Microsoft is introducing a new security policy in Microsoft Teams that gives organizations better control over third-party bots and automated services that attempt to join meetings. The new feature is designed to stop unauthorized or potentially malicious bots from joining without explicit approval from the meeting organizer.
The feature was first introduced in Microsoft 365's roadmap earlier this year and will be available for Teams on Windows, macOS, Android, and iOS in both global standard multi-tenant environments and GCC cloud environments.
Stops bots before they connect
When the policy is activated, it identifies Microsoft Teams automatically filters external bots and places them in the meeting lobby before they are allowed to join. The meeting organizer is then given the option to approve or deny access.
The protection includes both legitimate third-party bots used for things like transcription, annotation, and automation, as well as potentially malicious applications that can be exploited by threat actors.
The aim is to give organizations greater control over which automated services have access to sensitive meetings and corporate information.
“The new policy in the Teams Admin Center, Manage external bots and their access to meetings, can be assigned to individual users or specific groups,”, Microsoft states.
The company explains that Teams automatically identifies potential bots, places them in the meeting lobby, and clearly marks them as non-human participants. The meeting organizer must then actively approve the connection.
Even if a meeting is configured so that regular participants can skip the lobby, bots covered by the policy will still require approval before they are allowed to join.

More security checks are on the way
Microsoft also plans to further expand security features. Upcoming features include:
- Whitelists for approved bots.
- Ability to completely block external bots.
- Administrator reports and audit logs of identified bots.
- More detailed security policies tailored to the requirements of different organizations.
The new features will provide IT administrators better overview and strengthen control over automated services in Teams.
Part of Microsoft's broader security effort
The new bot policy is part of Microsoft's extensive effort to strengthen security in Teams against modern cyber threats.
Since December, administrators can block external Teams users via Microsoft Defender Portal to counter social engineering attacks from cybercriminals and ransomware groups.
Also introduced in January were new features that warn users when external callers pretend to represent trusted organizations, a common tactic in phishing and fraud attempts.
Microsoft has also introduced the ability to report suspicious calls as potential phishing or fraud attempts, giving organizations better opportunities to detect and manage security incidents.
Earlier this year, warned Microsoft also because attackers are increasingly leveraging external Teams collaboration to infiltrate corporate networks. By posing as IT support or helpdesk, attackers try to trick employees into granting remote access, which can lead to data theft and lateral movement within the organization's IT environment.
The new policy for external bots is another step in Microsoft's strategy to strengthen the security of digital collaboration and provide organizations with better protection against increasingly advanced cyber threats.
Increased control over AI and automation in meetings
The increasing use of AI-based tools and automated meeting assistants means that More and more third-party applications are gaining access to sensitive corporate meetings. At the same time, there is an increasing need for clear security controls that enable organizations to determine which services should be allowed to participate.
With the new policy, IT administrators gain better control over external bots and can ensure that only approved services have access to meetings and the information shared there. The feature complements Microsoft's Zero Trust initiative and strengthens protection against identity-based attacks, social engineering and other cyberthreats targeting modern collaboration platforms.
As AI becomes a natural part of the digital workplace, more security features are expected to be introduced to provide companies with increased transparency, better governance and higher security in Microsoft Teams.








