Microsoft Teams adds policy to automatically block external meeting bots
Microsoft is introducing a new Teams meeting protection policy that allows administrators to automatically block external bots from joining meetings. The policy, available in the Teams admin center, is off by default and can be assigned to specific users or groups. It builds on an earlier feature that required organizer approval for detected bots.
The new "Manage bots" meeting protection setting in the Teams admin center defaults to off, requiring administrators to activate and evaluate it before deployment. Once enabled, the policy can be assigned to specific users or groups through existing Teams meeting policy management channels. This follows June's bot protection feature that tagged detected bots in the lobby and required organizer approval before admission.
Microsoft's April warning highlighted surging attacks where threat actors impersonated IT staff via cross-tenant chats to trick employees into granting remote access. Since December, admins could block external Teams users through the Defender portal. The company also plans additional controls, including approved bot allow lists, admin reports, and audit logs for bot detection.
This policy could meaningfully reduce social engineering risks for organizations that rely on Teams for daily operations, particularly those targeted by credential theft and impersonation campaigns. By automatically blocking external bots, companies may lower the chance of malicious non-human participants accessing sensitive discussions. However, legitimate third-party bots used for productivity tasks could also be affected, potentially disrupting workflows. Administrators will need to balance security benefits against operational convenience when deciding whether to enable the policy.