3.7 Ensure external file sharing in Teams is enabled for only approved cloud storage services

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Microsoft Teams enables collaboration via file sharing. This file sharing is conducted within Teams, using SharePoint Online, by default; however, third-party cloud services are allowed as well.

NOTE: Skype for business is deprecated as of July 31, 2021 although these settings may still be valid for a period of time. See the the link in the reference for more information.

Rationale:

Ensuring that only authorized cloud storage providers are accessible from Teams will help to dissuade the use of non-approved storage providers.

Impact:

Impact associated with this change is highly dependent upon current practices in the tenant. If users do not use other storage providers, then minimal impact is likely. However, if users do regularly utilize providers outside of the tenant this will affect their ability to continue to do so.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set external file sharing in Teams:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Teams select Teams settings.

Set any unauthorized providers to Off.

To set cloud sharing options using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams

Run the following command to verify which cloud storage providers are enabled for Teams

Get-CsTeamsClientConfiguration | select AllowDropbox,AllowBox,AllowGoogleDrive,AllowShareFile,AllowEgnyte

Run the following PowerShell command to disable external providers that are not authorized. (the example disables Citrix Files, DropBox, Box, Google Drive and Egnyte)

Set-CsTeamsClientConfiguration -AllowGoogleDrive $false -AllowShareFile $false -AllowBox $false -AllowDropBox $false -AllowEgnyte $false

Default Value:

AllowDropbox true

AllowBox true

AllowGoogleDrive true

AllowShareFile true

AllowEgnyte true

See Also

https://workbench.cisecurity.org/benchmarks/10751