Description:

Verifies if Teams is configured to allow external communication by default on 3 settings:

  • "Users can communicate with other Skype for Business and Teams users" is compliant when set to Disabled.

  • "Users can communicate with Skype users" is compliant when set to Disabled.

  • "Allow guest access in Teams" is compliant when set to Disabled.

Why:

External collaboration through Teams can leave your organization open to security risks such as uncontrolled file sharing and sensitive data leakage.

Status detail shown in Augmentt: You have N out of M secure sharing settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Data

Microsoft Licensing: Requires Premium (P1) licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.

Compliance Frameworks:

  • CIS M365 2.0 — 3.3

  • CISA SCuBA — MS.TEAMS.2.1

  • NIST CSF 2.0 — PR.IR-01

  • CMMC Level 1 — AC.L1-b.1.iii

  • CMMC Level 2 — AC.L2-3.1.20

Microsoft documentation: