{"id":15542,"date":"2026-10-05T12:12:26","date_gmt":"2026-10-05T06:42:26","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15542"},"modified":"2026-10-05T12:12:29","modified_gmt":"2026-10-05T06:42:29","slug":"microsoft-teams-phishing-protection","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/","title":{"rendered":"Microsoft Teams Phishing Protection: Settings That Matter"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Microsoft Teams phishing is a social engineering attack that arrives as a chat or call instead of an email. Attackers pose as IT support, and email filters never see the message. The fix has four parts: restrict external access, add detection, train staff for chat and voice, and give people a fast way to report.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Why_Attackers_Moved_From_Email_to_Chat\" >Why Attackers Moved From Email to Chat<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#How_a_Typical_Teams_Helpdesk_Attack_Works\" >How a Typical Teams Helpdesk Attack Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Lock_Down_External_Access_First\" >Lock Down External Access First<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Add_Detection_and_Reporting\" >Add Detection and Reporting<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Train_Staff_for_Chat_and_Voice\" >Train Staff for Chat and Voice<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#If_You_Suspect_an_Active_Attack\" >If You Suspect an Active Attack<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#A_One-Week_Action_Plan\" >A One-Week Action Plan<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#The_Bottom_Line\" >The Bottom Line<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Attackers_Moved_From_Email_to_Chat\"><\/span>Why Attackers Moved From Email to Chat<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most companies have spent years defending the inbox. Filters scan links, block known bad senders, and flag odd attachments. Chat has received far less attention. Yet staff trust it more, because Teams feels like an internal space.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That trust is the weak point. Microsoft says the default Teams setting, <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoftteams\/manage-external-access\" rel=\"nofollow noopener\" target=\"_blank\">allow all external domains<\/a>, lets people outside your company find, call, and chat with your staff. An attacker only needs a Microsoft 365 tenant, which is cheap to create. Then they can message an employee directly, often under a name like &#8220;Help Desk.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop has also written about <a href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-attack\/\">how hackers impersonate technical support in Microsoft Teams<\/a>. So this guide focuses on the defense: what to change, what to watch, and what to teach.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_a_Typical_Teams_Helpdesk_Attack_Works\"><\/span>How a Typical Teams Helpdesk Attack Works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Several groups use the same Teams phishing playbook. Microsoft tracks one of them as Storm-1811, a Black Basta ransomware affiliate. Sophos reported a similar cluster in early 2025. Russian state group Midnight Blizzard has also used Teams messages from compromised accounts that posed as IT support. A <a href=\"https:\/\/www.uctoday.com\/unified-communications\/cyber-security-alert-how-ransomware-gangs-exploit-microsoft-teams\/\" rel=\"nofollow noopener\" target=\"_blank\">summary of the campaigns<\/a> shows how the steps fit together.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the typical chain, seen from the attacker&#8217;s side and from the employee&#8217;s side.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Stage<\/strong><\/th><th><strong>What the attacker does<\/strong><\/th><th><strong>What the employee sees<\/strong><\/th><\/tr><\/thead><tbody><tr><td>1. Flood<\/td><td>Signs the victim up to hundreds of mailing lists<\/td><td>An inbox full of junk<\/td><\/tr><tr><td>2. Contact<\/td><td>Chats or calls on Teams as &#8220;IT support&#8221;<\/td><td>Someone offering to fix the spam<\/td><\/tr><tr><td>3. Access<\/td><td>Asks the employee to open a remote-help tool<\/td><td>A helpful guide to &#8220;solve&#8221; it<\/td><\/tr><tr><td>4. Takeover<\/td><td>Steals data and installs malware<\/td><td>A screen that seems to work<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The takeaway is simple: the attack works because the problem and the rescue both come from the attacker. Your employee never contacted IT, and a real helpdesk would not cold-chat them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other lures follow the same pattern. In the <a href=\"https:\/\/threatcop.com\/blog\/anatomy-of-a-phishing-scam-how-email-attacks-really-work\/\">anatomy of a phishing scam<\/a>, an attacker builds urgency and borrows trust, and Teams just gives the attacker a new place to do it.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Lock_Down_External_Access_First\"><\/span>Lock Down External Access First<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The single biggest fix is a setting, so start there. In the Teams admin center, external access has several modes, and the table compares them.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Setting<\/strong><\/th><th><strong>What it allows<\/strong><\/th><th><strong>Risk<\/strong><\/th><th><strong>When to use it<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Allow all external domains (default)<\/td><td>Anyone on any Microsoft 365 domain can contact staff<\/td><td>High<\/td><td>Rarely<\/td><\/tr><tr><td>Allow only specific external domains<\/td><td>Only the partners you list<\/td><td>Low<\/td><td>Most companies<\/td><\/tr><tr><td>Block only specific external domains<\/td><td>Everyone except the domains you list<\/td><td>Medium to high<\/td><td>As a backup only<\/td><\/tr><tr><td>Block all external domains<\/td><td>No external chat or calls<\/td><td>Lowest<\/td><td>High-risk teams<\/td><\/tr><tr><td>Chat with unmanaged Teams accounts<\/td><td>Personal Microsoft accounts can chat<\/td><td>High<\/td><td>Only if needed<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">An allow list works best, because you cannot list every attacker in advance. However, Microsoft also notes two limits. Blocking a domain does not block its subdomains. And blocked domains can still join meetings anonymously if anonymous access is on. So review both settings together. Roll the change out in stages, too. Start with a pilot group, then widen it, so a missed partner does not stop real work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Calls and meetings need the same care as chat. An outside caller can start a call, share a screen, or send a meeting link, and each step builds false trust. So decide who may call your staff, not only who may type to them. Check the anonymous meeting setting too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Treat this as a <a href=\"https:\/\/threatcop.com\/blog\/zero-trust-security\/\">zero trust<\/a> decision. Do not trust a message just because it appears inside Teams. Start with the allow list, then widen it only when a business need appears.