Microsoft Teams Security Best Practices for UK Businesses
Microsoft Teams is the primary communication and collaboration platform for most UK businesses using Microsoft 365. It handles sensitive conversations, file sharing, meeting recordings, and increasingly, integration with business-critical application...
Overview
Microsoft Teams default settings are too permissive for most UK businesses — guest access, external sharing, and team creation all require deliberate governance. Teams is increasingly used as a phishing vector. Defender for Office 365 Safe Links and Safe Attachments should be extended to Teams. Quarterly guest access reviews prevent sensitive data being accessible to former external users.
Learn about M365 securityWhy does Microsoft Teams security matter for UK businesses?
Teams is now one of the most data-rich systems most UK firms run. It carries commercially sensitive negotiations, HR matters, financial approvals and strategic plans, while every file shared lives in SharePoint and every recording in OneDrive. That concentration of data, plus heavy external collaboration, makes it a target worth securing properly.
Attackers have noticed. The NCSC treats messaging and collaboration platforms as prime ground for social engineering, and phishing remains the single most common attack type reported by UK businesses in the government's Cyber Security Breaches Survey 2025. Once an attacker compromises one Microsoft 365 account, Teams chat becomes a trusted channel to impersonate colleagues and approve payments.
The default settings make this worse. Guest access, external federation, anonymous meeting join and open app installation all ship switched on, prioritising ease of use over containment. Tightening them — alongside Conditional Access — is the work that turns a usable platform into a safe one.
How do you control guest access in Microsoft Teams?
Guest access lets people outside your organisation join teams and channels using any email address. It is genuinely useful for client and supplier collaboration, but uncontrolled it becomes the most common Teams data-exposure route. The fix is to limit who can invite, force MFA on guests, and review accounts on a schedule.
By default a guest can read and post in channels they are added to, join meetings, and open files in those channels. They cannot create teams, invite other guests, or reach the admin centre. The problems are accumulation and scope: guests rarely get removed, and a guest invited at team level can often see every non-private channel in that team.
Recommended configuration:
- Restrict guest invitations to administrators and named roles, not all users.
- Require MFA for guests through Conditional Access — see MFA setup for Microsoft 365.
- Run Access Reviews in Microsoft Entra ID P2 so stale guests are re-confirmed or removed.
- Use private channels for sensitive topics when external guests sit in a team.
- Scope external federation to named partner domains, not "any organisation". See Microsoft's guest access guidance.
How do you secure Teams meetings?
External meetings are now the default for client and supplier calls, and anyone holding a meeting link can often join without challenge. Three controls close that gap: a lobby that holds external attendees until admitted, disabled anonymous join for sensitive calls, and recording policies that stop sessions being shared or kept forever.
- Lobby: admit only people in your organisation (and invited guests) automatically; never auto-admit dial-in callers.
- Anonymous join: disable it at tenant or policy level for internal and sensitive external meetings.
- Recordings: control who can record, who recordings auto-share with, and set expiry so they do not persist indefinitely.
Recordings inherit SharePoint and OneDrive access controls, so a single over-shared recording can expose a confidential discussion to every attendee, including guests. Treat recording governance as part of your wider data protection obligations under UK GDPR.
How do you stop sensitive data leaking from Teams?
Teams files are SharePoint and OneDrive files, so Teams sharing risk is SharePoint sharing risk. The strongest control is Microsoft Purview sensitivity labels, included in Microsoft 365 Business Premium, which can stamp a team as "Confidential" and automatically enforce its privacy, guest and external-sharing rules rather than relying on each owner to get it right.
- Apply sensitivity labels to teams to auto-configure guest and external-sharing behaviour.
- Set SharePoint external sharing to authenticated external users only — never anonymous links.
- Use Microsoft Intune compliance policies with Conditional Access to block or browser-restrict Teams on unmanaged devices; see Microsoft Intune.
- Turn on Data Loss Prevention to detect and block regulated data types leaving a chat.
How do you manage third-party app permissions in Teams?
Teams supports thousands of third-party apps, and each one requests permissions to read messages, open files, or act on a user's behalf. Left open, any user can install anything, which creates two real risks: over-permissioned apps reaching sensitive data, and OAuth consent phishing where a malicious app tricks staff into granting it access.
Bring this under governance:
- Allow only Microsoft-published apps or ones you have explicitly approved in the Teams admin centre.
- Review the global app permission policy — the default lets every user add apps.
- Use Entra ID App Governance to monitor consented permissions and flag unusual access patterns.
This pairs naturally with endpoint and identity protection from Microsoft Defender for Business, which gives you the telemetry to spot a compromised account before it abuses an app grant.
How does Teams phishing work, and how do you stop it?
As email defences improve, attackers move to Teams. Tactics include impersonation accounts using names close to real contacts, compromised supplier tenants messaging your staff through existing federation, and malicious links pasted into chat. Defence needs both technical filtering and trained scepticism — the NCSC's phishing guidance applies to Teams as much as email.
Microsoft Defender for Office 365 Safe Links can sandbox URLs inside Teams messages, but it is not always enabled for Teams by default — confirm the policy covers Teams, not just email. Defender does not read message body content the way it scans email, so user awareness remains essential: verify unexpected payment or credential requests through a known phone number, never the chat thread that made them.
What about Teams voice security and the 2025 PSTN switch-off?
Many UK firms are moving voice onto Microsoft Teams Direct Routing ahead of the 2025 PSTN switch-off, which adds voice-specific risks on top of collaboration ones. Call recordings need the same information governance as other sensitive data, SIP trunks must be configured to block toll fraud, and emergency call routing has to be verified because Teams handles it differently from a traditional line.
