Microsoft Teams Phishing Protection: Settings That Matter
Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.
Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.
Microsoft Teams phishing is a social engineering attack that arrives as a chat or call instead of an email. Attackers pose as IT support, and email filters never see the message. The fix has four parts: restrict external access, add detection, train staff for chat and voice, and give people a fast way to report.
Table of Contents
ToggleMost companies have spent years defending the inbox. Filters scan links, block known bad senders, and flag odd attachments. Chat has received far less attention. Yet staff trust it more, because Teams feels like an internal space.
That trust is the weak point. Microsoft says the default Teams setting, allow all external domains, lets people outside your company find, call, and chat with your staff. An attacker only needs a Microsoft 365 tenant, which is cheap to create. Then they can message an employee directly, often under a name like “Help Desk.”
Threatcop has also written about how hackers impersonate technical support in Microsoft Teams. So this guide focuses on the defense: what to change, what to watch, and what to teach.
Several groups use the same Teams phishing playbook. Microsoft tracks one of them as Storm-1811, a Black Basta ransomware affiliate. Sophos reported a similar cluster in early 2025. Russian state group Midnight Blizzard has also used Teams messages from compromised accounts that posed as IT support. A summary of the campaigns shows how the steps fit together.
Here is the typical chain, seen from the attacker’s side and from the employee’s side.
| Stage | What the attacker does | What the employee sees |
|---|---|---|
| 1. Flood | Signs the victim up to hundreds of mailing lists | An inbox full of junk |
| 2. Contact | Chats or calls on Teams as “IT support” | Someone offering to fix the spam |
| 3. Access | Asks the employee to open a remote-help tool | A helpful guide to “solve” it |
| 4. Takeover | Steals data and installs malware | A screen that seems to work |
The takeaway is simple: the attack works because the problem and the rescue both come from the attacker. Your employee never contacted IT, and a real helpdesk would not cold-chat them.
Other lures follow the same pattern. In the anatomy of a phishing scam, an attacker builds urgency and borrows trust, and Teams just gives the attacker a new place to do it.
Discover how Threatcop protects your workforce from modern cyber threats.
The single biggest fix is a setting, so start there. In the Teams admin center, external access has several modes, and the table compares them.
| Setting | What it allows | Risk | When to use it |
|---|---|---|---|
| Allow all external domains (default) | Anyone on any Microsoft 365 domain can contact staff | High | Rarely |
| Allow only specific external domains | Only the partners you list | Low | Most companies |
| Block only specific external domains | Everyone except the domains you list | Medium to high | As a backup only |
| Block all external domains | No external chat or calls | Lowest | High-risk teams |
| Chat with unmanaged Teams accounts | Personal Microsoft accounts can chat | High | Only if needed |
An allow list works best, because you cannot list every attacker in advance. However, Microsoft also notes two limits. Blocking a domain does not block its subdomains. And blocked domains can still join meetings anonymously if anonymous access is on. So review both settings together. Roll the change out in stages, too. Start with a pilot group, then widen it, so a missed partner does not stop real work.
Calls and meetings need the same care as chat. An outside caller can start a call, share a screen, or send a meeting link, and each step builds false trust. So decide who may call your staff, not only who may type to them. Check the anonymous meeting setting too.
Treat this as a zero trust decision. Do not trust a message just because it appears inside Teams. Start with the allow list, then widen it only when a business need appears.
Settings reduce exposure, but they do not catch everything. So turn on the protections your Microsoft 365 plan includes for Teams. Teams already shows external tags, first-contact accept or block prompts, and some phishing warnings, as Socura’s threat alert explains. Check that they are switched on and that staff understand them.
Also control the tool that attackers ask for. For example, remove Quick Assist from computers that do not need it. Alert on remote-help sessions that involve privileged users. These steps cost little, and they break the last link in the chain.
Finally, give people an easy way to report. Where your tenant offers it, let users flag suspicious Teams messages. Then make sure each report reaches someone who can act. Closing the gap between people security and incident response turns a single report into a fast response.
Email training alone leaves a gap in Microsoft Teams phishing defense. Staff need to practice against chat and voice, because that is where this attack lives. Teach five warning signs:
The safe response is always the same. Stop, hang up or close the chat, and contact IT through a number or ticket system you already know. Then report the attempt.
Practice makes this stick, because one-time training fades. A voice phishing simulation lets teams rehearse the callback habit in a safe setting. Then repeat it each quarter.
Speed matters in a Teams phishing incident. If an employee reports that a chat contact asked for remote access, act at once. First, ask them to disconnect the remote session and close the tool. Next, isolate the computer from the network. Then reset the employee’s passwords and revoke their active sessions, because attackers often steal them early. Also check for new remote-help tools, new accounts, and unusual sign-ins. Finally, record what happened and share the pattern with staff. A short, blame-free note helps the next person spot the same trick.
You can reduce most of the risk in five working days.
Then schedule a quarterly check, because settings drift and new tools appear.
Teams phishing works because attackers follow trust, and right now trust sits in chat. Restrict who can contact your staff, remove the tools attackers ask for, and teach people to verify before they act. A one-click reporting workflow builds the same habit for email, and the same rule should apply in Teams.
Yes. Attackers send phishing links and fake support requests through Teams chats and calls. Because the message arrives outside email, email filters often never see it. Staff also tend to trust Teams more than the inbox.
Attackers usually create their own Microsoft 365 tenant, then message staff in Microsoft Teams from an outside domain. Others use compromised accounts at partner companies. The default setting that allows all external domains makes both routes easy.
In the Teams admin center, open external access and change the setting from allow all domains to allow only specific domains. Add the partners you work with. Also review the setting for personal Microsoft accounts and for anonymous meeting access.
For a suspicious Microsoft Teams message, staff should stop engaging, then report it to the security team through whatever channel you set up. Where your tenant allows it, a built-in report option helps. The key is a simple, blame-free path that ends with someone who can act.
Not by itself. Email filters scan email, so a Teams message can bypass them. Microsoft Teams needs its own settings, detection, and reporting. Training also matters, since attackers target the person, not the tool.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Law firms lose client data through misdirected email and payment fraud. See the three biggest email security challenges and...
Banks across EMEA face phishing, supplier breaches, and ransomware downtime. See the main threats and the controls that cut...
The same training for everyone bores some staff and overwhelms others. See how to segment by role, tenure, and...
Table of Contents
×