Skip to content

Microsoft Teams governance & compliance security checks

Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.

On Microsoft Teams, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft Teams connector needs.

Checks (5)

severity: low Team Without Description fix difficulty: easy #

Add a meaningful description to Teams teams that lack one to improve governance visibility

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team and click Edit
  3. Add a meaningful description explaining the team's purpose
  4. Save the changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Large Team Without Moderation fix difficulty: medium #

Enable channel moderation and assign moderators to large Teams teams without governance controls

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the large team and go to Settings
  3. Enable channel moderation for general and key channels
  4. Assign moderators to manage content and membership

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Channel Without Moderation fix difficulty: easy #

Enable channel moderation and configure posting restrictions for unmoderated Teams channels

  1. Navigate to Teams Admin Center > Teams > Manage teams
  2. Select the team and navigate to the channel settings
  3. Enable channel moderation
  4. Configure who can post new messages and reply

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: low Meeting Recording Disabled fix difficulty: easy #

Enable cloud recording in Teams meeting policies and configure retention settings

  1. Navigate to Teams Admin Center > Meetings > Meeting policies
  2. Select the relevant meeting policy
  3. Enable Cloud recording for meetings
  4. Configure recording storage and retention settings

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b

severity: low Message Edit Delete Unrestricted fix difficulty: easy #

Restrict message editing and deletion in Teams messaging policies to preserve audit trails

  1. Navigate to Teams Admin Center > Messaging policies
  2. Select the relevant messaging policy
  3. Configure message editing and deletion restrictions
  4. Consider disabling Delete sent messages or Edit sent messages

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.23 SOC 2 Type II CC1.1 CIS Controls v8 CIS-05.1 NIST CSF 2.0 GV.RR GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

More Microsoft Teams checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial