8.5.3 Ensure only people in my org can bypass the lobby

Information

This policy setting controls who can join a meeting directly and who must wait in the lobby until they're admitted by an organizer, co-organizer, or presenter of the meeting.

Rationale:

For meetings that could contain sensitive information, it is best to allow the meeting organizer to vet anyone not directly sent an invite before admitting them to the meeting. This will also prevent the anonymous user from using the meeting link to have meetings at unscheduled times.

Impact:

Individuals who are not part of the organization will have to wait in the lobby until they're admitted by an organizer, co-organizer, or presenter of the meeting.

Any individual who dials into the meeting regardless of status will also have to wait in the lobby. This includes internal users who are considered unauthenticated when dialing in.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Meetings select Meeting policies.

Click Global (Org-wide default).

Under meeting join & lobby set Who can bypass the lobby to People in my org.

To remediate using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams.

Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -AutoAdmittedUsers 'EveryoneInCompanyExcludingGuests'

Default Value:

People in my org and guests (EveryoneInCompany)

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

References: 800-53|AC-2, 800-53|AC-3, 800-53|AC-6, 800-53|AC-6(1), 800-53|AC-6(7), 800-53|AU-9(4)

Plugin: microsoft_azure

Control ID: c4eba1666ae1e27cf5e64cbe26b1d129cd4ea5cf538a1f3da8a8e06dbb504424