Legal

By default, Teams lets any outside organization message your firm

Microsoft's threat researchers published findings on September 2 that should change how your firm thinks about Teams.

1 min readOriginally posted on LinkedIn

Microsoft's threat researchers published findings on September 2 that should change how your firm thinks about Teams.

Attackers aren't just emailing anymore. They're messaging your people in Teams, from outside your organization, posing as your IT help desk. The pretext is boring on purpose — a security update, an account about to be deactivated. They talk someone into clicking past the external-contact warning and handing over a remote session. From there they move deeper into the network.

Here's the part most firms don't know: out of the box, Teams lets anyone at any other organization chat and call your people. That's the default setting. Nobody turned it on, and nobody turned it off.

Picture the associate at 6pm prepping a filing who gets a Teams call from "IT" about an account problem. One click. Now you're having a conversation with clients about whose matter files were touched, and a conversation with your carrier at renewal about what controls you actually had.

The fix isn't dramatic. Limit external Teams chat to the domains you actually work with — co-counsel, your accountant, your vendors. And make one rule stick: nobody grants remote access from an inbound message. You call IT back on the number you already have.

Worth a look before your next cyber renewal. It's a settings review, not a project.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions