Skip to main content
Cybersecurity

Microsoft Teams Phishing: The Inbox Is Not the Only Door

Microsoft Teams Phishing: The Inbox Is Not the Only Door

Here’s the short version: Microsoft Teams phishing is real because chats, files, and meeting links do not go through DMARC. Email authentication will not save you. External access, leftover guests, and “the IT person in chat” will.

Teams is where work happens for a lot of small firms. That makes it a second inbox. Attackers noticed. They send a file, a meeting, or a “your account will be locked” chat from outside the tenant. SPF never runs. The costume is a display name.

Microsoft documents Defender support for Teams in Microsoft Defender for Office 365 support for Microsoft Teams and Safe Links policies. Those features help. They are not on by magic in every SKU, and they do not replace an external-access decision.

If your only anti-phish story is DMARC and email security, you have a hole in the sidebar.

Why Teams is a good phishing channel

Email has costumes (lookalike domains) and checks (SPF, DKIM, DMARC). Teams has display names, guests, and federation. A message can look like a coworker, a vendor, or “Microsoft support” without ever touching your MX.

Files in Teams live in SharePoint. A malicious file in a channel is a SharePoint object with a friendly wrapper. Safe Attachments for SharePoint, OneDrive, and Teams is the control that scans those, if you licensed it and turned it on.

The IC3 still reports BEC as a money problem. The channel is expanding. The callback habit has to expand with it. A wire instruction in Teams is still a wire instruction.

Guest access versus external access

These two get mixed up in every tenant review.

Guest access puts an Entra guest in a team. Microsoft’s guest access in Teams is the admin reference. Guests inherit whatever the team can see. They also linger after the project. Offboarding has to include guests, not only employees. See employee offboarding.

External access (federation) lets people outside chat with you without joining a team. Microsoft’s trusted organizations and manage external access pages are the knobs. Open federation with unmanaged Teams accounts is how a stranger DMs your bookkeeper.

SettingWhat it is good forDefault failure
Guests in a client teamReal projectsNever expire, too much access
External access, specific domainsKnown partner tenantsEveryone on the internet
Unmanaged external accountsAlmost nothing for a law or finance office“IT support” chats

Law firms and brokerages should start from deny-external, then allow named partners. “We might need it” is not a policy.

Remote worker with headset and laptop
Treat unexpected Teams chats like unexpected email

What a Teams phish looks like in a small office

Typical patterns we actually see:

  • A chat from “IT” asking you to approve a sign-in or open a page to keep your account.
  • A file named “Invoice” or “Updated wiring” in a channel you do not usually use.
  • A meeting link that is not on the calendar the office manager runs.
  • A guest who was added for a closed deal and now shares a link.

None of these need malware if they get a password or an Authenticator approve. MFA still matters. Number matching and phishing-resistant methods matter more when the prompt arrives during a fake Teams panic.

Business email compromise playbooks that only mention Outlook are incomplete. Add one line: “Unexpected Teams chat about money or passwords is a phone call, not a click.”

Controls that actually cut it

  1. Decide federation. Most 20-person professional firms can block external access except a short allowlist. Do that before you buy another filter.
  2. Expire guests. 90 days with an owner, or they go. Vendor risk applies to Teams guests too.
  3. Safe Links and Safe Attachments for Teams, if licensed. Confirm they are on for Teams, not only mail.
  4. MFA and Conditional Access so a stolen password is not enough, even if the chat was convincing.
  5. Sharing defaults so a channel file is not an Anyone-link. Copilot and search will make oversharing louder later. See Microsoft 365 Copilot security.
  6. A callback rule for money and credentials, including chat.

Defender for Office 365 features that mention Teams are listed in Microsoft’s MDO-for-Teams article. If you are on Business Premium, check which of those you actually have. Do not assume the brand name on the invoice enabled the Teams workload.

A calendar invite that only exists in chat is a red flag for offices that actually run a calendar. Attackers send Teams meeting links because they look like work. The join page can be a credential harvest. If your firm does not schedule that meeting, do not join it to be polite.

Files in a channel are SharePoint. That is useful and dangerous. A PDF named “W-9” in a team you barely use is not more trustworthy than a PDF in email. Safe Attachments helps if it is on. A callback still wins for money and identity.

