8.1.2 Ensure users can't send emails to a channel email address

Information

Teams channel email addresses are an optional feature that allows users to email the Teams channel directly.

Rationale:

Channel email addresses are not under the tenant's domain and organizations do not have control over the security settings for this email address. An attacker could email channels directly if they discover the channel email address.

Impact:

Users will not be able to email the channel directly.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Teams select Teams settings.

Under email integration set Users can send emails to a channel email address to Off.

To remediate using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams.

Run the following command to set the recommended state:

Set-CsTeamsClientConfiguration -Identity Global -AllowEmailIntoChannel $false

Default Value:

On (True)

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: microsoft_azure

Control ID: 404d8f4f8676444b36537a8ea7347f880f106c2a99a26cc07ac20948685b8029