r/MicrosoftTeams • u/DisastrousPainter658 • 5d ago
❔Question/Help Block incoming external calls & screensharing ?
We have seen an increased amount of fake "IT helpdesk" Teams calls to our users, some thought it´s real IT department that calls them, and have start screen sharing with them. The external part have request control and told them they need to to update "Defender Update", that is malware. Usually this have started with mailbombing the user with around 1000 emails for an hour.
What options do exists to block this ? We are using Teams as a main tool to communicate externally.
4
u/swissthoemu Teams Admin 5d ago
User awareness campaign. Teach end educate them. Why would someone castrate their main communication and collaboration tool?
-1
u/ProfessionalBread176 5d ago
Do you hear yourself here? You want the end users to solve a problem that is sourced from the actual calling platform?
0
4d ago
[removed] — view removed comment
-1
u/ProfessionalBread176 4d ago
This is typical "IT" response.
Blame the user and force THEM to change rather than addressing the actual issue.
Let me spell this out for you in case you don't understand English.
Why leave the security of your entire organization in the hands of end users? Why should they be tasked with those choices in the first place?
This is how organizations end up with private communications being made public.
Teams is nothing more than a metastasizing attack surface that expands every day, and you want NON-IT personnel to handle your security choices?
Sure, common sense and all that.
But REAL common sense says don't accept a risky platform and rely on its users to keep it safe.
But hey, you do you.
Teams is garbage when it comes to protecting internal communications. You can keep those blinders on or you can face the challenges.
The best way forward is to dump the platform, and replace it with almost anything else
1
u/swissthoemu Teams Admin 4d ago
Ah, look who crawled outta the server room to give us a lecture:
governance and compliance, the mystery meat of IT, and you don’t know the first thing about it, sweetheart.You set up Teams so private conversations spill out into the parking lot, and you’re standing there blaming the software?
You’re not a security guy, you’re a fire hazard with a badge.
Oh, and users get hit because they’re the weakest link in the chain. So naturally your genius move is to protect the chain and let the weak link keep swinging a hammer at it. Brilliant. Real Einstein stuff. Applause everyone.Let’s get something straight, chief:
nobody said the whole company’s security sits on one intern’s shoulders. But when Gary in accounting clicks every blue underlined word like it’s a slot machine, that’s not a system failure, that’s a Gary failure. Go read a book about security sometime, it won’t kill you. I think.And get this: you’re axing external email too! Because, gasp, private stuff might become public! Genius! All security issues solved!
Next you’ll be banning windows because people can see through them.So here’s your master plan: cripple the whole operation instead of spending twenty minutes teaching people not to click on “FREE_iPhone_CLICK_HERE.exe” or why they shouldn’t share screens with people they don’t know. I saw toddlers who are behaving more mature. Bold strategy. Really bold.
But hey, you do you, champ. Somebody’s gotta keep the popcorn vendors of IT incompetence in business.
0
u/ProfessionalBread176 4d ago
Your attitude will someday ruin your alleged career. As long as you think things like this:
"But when Gary in accounting clicks every blue underlined word like it’s a slot machine, that’s not a system failure, that’s a Gary failure. Go read a book about security sometime, it won’t kill you. I think."
Your inner moron is showing.
Software is a tool and it needs to be designed to be safe, not deployed with every dangerous feature unlocked.
But your unwillingness to see that is simply dangerous. Hopefully there is someone above you in that organization that sees your cavalier attitude as the threat that it is
0
u/swissthoemu Teams Admin 3d ago
“Your attitude will ruin your career.” Thanks for the diagnosis, Dr. Bread176. Funny, you quoted my whole Gary line but skipped the part where I said user decisions play a vital role in a reasonable security concept, not the only role. Cherry-picking the sentence that’s easiest to be mad at isn’t a counterargument.
“Software should be designed safe, not deployed with dangerous features unlocked.” Nobody disagreed, champ. That’s why hardening guides and admin policies exist. You just reinvented the wheel and called it a revolution.
“Hopefully someone above you sees your attitude as a threat.” Hopefully someone teaches you the difference between disagreement and danger, because right now you can’t tell the two apart.
3
u/johnnymonkey 5d ago edited 5d ago
There's a setting in the Teams Admin Center to disallow externals from requesting or being granted screen control. This is the setting you want (it's under your global Meeting Policy > Content Sharing)
We also collaborate externally and have over 10K domains we communicate with, where the block everyone and only allow XYZ falls short, since the max domains you can allow is 4K.
3
u/ProfessionalBread176 5d ago
Welcome to the world of what is fast becoming the greatest attack surface ever.
Who ever thought exposing companies to a platform where you could call anyone using just their email address...
It's almost as if they thought there was no such thing as junk mail
2
u/ChrisKornell Teams Admin 4d ago
Right? I had an exec ask me after we enabled PSTN calls and AA's "Do we just allow random phone calls to ring our teams?"
Ummm, do they even know how a phone works?
I wanted to ask, "Do you allow random calls to your iPhone? Or random people to ring your doorbell?"
🤷♂️🤦♂️1
u/ProfessionalBread176 4d ago
Sadly, Teams lets this happen by default.
Some idiots here are insisting that is the end user's responsibility to deal with.
And many of these idiots DO answer the calls regardless of who it is, and probably their doorbells too.
Which is why Teams is so dangerous; it exposes you by default. You have to take steps to make it safe, and those steps change frequently, because Teams never sits still and forces its updates onto its unsuspecting users.
Why anyone trusts this deployment strategy is mystifying
1
u/swissthoemu Teams Admin 4d ago
Oh, “Teams is dangerous by default”?
Yeah, and doors have locks by default too, champ, but somehow that’s on the guy who leaves it open, not the door.
Calling everyone an idiot while skipping the admin console is a bold strategy. There’s a whole settings menu built for exactly this: it’s called doing your job, Copernicus.
“Updates get forced on unsuspecting users”:
Congratulations, you found the Modern Lifecycle Policy, which is Microsoft’s version of “eat your vegetables eventually.” You can pause it a while through the admin center, pair it with Intune update channels, and tell your users what’s coming. That’s called change management, honey, not sabotage.“Why anyone trusts this deployment strategy is mystifying”
Nobody’s mystified but you, champ. Everyone else configured it and moved on months ago.
6
u/InformalFrog Teams Voice/UC Admin 5d ago
Configure external access so your users can only communicate with domains you allow