
Turn on a Teams External access allowlist today. Attackers have moved into Teams chat and Teams calls because your mail filter never sees them, and most small businesses still have Teams set to accept messages from every domain on the internet. The fix takes an afternoon and costs nothing.
Three settings, in this order:
- Teams admin center, External access: switch from all domains to an allowlist of your real vendors.
- Same screen: turn off chat with unmanaged personal Teams accounts, and with Skype users.
- Remove or block Quick Assist and any remote-access tool your help desk doesn't use.
Why did attackers move to Teams?
Because Teams skips the layer you already paid for. Email hits Exchange Online Protection, Safe Links and whatever gateway you run in front of it. A Teams chat from an outside tenant lands straight in an employee's window with a Microsoft-branded interface around it, and it looks like every other internal message they get all day.
Microsoft's Q2 2026 email threat report put numbers on it. Detected Teams phishing attacks rose 19% from March to April, held flat in May, then rose another 10% into June.
Voice phishing is the steeper curve. Weekly vishing attempts across all of Microsoft's telemetry, not Teams alone, now "run at nearly ten times the mid-2025 baseline," and the last two weeks of June set the two highest weekly records Microsoft has logged.
The disguise got better too. In the same report, Microsoft found 52% of June's Teams phishing attacks used generic display names instead of obvious IT-support impersonation, shifting away from support-themed domains toward SaaS-sounding ones. So "watch out for anyone claiming to be IT" is no longer useful advice.
What does a Teams attack actually look like?
A stranger messages or calls an employee, claims to be IT or a vendor, and talks them into granting remote control. Microsoft published a real case in March 2026: an actor impersonated IT support, struck out with two employees, then "convinced a third user to grant remote access through Quick Assist, enabling the initial compromise of a corporate device."
From there the user was walked to a fake sign-in page, entered credentials, and pulled down a malicious MSI that sideloaded a DLL through trusted Windows mechanisms.
No exploit. No malware attachment. One helpful employee and a built-in Windows tool.
Read that chain again and notice what stopped nothing: your firewall, your spam filter, your endpoint agent's file scanning. The entry point was a conversation.
How do I block external Teams messages?
Teams admin center, External access, switch from allowing all domains to an allowlist. Microsoft's own description is blunt: "By adding domains to an Allow list, you limit external access to only the allowed domains. Once you set up a list of allowed domains, all other domains are blocked."
Add your real vendors, accountant and outside counsel. Everyone else is done.
Two more switches on the same screen, both worth flipping:
- Chat with external Teams users not managed by an organization. This is the personal-Teams-account door. Turn it off. Legitimate vendors have a work tenant.
- Chat and calls with Skype users. Off. Microsoft still exposes the toggle, and nothing in your business depends on it.
Then test it. Have someone at a domain you did not allowlist try to start a chat with one of your users, and confirm it fails. Settings changes here aren't always instant, so if the first attempt still goes through, wait and try again before assuming you misconfigured something.
People will object that an allowlist creates friction. It does, roughly once a month, when someone new needs adding. That's a two-minute ticket weighed against the channel your attackers are actively using.
Block Quick Assist while you're in there
Quick Assist ships with Windows, needs no admin rights to run, and hands a stranger your screen and keyboard in a handful of clicks. Microsoft's guidance after that March incident was to "review their use of remote monitoring and management tools, inventory what is truly required, and remove or disable utilities—such as Quick Assist—where they are unnecessary."
Quick Assist is a Store app now, so Group Policy won't uninstall it. Microsoft documents two working approaches: remove the package with Get-AppxPackage -Name MicrosoftCorporationII.QuickAssist | Remove-AppxPackage -AllUsers, or block traffic to the remoteassistance.support.services.microsoft.com endpoint, which stops Quick Assist sessions outright. The endpoint block is the more durable of the two, since a removed Store app can come back. It also breaks Microsoft Remote Help, so check whether your help desk uses that first.
If your team does use Quick Assist, decide that on purpose and tell staff which tool is the real one. An employee who knows your help desk only ever uses one named tool has a script for saying no.
Same logic applies to the rest of the remote-access pile: TeamViewer, AnyDesk, LogMeIn, ScreenConnect. Inventory what's installed. Most of it got put there once, for one problem, years ago.
What locking down External access doesn't fix
External access is one door of several, and closing it leaves the others open. The other two that matter are guest access and B2B direct connect, which govern shared channels, and both live in Entra cross-tenant access settings rather than on the Teams External access screen. Microsoft is explicit that External access doesn't grant access to your teams or channels at all.
Meeting joins are a third path, governed by your Teams meeting policies. So don't tell staff that outsiders can't reach them in Teams. Tell them outsiders can't start a chat.
Audit all of it. A tight External access allowlist next to a shared channel open to any tenant is a locked front door beside an open window.
An allowlist also can't stop a compromised partner account, and partner accounts are exactly what a domain allowlist trusts. That's why the rest of the stack still matters: conditional access policies that block sign-ins from unmanaged devices, and a help desk that verifies who's calling before it resets anything.
And tell your staff the specific thing, not the general thing. "Nobody from IT will ever ask you to start a screen-sharing session" beats an hour on email red flags they've heard four times, whatever awareness training costs you per seat.
Frequently asked questions
Can someone outside my company message me on Teams by default?
Yes. Microsoft's default is "Allow all external domains", which lets anyone in any Microsoft 365 tenant find your users and start a chat or call. Most small businesses have never changed it, because nothing about the default announces itself. It's under External access in the Teams admin center.
Does Defender for Office 365 scan Teams messages?
Safe Links covers links in Teams, once your Safe Links policy is set to include it. Microsoft documents the scope as "Safe Links protection for links in Teams conversations, group chats, or from channels". Malicious files are a separate feature, Safe Attachments. Neither catches a plain-text message talking someone into a screen-share, which is the attack pattern in Microsoft's reporting.
Is blocking all external Teams access better than an allowlist?
Block-all is safer and it breaks real work. If your team collaborates with outside firms in Teams, an allowlist gets most of the protection without the help desk calls. Block-all makes sense for a small office whose external contact happens entirely over email and phone.
How long does this take to set up?
Under an hour for the Teams settings themselves. The real work is building the vendor list, which means asking your team who they actually talk to outside the company. Budget an afternoon, then revisit the list twice a year as vendors come and go.
We're on Microsoft 365 Business Premium. Do we have what we need?
Yes. External access controls are part of Teams itself, and Business Premium includes Microsoft Defender for Office 365 Plan 1 plus the conditional access you'd want behind it. This is a configuration problem, not a licensing one.
If you'd rather not audit your Teams tenant, remote-access tools and cross-tenant settings yourself, get in touch for a free risk assessment. We'll tell you what's open and what it would take to close it, whether or not you hire us to do it.
Discuss security awareness & phishing training for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



