"With this update, organizations can strengthen meeting security by configuring Teams policies to automatically block detected external meeting bots from joining meetings," the company said in a Microsoft 365 Message Center update on Friday.
Microsoft’s new Teams meeting protection policy
Microsoft is rolling out a meeting protection policy for Teams that automatically blocks identified external bots from joining meetings. The capability goes beyond a June change that tagged detected bots in the lobby and required organizer approval; under the new policy, identified external meeting bots are prevented from joining without needing explicit organizer confirmation.
Rollout timing, location, and activation requirements
The feature is being rolled out as part of a targeted release until the end of August and is scheduled to reach general availability worldwide by late September. Administrators will find the control under the "Manage bots" meeting protection settings in the Teams admin center. The policy will be off by default and requires administrators to activate and evaluate it before deployment. Once enabled, it can be assigned to specific users or groups through existing Teams meeting policy management; any meetings governed by that assigned policy will block identified external meeting bots.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhy Microsoft framed the change as risk reduction
Microsoft framed the policy as a way to reduce organizational risk by giving administrators "additional control over how identified bots are handled." The company noted that the change helps ensure third‑party bots—used for tasks such as note‑taking and transcription as well as "other automated tasks"—and malicious apps controlled by threat actors cannot join meetings without attendees and organizers realizing a non‑human participant has been added.
Context: Teams abuse and related defenses
The rollout arrives against a backdrop Microsoft described as a surge in attacks abusing Teams for access and lateral movement on enterprise networks. In April, Microsoft warned that threat actors were impersonating IT or helpdesk staff via cross‑tenant chats to contact employees and trick them into granting remote access to steal data. Microsoft also highlighted a December addition: since then, administrators have had the option to block external Teams users via the Defender portal to thwart cybercrime gangs, including ransomware groups, that attempt to abuse Teams in social engineering attacks.
The source material also references the Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments, and notes that "overall prevention scores can hide what happens after initial access," signaling concern about post‑access activity once attackers have valid credentials.
What this means for security teams, admins, and enterprises
- Security teams: The new policy gives security teams a direct lever to stop detected external meeting bots from joining meetings automatically. That capability complements existing Defender portal controls and the June lobby‑tagging behavior, creating layered choices for how bots are handled.
- Teams administrators: Admins must explicitly enable and evaluate the policy because it is off by default; they can deploy it narrowly by assigning it to specific users or groups through existing Teams meeting policy management. The setting lives under "Manage bots" in the Teams admin center and will move from targeted release to general availability by late September.
- Enterprises and procurement leaders: The change affects how third‑party bot integrations are governed. Organizations using note‑taking, transcription, or other automated meeting assistants will need to decide whether to allow those bots, rely on the lobby and organizer‑approval model, or block external bots entirely as this policy permits. Microsoft has signaled more admin controls are coming—allow lists, broader block policies, and audit reporting—so procurement and governance teams should watch the upcoming features.
Microsoft also announced in June that it plans additional admin controls, including policies to block external bots entirely, allow lists for approved bots, admin reports and audit logs on bot detection and presence, and more granular controls for different security requirements. Combined with the new automatic block option, those planned controls form a broader set of administrative choices intended to limit unobserved non‑human participants in meetings.
The policy is a narrowly scoped tool: it does not act until an administrator enables it, and it can be targeted to particular users or groups. That design leaves the practical impact in the hands of administrators—who must weigh the benefits of automated blocking against the operational need for third‑party meeting assistants—while joining a growing set of controls Microsoft has introduced to counter abuse of Teams that the company has explicitly warned is on the rise.
Source: BleepingComputer — Microsoft Teams now lets admins block external bots from meetings




