Microsoft Teams gets a new switch that kicks uninvited bots out of meetings
Admins can now auto-block external bots from joining Teams calls, closing a quiet side door that attackers have been probing.

Key points
- Microsoft is adding a Teams policy that automatically blocks detected external bots from joining meetings, with rollout finishing worldwide by late September.
- The setting lives under "Manage bots" in the Teams admin centre, is off by default, and must be turned on and assigned to users or groups.
- It builds on a June change that put unknown bots in the lobby and required organiser approval.
- Microsoft warned in April that attackers are increasingly abusing Teams to pose as IT staff and trick employees into handing over remote access.
Microsoft is rolling out a Teams setting that lets administrators automatically block external bots, meaning automated software accounts run from outside the company, from joining meetings. First reported by BleepingComputer, the change is a small but meaningful tightening of who, or what, can sit silently on a call.
Today, a bot can join a Teams meeting for lots of harmless reasons. Note-taking assistants, transcription services and scheduling helpers all show up as bot participants. The problem is that a malicious app, dressed up the same way, can join too.
What is actually changing?
Admins get a new toggle. Once switched on, Teams will refuse entry to any external bot it identifies, without waiting for the meeting organiser to approve or reject it in the lobby.
Until now, the strongest option, added in June, was to force detected bots into the lobby and require the organiser to let them in. That still relied on a human noticing and making the right call in the moment. The new policy removes that decision from the meeting itself.
The control sits under the "Manage bots" meeting protection settings in the Teams admin centre. It is off by default. Microsoft says a targeted release runs until the end of August, with general availability by late September.
Timeline at a glance
| Date | Change |
|---|---|
| April 2025 | Microsoft warns of rising Teams abuse by attackers posing as IT staff |
| June 2025 | Detected bots sent to lobby, organiser approval required |
| End of August 2025 | Targeted release of auto-block policy |
| Late September 2025 | General availability worldwide |
Why does this matter beyond IT teams?
Because Teams has quietly become one of the routes attackers use to reach staff. In April, Microsoft flagged a surge in campaigns where criminals impersonate IT or helpdesk workers over cross-tenant chats, meaning messages sent from one company's Microsoft account into another's, then talk employees into granting remote access to their machines.
Groups tracked as Storm-1811 in Microsoft's naming convention, with tooling and behaviour that overlaps with the Black Basta ransomware crew, have been among the most active. Sophos and others have reported similar activity clusters using near-identical playbooks, so single-vendor attribution here should be read with medium confidence.
A rogue bot in a meeting is a different flavour of the same problem. It can transcribe a confidential call. It can sit in as a plausible-looking participant while a social engineering conversation plays out. Blocking it at the door is cheaper than spotting it later.
What should admins actually do?
Turn it on, but test first. Because the policy is off by default and can be scoped to specific users or groups, Microsoft is clearly expecting organisations to trial it before flipping it on company-wide. Legitimate note-taking and transcription bots used by staff will need to be identified and, once Microsoft ships the promised allow-list feature, added to it.
Microsoft has also said more controls are coming: allow lists for approved bots, admin reports on bot detection, and audit logs showing which bots tried to join which meetings. Those are the pieces defenders will want for investigations after the fact.
For everyone else, the practical takeaway is simpler. If a stranger, human or not, appears in a Teams meeting you organised and you did not invite them, ask who they are before you keep talking. That habit costs nothing and closes most of the gap this policy is trying to shut.