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Add_Detection_and_Reporting\"><\/span>Add Detection and Reporting<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Settings reduce exposure, but they do not catch everything. So turn on the protections your Microsoft 365 plan includes for Teams. Teams already shows external tags, first-contact accept or block prompts, and some phishing warnings, as <a href=\"https:\/\/socura.co.uk\/threat-alerts\/weaponisation-of-microsoft-teams-for-it-support-vishing-and-enterprise-ransomware-deployment\" rel=\"nofollow noopener\" target=\"_blank\">Socura&#8217;s threat alert<\/a> explains. Check that they are switched on and that staff understand them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also control the tool that attackers ask for. For example, remove Quick Assist from computers that do not need it. Alert on remote-help sessions that involve privileged users. These steps cost little, and they break the last link in the chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, give people an easy way to report. Where your tenant offers it, let users flag suspicious Teams messages. Then make sure each report reaches someone who can act. <a href=\"https:\/\/threatcop.com\/blog\/integrating-people-security-into-incident-response-playbooks\/\">Closing the gap between people security and incident response<\/a> turns a single report into a fast response.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Train_Staff_for_Chat_and_Voice\"><\/span>Train Staff for Chat and Voice<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Email training alone leaves a gap in Microsoft Teams phishing defense. Staff need to practice against chat and voice, because that is where this attack lives. Teach five warning signs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Contact you did not ask for, from an outside &#8220;IT&#8221; account.<\/strong> Real IT works through tickets and known channels.<\/li>\n\n\n\n<li><strong>An offer to fix a problem you never reported.<\/strong> A sudden spam flood followed by an offer to help is a classic setup.<\/li>\n\n\n\n<li><strong>Any request to open a remote-help tool.<\/strong> That tool gives someone control of your computer.<\/li>\n\n\n\n<li><strong>Any ask for a password or MFA code.<\/strong> IT never needs either.<\/li>\n\n\n\n<li><strong>Pressure to act fast.<\/strong> Urgency is how attackers stop you from checking.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The safe response is always the same. Stop, hang up or close the chat, and contact IT through a number or ticket system you already know. Then report the attempt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Practice makes this stick, because one-time training fades. A <a href=\"https:\/\/threatcop.com\/ai-vishing-attack-simulation\">voice phishing simulation<\/a> lets teams rehearse the callback habit in a safe setting. Then repeat it each quarter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"If_You_Suspect_an_Active_Attack\"><\/span>If You Suspect an Active Attack<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Speed matters in a Teams phishing incident. If an employee reports that a chat contact asked for remote access, act at once. First, ask them to disconnect the remote session and close the tool. Next, isolate the computer from the network. Then reset the employee&#8217;s passwords and revoke their active sessions, because attackers often steal them early. Also check for new remote-help tools, new accounts, and unusual sign-ins. Finally, record what happened and share the pattern with staff. A short, blame-free note helps the next person spot the same trick.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_One-Week_Action_Plan\"><\/span>A One-Week Action Plan<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You can reduce most of the risk in five working days.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Day 1.<\/strong> Open the Teams admin center and record your current external access setting.<\/li>\n\n\n\n<li><strong>Day 2.<\/strong> Switch to an allow list of known partners, or block external access for high-risk groups.<\/li>\n\n\n\n<li><strong>Day 3.<\/strong> Remove or restrict Quick Assist on machines that do not need it.<\/li>\n\n\n\n<li><strong>Day 4.<\/strong> Turn on user reporting and confirm where reports go.<\/li>\n\n\n\n<li><strong>Day 5.<\/strong> Send staff a short note about fake helpdesk chats and the callback rule, as one step in a wider <a href=\"https:\/\/threatcop.com\/blog\/best-phishing-awareness-training-programs-for-employees\/\">phishing awareness training<\/a> plan.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Then schedule a quarterly check, because settings drift and new tools appear.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Bottom_Line\"><\/span>The Bottom Line<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Teams phishing works because attackers follow trust, and right now trust sits in chat. Restrict who can contact your staff, remove the tools attackers ask for, and teach people to verify before they act. A <a href=\"https:\/\/threatcop.com\/threatcop-phishing-incident-response\">one-click reporting workflow<\/a> builds the same habit for email, and the same rule should apply in Teams.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-ef485c566d09\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-195f2cc76d6b\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-566d09\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-566d09'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tCan Microsoft Teams be used for phishing?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-566d09'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Yes. Attackers send phishing links and fake support requests through Teams chats and calls. Because the message arrives outside email, email filters often never see it. Staff also tend to trust Teams more than the inbox.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-abe20bb619ab\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-566d09\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-566d09'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow do attackers contact employees in Teams?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-566d09'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Attackers usually create their own Microsoft 365 tenant, then message staff in Microsoft Teams from an outside domain. Others use compromised accounts at partner companies. The default setting that allows all external domains makes both routes easy.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-7206e08c7c54\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-566d09\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-566d09'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow do I restrict external access in Teams?