How much does securing Microsoft Teams cost?
The technical controls above are licensing-dependent, and the controls that matter most — Defender for Office 365 Safe Links and Purview sensitivity labels — live in Microsoft 365 Business Premium. The table below shows Microsoft's UK list prices; AMVIA's role is configuring and managing these features, not reselling licences.
| Microsoft 365 plan | Price (ex VAT, /user/mo, annual) | Teams security features included |
|---|---|---|
| Business Basic | £4.60 | Teams, core admin controls, MFA |
| Business Standard | £9.60 | Above + desktop apps |
| Business Premium | £16.90 | Above + Defender for Office 365, Purview sensitivity labels, Intune, Entra ID P1 |
Prices are Microsoft UK list prices via Microsoft 365 plans. Business Premium is the practical baseline for the Teams hardening described here.
Default Teams vs AMVIA-hardened Teams
The difference between a secure Teams tenant and an exposed one is configuration, not licensing alone. This is what changes when AMVIA takes it on.
| Area | Default Teams | AMVIA-hardened Teams |
|---|---|---|
| Guest invites | Any user can invite | Restricted to approved roles |
| Guest MFA | Not enforced | Required via Conditional Access |
| Guest review | Never | Quarterly Access Reviews |
| Anonymous meeting join | Enabled | Disabled for sensitive meetings |
| External app install | Any user | Approved apps only |
| Safe Links on Teams | Often off | Verified on |
| Sensitivity labels | Unused | Applied to confidential teams |
How does AMVIA secure Microsoft Teams?
AMVIA configures Teams security as a standard component of its managed Microsoft 365 service: one provider, security-first, Microsoft-certified engineers. We audit current Teams settings against NCSC guidance, then own the configuration and the ongoing reviews so it does not drift.
- Audit of Teams admin settings against NCSC guidance.
- Guest access policy and cleanup of stale guest accounts.
- Meeting and recording policy configuration for external calls.
- App permission governance in the Teams admin centre.
- Safe Links extended to Teams in Defender for Office 365.
- Purview sensitivity labels for Teams information protection.
- Quarterly review of guest accounts and app permissions.
Key Points
What UK businesses need to know about Microsoft Teams security.
Teams Is a Phishing Vector
Attackers use compromised accounts and guest access to send malicious links and files through Teams. Defender for Office 365 Safe Links and Safe Attachments should be extended to cover Teams.
Guest Access Needs Governance
Guest users can access channels, files, and conversations if misconfigured. Quarterly guest access reviews and clear governance policies prevent sensitive data being accessible to former guests.
Meeting Recordings Require Policy
Teams meetings capture sensitive business discussions. Recording storage, access controls, and who-can-record policies should be explicitly configured, not left at defaults.
Team Creation Needs Controls
Unrestricted team creation leads to governance sprawl — data spread across hundreds of unmanaged channels, with no visibility of external sharing or guest access granted by individual team owners.
Teams Security Checklist
Guest access configured — restricted channels, MFA required, no directory browsing
Quarterly guest access review process in place — removing unused accounts
External access (federation) configured — known partners allowed, unknown contacts blocked
Team creation policy — restricted to IT or approved requestors, not all users
Safe Links and Safe Attachments extended to Teams — scanning links and files in messages
Meeting lobby settings configured — external participants require explicit admission
Recording policies configured — storage location and access controls reviewed
Frequently Asked Questions
Yes. Teams runs on enterprise-grade infrastructure and Microsoft certifies the platform against international standards including ISO 27001, SOC 2 and GDPR requirements. Its real-world security, though, depends on configuration. Defaults favour ease of use, so hardening guest access, meetings and app permissions is what makes Teams genuinely safe for your data.
No — guests only reach files in the teams and channels they are explicitly added to, not other teams or SharePoint sites. The catch is scope: a guest invited at team level can usually see every non-private channel in that team. Use private channels for sensitive material and review guest accounts quarterly to keep access tight.
Apply Microsoft Purview sensitivity labels to teams so external sharing rules are enforced automatically, and use private channels when external guests are present. Set SharePoint external sharing to require authentication rather than anonymous links, and enable Data Loss Prevention policies to detect and block regulated content types before they leave a chat.
Partly. Defender for Office 365, included in Microsoft 365 Business Premium, provides Safe Links protection that sandboxes URLs in Teams messages, but it does not scan message body text the way it scans email. Stopping Teams-based social engineering needs both that technical control and user awareness training for staff.
In the Microsoft Entra ID portal, review the external users section to see every guest with tenant access. Entra ID P2 includes Access Reviews, which automate periodic confirmation that each guest is still needed. AMVIA runs this review quarterly as part of its managed Microsoft 365 service so accounts never accumulate unchecked.
Restrict guest invitations and enforce MFA on guests through Conditional Access. Most Teams data exposure comes from unmanaged external accounts, so controlling who can invite guests and proving those guests' identity closes the largest gap first — before you move on to meeting, recording and app permission policies.
Secure Your Microsoft Teams Environment
AMVIA configures Teams guest access, external sharing, meeting policies, and Safe Links/Safe Attachments protection as part of its managed Microsoft 365 security service.
Related Resources
Microsoft 365 Security Services
Microsoft 365 Security Services
Conditional Access in Microsoft 365
Conditional Access in Microsoft 365
Microsoft Entra ID Security
Microsoft Entra ID Security
Microsoft Intune for Business
Microsoft Intune for Business