Microsoft Teams now lets admins block external bots from meetings

Teams

Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings.

This new feature builds on another Teams policy introduced in June that added smarter bot protection, ensuring all detected bots are tagged in the lobby and require organizer approval before joining.

The new policy goes one step further and will automatically prevent external bots from joining Teams meetings, without requiring explicit organizer confirmation before they’re admitted.

image

“With this update, organizations can strengthen meeting security by configuring Teams policies to automatically block detected external meeting bots from joining meetings,” the company said in a Microsoft 365 Message Center update on Friday. “This gives administrators additional control over how identified bots are handled and can help reduce organizational risk.”

This new admin policy is rolling out as part of a targeted release until the end of August and should reach general availability worldwide by late September.

It will be available under the “Manage bots” meeting protection settings in the Teams admin center, will be off by default, and will require admin activation and evaluation before deployment.

After being enabled, the policy can be assigned to specific users or groups through existing Teams meeting policy management, and all identified external meeting bots will be blocked from joining meetings governed by the newly assigned policy.

The change ensures that third-party bots (which can have various uses, from note-taking and transcription to other automated tasks) and malicious apps controlled by threat actors cannot join Teams meetings without attendees and organizers realizing that a non-human participant has been added.

As Microsoft warned in April, attacks abusing Teams for access and lateral movement on enterprise networks are surging, with threat actors impersonating IT or helpdesk staff to contact employees via cross-tenant chats and trick them into granting remote access to steal data.

Since December, admins can also block external Teams users via the Defender portal to thwart cybercrime gangs (including ransomware groups) attempting to abuse Teams in social engineering attacks targeting victims’ employees.

As announced in June, Microsoft is also planning to add additional admin controls, including policies to block external bots entirely, allow lists for approved bots, admin reports and audit logs on bot detection and presence, and more granular controls for different security requirements.​

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report