Microsoft has introduced a new policy for Teams that allows administrators to automatically block all identified external bots from joining meetings. This feature is designed to enhance meeting security by preventing third-party bots and potentially malicious applications from accessing conversations without explicit human approval.
The new policy builds on a previous update from June, which introduced smarter bot protection by tagging detected bots in the meeting lobby and requiring organizer approval for their admission. The latest iteration streamlines this process, automatically denying entry to external bots without requiring an organizer's manual confirmation.
According to a Microsoft 365 Message Center update, the company stated that this update provides administrators with greater control over how identified bots are handled, thereby helping to reduce organizational risk. The policy is currently in a targeted release phase, expected to conclude by the end of August, with worldwide general availability anticipated by late September.
Administrators can find the new setting under "Manage bots" within the meeting protection settings in the Teams admin center. It will be disabled by default, requiring activation and evaluation by an administrator before deployment. Once enabled, the policy can be assigned to specific users or groups through existing Teams meeting policy management.
The change addresses concerns that various third-party bots, used for tasks such as note-taking or transcription, as well as malicious apps controlled by threat actors, could join Teams meetings unnoticed. Microsoft previously warned in April about a surge in attacks exploiting Teams for initial access and lateral movement within enterprise networks. These attacks often involve threat actors impersonating IT or helpdesk personnel via cross-tenant chats to trick employees into granting remote access and stealing data.
Since December, administrators have also been able to block external Teams users via the Defender portal to counter cybercrime groups, including ransomware operators, who leverage Teams for social engineering attacks. Additional admin controls announced in June are also planned, including options to entirely block external bots, create allow lists for approved bots, and access admin reports and audit logs on bot detection and presence, along with more granular security controls.






