MS.TEAMS.2.2v1 - Unmanaged users SHALL NOT be enabled to initiate contact with internal users.

Information

Allowing contact from unmanaged users can expose users to email and contact address harvesting. This policy provides protection against this type of harvesting.

Solution

1. Sign in to the Microsoft Teams admin center.

2. Select Users > External access.

3. Under Teams accounts not managed by an organization, toggle People in my organization can communicate with Teams users whose accounts aren't managed by an organization to one of the following:
1. To completely block contact with unmanaged users, toggle the setting to Off.
2. To allow contact with unmanaged users only if the internal user initiates the contact:
- Toggle the setting to On.
- Clear the check next to External users with Teams accounts not managed by an organization can contact users in my organization.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-4, 800-53|CA-7, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|SC-7, 800-53|SC-44, 800-53|SI-2, 800-53|SI-3, 800-53|SI-4, 800-53|SI-8

Plugin: microsoft_azure

Control ID: 0f55b5e5c2b360d73cb3bb01c58bab6739ea16dbbf8542e9a5f177778d92dc9a