Microsoft Tightens Bot Controls in Teams Meetings

Microsoft is rolling out a new Teams admin policy that gives organizations more control over which bots can join their meetings. It’s a response to a growing problem: malicious actors using third-party bots to infiltrate corporate calls.

Once enabled, the policy automatically detects potential bots and places them in the meeting lobby. Organizers then have to explicitly approve them before they can join. Even in meetings where participants can bypass the lobby, flagged bots will still need approval.

Why now? Attackers have increasingly abused Teams for social engineering. Ransomware groups like Black Basta have posed as IT support through Teams calls. Others have used cross-tenant chats to impersonate helpdesk staff and trick employees into granting remote access.

Microsoft says additional controls are coming: allow lists for approved bots, policies to block external bots entirely, admin reports and audit logs, and more granular security controls. Starting in December, admins will also be able to block external Teams users through the Defender portal.

The company’s been building out Teams security features steadily — brand impersonation warnings for calls arrived in January, and a call reporting feature launched in March. This bot protection policy is the next layer in what’s becoming a much-needed defense stack.

If you’re running Teams at scale, this is worth enabling sooner rather than later.