M365TEAMS-006: Messaging policies (external communication)

Plataforma
Entra ID / M365
Categoría
Microsoft Teams Security
Severidad
Medium
Pilar de Zero Trust
Applications & Workloads (peso 1)
Fixtures de referencia
3
Cobertura de ramas
Observada: los fixtures prueban los veredictos que ejercitan
Procedencia
baseline

Qué comprueba

Teams messaging policies control user capabilities within chat and channel conversations, including the ability to communicate with external users through chat. Unrestricted messaging to external users enables data exfiltration through chat, file sharing, and link sharing without the visibility and controls applied to email communication. Messaging policies must be configured to prevent sensitive data leakage through the Teams chat channel.

Valor recomendado

External chat limited to specific domains; URL preview disabled for external conversations; file sharing restricted in external chats

Remediación

Review the Teams messaging policies and restrict the ability to chat with external users to only those personnel who have a business need for cross-organization communication. Disable URL previews in conversations with external users to prevent accidental data exposure through link expansion. Consider implementing DLP policies for Teams chat to detect and block sharing of sensitive information types in external conversations.

Veredictos probados con fixtures

Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.

Escenarios de veredicto de M365TEAMS-006
EscenarioVeredicto esperado
cleanPASS
known-badWARN
no-dataNot Assessed

Mapeos a marcos de referencia

CISA SCuBA
MS.TEAMS.2.2v2, MS.TEAMS.2.3v2
NIST SP 800-53
AC-20
CIS M365 Benchmark
8.2.1