Private chat files are OneDrive shares. They inherit whatever sharing defaults you left messy. The Copilot and sharing posts are the long version. The short version: if Anyone-links are on, a Teams file can leave the tenant without anyone feeling like they “shared a site.”

What not to do

  • Do not train people that “Teams is internal so it is safe.” That sentence is the phish.
  • Do not leave “open federation” because one salesperson wanted to chat a prospect. Give them email.
  • Do not hunt malware only. Many Teams phishes are social engineering.
  • Do not skip mail DMARC because you use Teams. You need both.

Team working around laptops in a meeting room
External access and leftover guests are the usual Teams phishing path

A one-week Teams hardening pass

Day 1: screenshot the current policy

External access, guest defaults, who can add guests. If nobody can explain the screenshot, you do not have a policy.

Day 2: kill unused federation

Allow specific domains or block external. Tell the office before you do it. Help desk will get “I cannot chat so-and-so.” That is the point.

Day 3: guest report

Export guests. Disable the ones with no owner and no project. Keep a list of the rest with an expiry.

Turn on for Teams if licensed. Send a test file in a test team. Confirm it is inspected.

Day 5: one staff message

Four sentences: unexpected chats, no credential requests in Teams, callback for money, report to help desk. Not a 40-slide deck.

Managed help desk has to know this is coming. A federation change without a ticket path is how you get rolled back by the loudest salesperson.

Reporting has to be as easy as the phish. If the only instruction is “forward to IT,” people will not. In Teams they can screenshot and drop it in a known internal channel, or call. Pick one path. Tell help desk to treat those reports as real even when the chat looks clumsy. Clumsy is how the first one looks. The second one is polished.

Keep a monthly glance at external access settings. Policies drift when someone “just needs to chat a vendor this once” and the allow-all toggle is the fast path. The fast path is the incident. Put a calendar reminder. Settings that only move when someone is angry will move the wrong way. A quarterly screenshot of the external-access page in the ticket system is enough. If the screenshot matches last quarter, you are still in control. If it does not, ask who changed it and why. Write the answer in the ticket.

How this fits the rest of the tenant

Teams phishing sits next to email phishing, not instead of it. Cybersecurity for a Microsoft 365 shop is identity, mail, collaboration, and recovery. Collaboration is the piece most checklists still treat as “the app we like.”

If a stranger can DM your finance person in Teams, fix federation before you buy another awareness video. Training without the control is a sermon. The control without a callback habit still loses to a calm liar.

Awareness still has a job. People will get a convincing chat. Tell them the office does not reset passwords in Teams, does not send wiring changes in chat, and does not ask for Authenticator codes in a DM. Then make sure IT actually never does those things. A policy that staff see IT violate is not a policy.

If you already run employee security awareness training, add two Teams screenshots to the next session. Email-only training is how people click in the app you forgot to mention.

If you want external access decided and guests expired as a project, contact Secure Techies. We work from Canoga Park. We will tell you whether your firm can live with an allowlist, and we will not pretend DMARC covers chat.

Frequently Asked Questions

Yes. Attackers send chats, meeting invites, and files in Teams that skip the SPF, DKIM, and DMARC checks that protect email. External access and guest accounts are the usual path. Treat Teams as a second inbox with weaker costumes.
No. DMARC authenticates email From domains. Teams chats are not SMTP. You still want DMARC for mail. For Teams you need external access policy, guest hygiene, Safe Links, and users who treat unexpected chats like unexpected mail.
Many small professional firms can. If you must talk to clients in Teams, use trusted organizations or verified guests, not open federation with the whole internet. Unlimited external chat is how a stranger appears as a helpful IT person.
Guest access adds a person to your team as a guest account in Entra. External access (federation) lets someone outside chat with you without being in your directory. Both can be abused. Guests linger. External chat looks like a coworker.
Block unused external access, expire guests, turn on Safe Links for Teams, require MFA, and tell staff that ‘IT in chat’ is a callback. Most firms do not need the whole planet federated.
Share

Talk to a real IT expert — free

No sales pressure, no jargon. Just a straight assessment of where your IT and security stand, and what to do next.