Microsoft has introduced a new feature in its popular collaboration platform, Teams, designed to strengthen meeting security by automatically blocking external bots from joining meetings. This move comes as part of an ongoing effort to mitigate the rising threat of attacks that exploit Teams vulnerabilities for unauthorized access and lateral movement on enterprise networks.
The new policy allows administrators to configure their Teams settings to automatically detect and block identified external bots from joining meetings, without requiring explicit organizer confirmation before they’re admitted. This feature builds upon a previous update introduced in June, which added smarter bot protection by tagging all detected bots in the lobby and requiring organizer approval for them to join.
The new policy is now available as part of a targeted release until the end of August, with general availability worldwide expected by late September. Admins can enable this feature under the “Manage bots” meeting protection settings in the Teams admin center, which will be off by default and require activation before deployment. Once enabled, the policy can be assigned to specific users or groups through existing Teams meeting policy management.
This change is crucial as it ensures that malicious apps controlled by threat actors cannot join Teams meetings without attendees and organizers realizing that a non-human participant has been added. As Microsoft warned in April, attacks abusing Teams for access and lateral movement on enterprise networks are surging, with threat actors impersonating IT or helpdesk staff to contact employees via cross-tenant chats and trick them into granting remote access to steal data.
The introduction of this new feature marks another step towards enhancing meeting security within Teams. In addition to blocking external bots, Microsoft has also planned additional admin controls, including policies to block external users entirely, allow lists for approved bots, and more granular controls for different security requirements. These measures aim to provide organizations with greater control over how identified bots are handled, ultimately reducing the risk of organizational compromise.
For businesses relying on Teams, this update serves as a reminder that even seemingly innocuous features can pose significant security risks if not properly managed. Admins should take advantage of this new feature and review their current bot management policies to ensure they’re adequately equipped to handle emerging threats.
Source: Bleeping Computer — 2026-08-24