Microsoft has rolled out a new feature to its popular team collaboration platform, Teams, aimed at protecting users from external bots joining meetings. The company is allowing administrators to automatically block all identified external bots from participating in Teams meetings, adding an extra layer of security to its existing bot protection policies.
This move comes as part of Microsoft’s ongoing efforts to bolster the security of its services, particularly after a surge in attacks abusing Teams for unauthorized access and lateral movement on enterprise networks. Threat actors have been impersonating IT or helpdesk staff to trick employees into granting remote access, which has led to data theft. To counter this trend, Microsoft is providing administrators with more control over how identified bots are handled.
The new policy will be available in the Teams admin center under “Manage bots” meeting protection settings and will require administrator activation before deployment. Once enabled, it can be assigned to specific users or groups through existing Teams meeting policy management. This feature ensures that third-party bots, which may be used for automated tasks such as note-taking and transcription, cannot join meetings without attendees’ knowledge.
The change is also a response to the growing threat of social engineering attacks targeting employees via cross-tenant chats in Teams. Cybercrime gangs, including ransomware groups, have been using this tactic to gain access to sensitive data. Microsoft has been working to address these issues by introducing additional admin controls, such as policies to block external bots entirely and allow lists for approved bots.
The new policy will be rolling out as part of a targeted release until the end of August, with general availability worldwide expected by late September. While this development is a welcome addition to Teams’ security features, it’s essential for administrators to stay vigilant and continuously monitor their networks for potential threats.
For users, this means that meeting organizers can now have more confidence in the participants joining their meetings, knowing that any external bots will be automatically blocked. However, it also highlights the importance of staying informed about the latest security developments and updates to ensure that your organization is protected against emerging threats.
Source: Bleeping Computer — 2026-08-24