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-566d09'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">In the Teams admin center, open external access and change the setting from allow all domains to allow only specific domains. Add the partners you work with. Also review the setting for personal Microsoft accounts and for anonymous meeting access.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-62caf460326b\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-566d09\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-566d09'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow can staff report a suspicious Teams message?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-566d09'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">For a suspicious Microsoft Teams message, staff should stop engaging, then report it to the security team through whatever channel you set up. Where your tenant allows it, a built-in report option helps. The key is a simple, blame-free path that ends with someone who can act.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-e9802b4a71c1\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-566d09\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-566d09'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tDoes email security protect Teams?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-566d09'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Not by itself. Email filters scan email, so a Teams message can bypass them. Microsoft Teams needs its own settings, detection, and reporting. Training also matters, since attackers target the person, not the tool.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.<\/p>\n","protected":false},"author":30,"featured_media":15545,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42],"tags":[],"class_list":["post-15542","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-awareness"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Teams Phishing Protection: Settings That Matter<\/title>\n<meta name=\"description\" content=\"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Teams Phishing Protection: Settings That Matter\" \/>\n<meta property=\"og:description\" content=\"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-05T06:42:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-05T06:42:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Arpit Rao\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Arpit Rao\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/\"},\"author\":{\"name\":\"Arpit Rao\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/659c5669ff38838b35393cf8aec039e0\"},\"headline\":\"Microsoft Teams Phishing Protection: Settings That Matter\",\"datePublished\":\"2026-10-05T06:42:26+00:00\",\"dateModified\":\"2026-10-05T06:42:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/\"},\"wordCount\":1428,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Microsoft-Teams-Phishing-Protection-blog-banner.png\",\"articleSection\":[\"Cybersecurity Awareness\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/\",\"name\":\"Microsoft Teams Phishing Protection: Settings That Matter\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Microsoft-Teams-Phishing-Protection-blog-banner.png\",\"datePublished\":\"2026-10-05T06:42:26+00:00\",\"dateModified\":\"2026-10-05T06:42:29+00:00\",\"description\":\"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Microsoft-Teams-Phishing-Protection-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Microsoft-Teams-Phishing-Protection-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Microsoft Teams Phishing Protection, Settings That Matter, over an abstract network graph on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/microsoft-teams-phishing-protection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Teams Phishing Protection: Settings That Matter\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/659c5669ff38838b35393cf8aec039e0\",\"name\":\"Arpit Rao\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_30_1790166707-96x96.png\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_30_1790166707-96x96.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/avatar_user_30_1790166707-96x96.png\",\"caption\":\"Arpit Rao\"},\"description\":\"Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Teams Phishing Protection: Settings That Matter","description":"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft Teams Phishing Protection: Settings That Matter","og_description":"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.","og_url":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-10-05T06:42:26+00:00","article_modified_time":"2026-10-05T06:42:29+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png","type":"image\/png"}],"author":"Arpit Rao","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Arpit Rao","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/"},"author":{"name":"Arpit Rao","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/659c5669ff38838b35393cf8aec039e0"},"headline":"Microsoft Teams Phishing Protection: Settings That Matter","datePublished":"2026-10-05T06:42:26+00:00","dateModified":"2026-10-05T06:42:29+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/"},"wordCount":1428,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png","articleSection":["Cybersecurity Awareness"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/","url":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/","name":"Microsoft Teams Phishing Protection: Settings That Matter","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png","datePublished":"2026-10-05T06:42:26+00:00","dateModified":"2026-10-05T06:42:29+00:00","description":"Attackers now pose as IT support in Teams chats, outside email filters. Learn the settings, detection, and training that stop Teams phishing.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/10\/Microsoft-Teams-Phishing-Protection-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Microsoft Teams Phishing Protection, Settings That Matter, over an abstract network graph on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/microsoft-teams-phishing-protection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Microsoft Teams Phishing Protection: Settings That Matter"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/659c5669ff38838b35393cf8aec039e0","name":"Arpit Rao","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_30_1790166707-96x96.png","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_30_1790166707-96x96.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/avatar_user_30_1790166707-96x96.png","caption":"Arpit Rao"},"description":"Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.","sameAs":["https:\/\/threatcop.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15542"}],"version-history":[{"count":2,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15542\/revisions"}],"predecessor-version":[{"id":15548,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15542\/revisions\/15548"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15545"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}