8.5.5 Ensure meeting chat does not allow anonymous users

Information

This policy setting controls who has access to read and write chat messages during a meeting.

Rationale:

Ensuring that only authorized individuals can read and write chat messages during a meeting reduces the risk that a malicious user can inadvertently show content that is not appropriate or view sensitive information.

Impact:

Only authorized individuals will be able to read and write chat messages during a meeting.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To remediate using the UI:

Navigate to Microsoft Teams admin center https://admin.teams.microsoft.com.

Click to expand Meetings select Meeting policies.

Click Global (Org-wide default).

Under meeting engagement set Meeting chat to On for everyone but anonymous users.

To remediate using PowerShell:

Connect to Teams PowerShell using Connect-MicrosoftTeams.

Run the following command to set the recommended state:

Set-CsTeamsMeetingPolicy -Identity Global -MeetingChatEnabledType 'EnabledExceptAnonymous'

Default Value:

On for everyone (Enabled)

See Also

https://workbench.cisecurity.org/benchmarks/15279

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: microsoft_azure

Control ID: a213776520d42d7315b605268ccbda8a08ec6a6683de237e455038c3539cf815