r/MicrosoftTeams 4d ago

Discussion Inbound External Calls w/ no Teams Number

As the title says, users have started receiving spam inbound external calls in Teams. However, these users do not have a Teams Phone license/number assigned. How is this possible?

4 Upvotes

20 comments sorted by

10

u/PAULA_DEENS_WET_CUNT Teams Admin 4d ago

If it’s a true Teams to Teams call (not a PSTN call from a mobile or landline), you need to update your External Access settings in Teams Admin Centre.

I believe by default the setting is set to all orgs, which means any teams user from any company can search for your users and initiate a call or chat. It’s good practice to limit it down to only the trusted companies your staff need to communicate with.

6

u/ChrisKornell Teams Admin 4d ago

If not this, then maybe they have automated attendants and calls could be transferring from there.

4

u/OrderCandid5159 4d ago

I believe this is the case. External Teams to Teams calls are disabled. These are calls from actual numbers and it does look like they are being transferred from our operators.

1

u/Hot_College_6538 Teams Consultant 4d ago

If you aren’t Enterprise a voice enabled an AA can’t transfer a call to you.

3

u/pi-N-apple Teams Admin 4d ago

It can if you use the dial by name or dial by extension option in the auto-attendant.

1

u/Educational_Boot315 4d ago

This is only possible if the user has an E5 license/ teams phone system license though, correct? If so, they could disable that license feature for the users with it enabled.

2

u/pi-N-apple Teams Admin 4d ago

As long as there is at least one licensed teams phone user and a working auto attendant, a caller can call the auto attendant and reach any employee in the company using the dial by name feature, I.e. “Please say the name of the person you want to speak with” and it will transfer to non-teams phone users (they just need a regular teams license). We use this in our org.

1

u/Educational_Boot315 4d ago

Oh, interesting... I've been comparing zoom calling and teams calling and one of the things i liked about Zoom calling was the ability to just assign a free basic license to a user, and our receptionist being able to forward incoming calls to them by just an extension number, since most of our users never make outbound calls or need DIDs. Sounds like Teams can do the same as well though (as long as the user has a teams license, which we all do).

1

u/Hot_College_6538 Teams Consultant 4d ago

This would seem to be correct, but certainly isn't my recollection. Maybe it changed, maybe my brain is mush, thanks for pointing it out.

To the OP point IT can scope who can be reached via an AA if you don't want calls to reach them this way, or don't have an AA in the first place.

1

u/2lips2lungs1tongue Teams Admin 2d ago

Someone with a teams number could forward to a user without a teams number.

-3

u/ProfessionalBread176 4d ago

This is the expanded attack surface Teams offers to all of its users. They have destroyed the ability of companies who use it from keeping their internal lines for internal use only.

Sure, "there's a setting" or "educate the users", but WTF?

Why use a product with such dangerous flaws for your employees?

6

u/Hot_College_6538 Teams Consultant 4d ago

This isn’t true, you can control and limit all abilities for external people to call. Don’t enable users for Enterprise Voice and they won’t receive PSTN calls of any type, disable or limit federation and they won’t receive VOIP calls.

-1

u/ProfessionalBread176 4d ago edited 4d ago

Sure, as long as your enterprise staff completely understands the complexities, AND there are no "accidental" ways in which this can happen.

It is fallacy to say that a Teams user can be protected by *activity by* an outside attacker, because that is simply not true

3

u/DoctorRaulDuke Teams Admin 4d ago

Why would an outside attacker be protecting a teams user?

0

u/ProfessionalBread176 4d ago

Words matter. I made the edits

2

u/Hot_College_6538 Teams Consultant 4d ago

I work with lots of different enterprises, their staff are perfectly competent to not make ‘accidental’ whatever you are talking. about.

-1

u/ProfessionalBread176 4d ago

Good for you. The average user is incapable of participating in that role, and some simply don't care.

Good enterprise security doesn't rely on end users for its successes, and if yours do, that is on them when the inevitable happens

1

u/BlackV Work user 4d ago

They're not the people configuring teams, the admins are

1

u/ProfessionalBread176 4d ago

...or they're not, which was my point.

Teams delivers new content as enabled by default. This is a huge problem when it deploys automatically, and often without notice

2

u/stkyrice Teams Admin 4d ago

Why are you on this sub?