Microsoft Teams Adds Policy to Fully Block External Bots From Meetings
Corporate video meetings are increasingly attracting attention not only from employees but from automated services as well, prompting Microsoft to roll out new protections within Teams. Administrators will now be able to fully block detected external bots outright, preventing them from joining meetings without requiring an organizer to make an additional decision each time.
Building on June’s Bot Detection Feature
The new policy extends a mechanism Microsoft introduced back in June. Currently, Teams flags detected bots within the meeting lobby, leaving the organizer to decide whether to admit them. Once the new setting is enabled, an external bot the system identifies will be unable to join a protected meeting at all – full stop.
Configuration Through the Teams Admin Center
This control will appear within the “Manage bots” section of the Teams admin center. By default, the feature will remain disabled, meaning organizations will need to evaluate the setting themselves and activate it deliberately. The policy can be assigned to individual users and groups through Teams’ existing meeting management system.
What the Restriction Covers
The restriction applies to third-party bots commonly used for transcribing conversations, generating meeting notes, and other automated tasks. This same blocking mechanism will also prevent malicious applications from connecting, provided Teams recognizes them as external bots, reducing the risk of an automated participant quietly joining a meeting unnoticed.
A Response to Growing Abuse of Teams
Microsoft is strengthening these protections against a backdrop of rising abuse of Teams within corporate networks. The company has previously warned about schemes in which attackers impersonate IT staff, contact employees through cross-organizational chats, and persuade them to grant remote access – access that is subsequently used to steal data.
Rollout Timeline
Microsoft has begun a limited rollout of the new policy and plans to complete it by the end of August. A full worldwide launch is expected by the end of September. The company is also preparing allowlists for approved bots, detailed reports and detection logs, and more flexible rules to accommodate organizations with varying meeting-protection requirements.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.