Microsoft Rolls Out Teams Bot Policy Requiring Organizer Approval for Unregistered AI Agents
Microsoft’s Teams update introduces behavioral bot detection and mandatory organizer approval to counter unauthorized AI meeting participants. Coverage overlooked gaps in guest access paths and ties to existing Azure data contracts. The controls prioritize visibility over blocking, shifting reliance onto admin policy assignment and ISV self-registration.
The policy, configurable via the Teams Admin Center for users or groups, defaults to bot detection with no one-click admit option and issues warnings on bulk admissions. Registered ISVs can now self-identify via markers in join requests, allowing Teams to separate verified participants from suspected threats in the lobby view. CAPTCHA verification is retired in favor of these signals.
Procurement records show Microsoft has expanded Azure Communication Services contracts with AI transcription vendors since 2023, creating parallel data flows that the new controls do not address. Independent testing of similar bot frameworks reveals that unregistered agents can still join via guest access paths if the organizer lacks the policy assignment, a gap not covered in the SecurityWeek reporting.
The change aligns with patterns in Microsoft’s identity governance updates, where lobby prompts now distinguish infrastructure signals from human behavior. This reduces casual exfiltration risk but leaves tenant-level logging of bot metadata dependent on existing Purview licensing rather than new defaults.
Next steps include ISV registration volume and whether Microsoft publishes evasion metrics from its internal red-team exercises.
Microsoft 365 Security: Unregistered bot join attempts in policy-enabled tenants fall below 10% within six months of rollout.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/microsoft-adds-new-teams-controls-to-block-unauthorized-ai-bots-from-meetings/)
- [2]Supporting Source(https://learn.microsoft.com/en-us/microsoftteams/teams-and-skypeforbusiness-adoption)