8.5.4 Ensure users dialing in can't bypass the lobby

Information

This policy setting controls if users who dial in by phone can join the meeting directly or must wait in the lobby. Admittance to the meeting from the lobby is authorized by the meeting organizer, co-organizer, or presenter of the meeting.

Rationale:

For meetings that could contain sensitive information, it is best to allow the meeting organizer to vet anyone not directly from the organization.

Impact:

Individuals who are dialing in to the meeting must wait in the lobby until a meeting organizer, co-organizer, or presenter admits them.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Meetings select Meeting policies.

Click Global (Org-wide default).

Under meeting join & lobby set People dialing in can't bypass the lobby to Off.

To remediate using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams.

Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -AllowPSTNUsersToBypassLobby $false

Default Value:

Off (False)

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: 56b9367a247986a08510a90eb414f2cdd3603b137598d42faf03461e43bacb1f