8.5.2 Ensure anonymous users and dial-in callers can't start a meeting

Information

This policy setting controls if an anonymous participant can start a Microsoft Teams meeting without someone in attendance. Anonymous users and dial-in callers must wait in the lobby until the meeting is started by someone in the organization or an external user from a trusted organization.

Anonymous participants are classified as:

Participants who are not logged in to Teams with a work or school account.

Participants from non-trusted organizations (as configured in external access).

Participants from organizations where there is not mutual trust.

Note: This setting only applies when Who can bypass the lobby is set to Everyone. If the anonymous users can join a meeting organization-level setting or meeting policy is Off, this setting only applies to dial-in callers.

Rationale:

Not allowing anonymous participants to automatically join a meeting reduces the risk of meeting spamming.

Impact:

Anonymous participants will not be able to start a Microsoft Teams meeting.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Meetings select Meeting policies.

Click Global (Org-wide default).

Under meeting join & lobby set Anonymous users and dial-in callers can start a meeting to Off.

To remediate using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams.

Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -AllowAnonymousUsersToStartMeeting $false

Default Value:

Off (False)

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: microsoft_azure

Control ID: 951ba5d652ac76cd73d55bbd759122c1faadadbd20cdeed14a090c14771e2444