately raise suspicion
When businesses think about phishing, they think about email. Teams barely registers as an attack surface — which is exactly what makes it useful for attackers. A malicious link in a Teams chat from what appears to be a supplier, a “helpdesk” message asking you to click to verify your credentials, a file shared by what looks like a colleague — these attacks work partly because people are less suspicious in Teams than they are in email.
The Russian state-linked threat group Midnight Blizzard (Cozy Bear) ran a documented campaign in 2023–2024 that specifically used Teams messages to social-engineer targets into providing MFA codes. They created domains that looked like IT or security companies, added the attacker-controlled accounts as external users, and sent Teams messages to targets impersonating internal IT. It worked.
Small businesses don’t need to worry about Russian state actors specifically, but the same techniques are used by commodity cybercriminals running business email compromise and credential theft campaigns. Here’s what to do about it.
Review Your External Access Settings
External access (sometimes called federation) controls whether people in other organisations can find and message your users in Teams. In many Microsoft 365 tenants, this is enabled by default with minimal restrictions.
Go to Microsoft Teams admin centre → External access.
You have three options: allow all external domains, allow only specific domains, or block all external domains. For most small businesses, the middle option — allowing external access only for domains you have active business relationships with — is the right balance.
If you regularly collaborate with specific suppliers, clients, or partners, allowlist their domains. Block everything else. The practical effect is that random external organisations can no longer cold-message your staff via Teams, which removes a significant attack vector.
If your business never needs to communicate externally via Teams (you use email for external comms and Teams for internal only), turn external access off entirely.
Tighten Guest Access
Guest access is different from external access — it allows people outside your organisation to be added to specific teams and channels, where they can participate in conversations, access files, and use the full Teams experience within that team.
Guests are useful for project collaboration with clients or contractors. But check who can add guests in your current configuration. In some Microsoft 365 plans, any user can invite guests by default. This means any employee can give an external person access to internal team channels without IT or management being involved.
In the Teams admin centre under Guest access, you can:
- Disable guest access entirely if you don’t use it
- Restrict who can invite guests (Microsoft 365 group/team owners only, rather than all members)
- Limit what guests can do (turn off ability to delete messages, restrict calling permissions)
Review your existing guests periodically. In the Microsoft Entra ID portal you can see all guest accounts in your tenant — remove any that are no longer active. An unused external account from a contractor who finished six months ago is a dormant risk if that contractor’s Microsoft account is ever compromised.
Control Who Can Create Teams
By default in many Microsoft 365 configurations, any user can create a new team. This sounds harmless but creates a sprawl problem: dozens of ad hoc teams with inconsistent access controls, files scattered without oversight, and guests added without any review process.
Restricting team creation to specific groups (IT administrators, department heads) means you maintain visibility over what Teams channels exist and who has access to them. Set this in Microsoft Entra ID → Groups → General settings → Users can create Microsoft 365 groups.
What Users Need to Know
Admin settings help, but the most important defence is user awareness of two specific things.
The “External” label: When someone outside your organisation messages you in Teams, their name displays with a green “(External)” tag next to it. This is Teams telling you that this person is not from your company. Train your team to look for this label — if they receive a message from “IT Support (External)” or “Microsoft Technical (External)”, that’s an immediate red flag. Your actual IT support is internal. Microsoft will never contact you this way.
Meeting links and file requests: Attackers send Teams messages asking recipients to click a link to “verify their Microsoft account” or “approve a pending request.” The URL often points to a phishing page designed to steal Microsoft 365 credentials. The rule for Teams is the same as for email: if a message asks you to click a link and enter credentials, verify through a different channel before doing so.
Protecting Meetings
If your business uses Teams for client calls or sensitive discussions, review these meeting settings in the Teams admin centre:
Lobby settings: Configure who bypasses the lobby by default. “People in my organisation” is the appropriate setting for internal meetings. “People in my organisation and guests” is suitable for regular external collaborators. “Everyone” should only be used when you’re running a public event.
Recording permissions: Decide whether meeting recordings should be permitted and where they’re stored (OneDrive/SharePoint). Recordings of sensitive discussions should be treated as sensitive files and stored accordingly.
Who can present: Default to “People in my organisation and guests” rather than “Everyone”. This prevents a non-participant from taking control of a screen share in an open meeting.
Two Quick Security Checks to Do Today
Check Secure Score for Teams: In the Microsoft 365 Defender portal, Microsoft Secure Score shows recommended improvements specifically for Teams configuration. Filter recommendations by “Teams” for a prioritised list based on your current settings.
Enable Safe Links for Teams: If your Microsoft 365 plan includes Defender for Office 365 (available in Business Premium), make sure Safe Links is enabled for Teams. Safe Links rewrites URLs in Teams messages and checks them against Microsoft’s threat intelligence before allowing the click — catching known malicious URLs that users might otherwise follow without thinking.
Teams security isn’t complicated. The settings are all accessible, the user training is straightforward, and the threat model is the same as email — just in a channel people tend to trust more than they should.