How to Restrict External Access and Federation in Microsoft Teams
Retrospective: this article looks back at events from August 2023, written in 2026 with the benefit of hindsight.
Microsoft Teams external access lets users chat with people in other organizations. Attackers use it for phishing. Here is how to restrict it to what your business needs.
Understand the settings
- External access (federation): chat and meetings with users in other Microsoft 365 organizations, without adding them to your tenant.
- Teams accounts not managed by an organization: chat with consumer Teams users.
- Guest access: inviting external users into your Teams and channels (managed separately).
Step 1: Review current settings
In the Teams admin center, go to Users → External access. Check whether users can communicate with all external domains, and whether consumer accounts are allowed.
Step 2: Choose a model
- Allow only specific external domains (allowlist) — strongest; works for organizations with a known set of partners.
- Allow all except blocked domains — easier, but reactive.
- Disable external access entirely — rare, but suits some highly regulated groups.
Many organizations allow external access but block unmanaged (consumer) Teams accounts from initiating contact.
Step 3: Use policies for different groups
Assign stricter external access policies to executives, finance and IT admins, and broader policies to sales or support teams who collaborate widely.
Step 4: Keep user protections on
Make sure external sender labeling and message request acceptance remain enabled, so users see clearly when a chat comes from outside.
Step 5: Enable reporting
Allow users to report suspicious Teams messages (Defender for Office 365 user reported settings include Teams).
Step 6: Train users
"IT and security will never ask you to approve an MFA prompt or share a code in a chat."
Verify
Test from an external tenant that blocked domains can't initiate chats.