Description:
Verifies if Teams is configured to allow external communication by default on 3 settings:
"Users can communicate with other Skype for Business and Teams users" is compliant when set to Disabled.
"Users can communicate with Skype users" is compliant when set to Disabled.
"Allow guest access in Teams" is compliant when set to Disabled.
Why:
External collaboration through Teams can leave your organization open to security risks such as uncontrolled file sharing and sensitive data leakage.
Status detail shown in Augmentt: You have N out of M secure sharing settings applied.
This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.
Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.
Category: Data
Microsoft Licensing: Requires Premium (P1) licensing
Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.
Remediation in Augmentt: No in-product remediation — remediate in the Microsoft admin portals.
Compliance Frameworks:
CIS M365 2.0 — 3.3
CISA SCuBA — MS.TEAMS.2.1
NIST CSF 2.0 — PR.IR-01
CMMC Level 1 — AC.L1-b.1.iii
CMMC Level 2 — AC.L2-3.1.20
Microsoft documentation:
