Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review and test new Teams setting: control of tenant users joining externally hosted Teams meetings #1320

Closed
1 task
rmoffitt-m opened this issue Sep 19, 2024 · 2 comments
Assignees
Labels
baseline-document Issues relating to the text in the baseline documents themselves hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping microsoft roadmap Issues relating to Microsoft's roadmap.
Milestone

Comments

@rmoffitt-m
Copy link
Collaborator

💡 Summary

Microsoft added a feature in May of 2024 to allow tenant administrators to control whether some users can join externally hosted Teams meetings. Consider adding a policy to check these settings.

The Microsoft roadmap feature related to this issue has ID 187230.

Motivation and context

As per Microsoft, "This capability can be used by the tenant admins to protect potential data exfiltration from specific user groups within their organization."

Implementation notes

Acceptance criteria

How do we know when this work is done?

  • Determine an update to Teams baseline to include the new setting
@rmoffitt-m rmoffitt-m added baseline-document Issues relating to the text in the baseline documents themselves microsoft roadmap Issues relating to Microsoft's roadmap. labels Sep 19, 2024
@adhilto
Copy link
Collaborator

adhilto commented Sep 23, 2024

See https://github.com/cisagov/ScubaGoggles/blob/main/baselines/meet.md#gwsmeet21v03 for the equivalent GWS baseline policy.

@schrolla schrolla added this to the Kraken milestone Sep 23, 2024
@schrolla schrolla changed the title Update baseline to include control of tenant users joining externally hosted Teams meetings Review and test new Teams setting: control of tenant users joining externally hosted Teams meetings Nov 6, 2024
@schrolla schrolla added the hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping label Nov 6, 2024
@schrolla schrolla modified the milestones: Kraken, Lionfish Nov 6, 2024
@nanda-katikaneni nanda-katikaneni self-assigned this Jan 2, 2025
@nanda-katikaneni
Copy link
Collaborator

nanda-katikaneni commented Jan 27, 2025

Reviewed and tested the new Teams config options to restrict tenant users joining externally hosted Teams meetings: this needs adding an additional Meeting Policy guidance to Teams SCB's. The details of the proposal new policy is below:

MS.TEAMS.1.8v1: Tenant users SHOULD be restricted in joining externally organized Teams meetings - they SHOULD be allowed to only meetings organized by 'People in Trusted Organizations'.

Rationale:
Allowing M365 tenant users to join externally organized meetings presents security concerns primarily because it exposes agencies/organizations to potential data leaks and malware risks from untrusted external domains. Tenant user joining meetings organized by unmanaged users can pose the risk of data leakage and other security threats. This policy provides protection by disabling internal user joining meetings from unmnaged/unknown users.

Implementation steps:

  1. In the Teams Meeting Policies, update Global Policy with following change:
  2. For "People can join external meetings hosted by" change the option from default "Anyone" to "Only people in trusted organizations".
  3. Under the Users, select the "Trusted domain config", ensure that trusted domains are configured (similar to MS.TEAMS.2.3v1)

ScubaGear impact:
The proposed new policy will require two config checks; ScubaGear need to be enhanced with thise two checks.

Course of action:
A new issue will be added to track both baseline document changes and ScubaGear code updates. The new issue will be trageted to Marlin release (#1540 ).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
baseline-document Issues relating to the text in the baseline documents themselves hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping microsoft roadmap Issues relating to Microsoft's roadmap.
Projects
None yet
Development

No branches or pull requests

4 participants