Microsoft is rolling out a new meeting protection policy for Teams that lets administrators automatically block all identified external bots from joining meetings. The feature, announced in a Microsoft 365 Message Center update, is designed to give organizations more control over non-human participants and reduce security risks. It builds on a policy introduced in June that tagged detected bots in the lobby and required organizer approval before they could enter. The new setting removes that step, preventing external bots from joining without any explicit confirmation.

The policy will appear under the "Manage bots" meeting protection settings in the Teams admin center. It will be off by default, meaning admins must activate it and evaluate it before deployment. Once enabled, it can be assigned to specific users or groups through existing Teams meeting policy management. Any identified external bot will then be blocked from meetings governed by that policy.

The change addresses both legitimate and malicious uses of bots. Third-party bots are often used for note-taking, transcription, or other automated tasks, but threat actors can also deploy malicious apps that join meetings without attendees realizing a non-human participant is present. By blocking these bots automatically, Microsoft aims to prevent unauthorized access through Teams.

The rollout is part of a targeted release that should continue through the end of August, with general availability worldwide expected by late September. The company has been warning about Teams-based attacks for months. In April, Microsoft noted a surge in attacks abusing Teams for access and lateral movement on enterprise networks, with threat actors impersonating IT or helpdesk staff to trick employees into granting remote access.

Since December, admins have had the option to block external Teams users via the Defender portal to counter cybercrime gangs, including ransomware groups, that use Teams in social engineering attacks. Microsoft first announced plans for this new bot policy in June, along with other upcoming controls. Those include allow lists for approved bots, admin reports and audit logs on bot detection and presence, and more granular security settings.

The new policy is part of a broader push to tighten meeting security as organizations increasingly rely on the platform for remote work. The default-off setting gives admins time to assess how the policy affects their environments before rolling it out widely. Microsoft said the move gives administrators additional control over how identified bots are handled, helping to reduce organizational risk.

More cybersecurity news from TechManNews.