discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

By Sergiu Gatlan·Aug 24·bleepingcomputer.com·3 min read

Intelligence analysis by Llama

Microsoft Teams now lets admins block external bots from meetings
Image: bleepingcomputer.com

Microsoft adds a new admin-level control that automatically blocks external bots from joining Teams meetings, extending a June policy that only tagged bots in the lobby. The feature rolls out through late September and sits under 'Manage bots' in the Teams admin center.

Why it matters

External bots have become a viable vector for social engineering on Teams, and any tooling that lets defenders hard-block them at the policy layer reduces reliance on per-meeting vigilance by organizers.

Microsoft is giving the people who run a company's Teams account a new button that says 'no robots allowed in our video calls unless we say so.' It works like a bouncer at a party who checks the guest list and turns away anyone who isn't a real person, so bad guys can't sneak in disguised as helpful computer helpers.

Analysis

"Manage bots" meeting protection settings

The new control lives under the "Manage bots" meeting protection settings inside the Teams admin center, sitting one layer above the per-user meeting policy framework admins already use. It is off by default, which means tenant owners will have to opt in deliberately after evaluating the impact on legitimate third-party bots that some departments rely on for transcription, note-taking, or workflow automation. Once enabled, the policy can be scoped to specific users or groups through the existing Teams meeting policy assignment flow, so a security team can roll it out to high-risk groups first without disrupting every meeting in the tenant.

Because the toggle operates at the policy layer rather than as a per-meeting switch, it effectively flips the default posture: an external bot that would have previously landed in the lobby now never gets that far. That is a meaningful shift from the June update, which only labeled detected bots in the lobby and forced organizers to manually approve or reject them. Manual approval is the weakest link in any bot-screening workflow, because organizers under time pressure tend to admit unfamiliar participants, especially when the bot name looks plausible.

April warning about surging Teams abuse

The new policy lands against a backdrop Microsoft itself flagged in April, when the company warned that attacks abusing Teams for access and lateral movement on enterprise networks were accelerating. In those campaigns, threat actors impersonated IT or helpdesk staff, contacted employees through cross-tenant chats, and walked them through granting remote access that ended in data theft. Blocking external bots by policy does not directly stop a human-impersonating attacker, but it removes one of the automation tools those operations lean on, such as scripts or recorded-message bots that can probe meeting links at scale.

The April advisory also pointed out that once an attacker is already inside a tenant, defenders have less time and fewer signals to work with than the initial-access phase suggests. That asymmetry is exactly the kind of risk an organization-wide block on external bots is designed to shrink, by cutting off a class of automated visitors before they ever appear in a meeting roster.

December Defender portal integration

The bot-blocking policy is the third leg of a broader hardening sequence Microsoft has been building across Teams and its security stack since late last year. Since December, admins have been able to block external Teams users outright through the Defender portal, a control aimed at ransomware crews and other cybercrime gangs that were running Teams-based social engineering against employee targets. Together with the June lobby-tagging policy and this new automatic block, Microsoft is moving from reactive, organizer-level approvals toward a tenant-wide default that is harder to bypass.

Microsoft has also signaled that more controls are still on the roadmap, including allow lists for approved bots, admin reports and audit logs covering bot detection and presence in meetings, and more granular policies for different security requirements. For security teams that have been treating Teams as a soft underbelly in their collaboration stack, the combination of a default-off but centrally managed block, Defender-level external user controls, and forthcoming visibility tooling gives them a much more defensible posture going into 2026.

Key points

  • Microsoft is rolling out a new Teams policy that automatically blocks identified external bots from joining meetings, without organizer approval.
  • The feature is off by default, lives under 'Manage bots' in the Teams admin center, and can be scoped to specific users or groups.
  • Targeted release runs through the end of August, with general availability worldwide expected by late September.
  • It builds on a June policy that only tagged detected bots in the lobby, and on December Defender portal controls that block external Teams users.
  • Microsoft warned in April that Teams-based attacks for access and lateral movement are surging, often via cross-tenant chats impersonating IT or helpdesk staff.
The Upside

If widely enabled, the policy could meaningfully reduce the attack surface that threat actors have exploited through Teams-based social engineering, and the forthcoming audit logs and allow lists would give security teams real visibility into bot traffic for the first time. Combined with the December Defender portal controls, it positions Teams as a more defensible collaboration surface heading into the next wave of enterprise attacks.

The Downside

Because the feature is off by default and must be assigned per user or group, many tenants will leave it disabled to preserve third-party transcription and note-taking bots, blunting its real-world impact. Attackers can also pivot to impersonating human users through cross-tenant chats, which this policy does not address and which Microsoft itself warned about in April.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechbusinesspolicy

Author

Sergiu Gatlan

Intelligence analysis by

Llama

Published

Aug 24, 2026

Source

bleepingcomputer.com

Share

Topics

securitytechbusinesspolicy

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.

Aug 24·thehackernews.com

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

AI coding tools can introduce open-source packages at a pace security teams were never built to handle, leading to remediation debt and security work accumulating faster than teams can close it.