LearnMicrosoft Teams › 4 · Meetings & events

Meeting security controls

Meeting security is concentric rings: who reaches the lobby, who gets in, what they can do, and what they can take away. Harden from the outside in, and know which rings are Premium.

The rings, outside in

  1. Reachability — can the identity class even attempt to join? Anonymous join on/off (org + per-organizer policy), federated allowed, guests allowed. Off here = no lobby event, no log, nothing.
  2. Admission — lobby rules per identity class; who bypasses (settable down to 'only organizers'); PSTN callers' lobby treatment; identity verification for unverified joiners (email passcode — Premium) closes the fake-name-in-browser hole.
  3. Capability — presenter allow-list ('specific people'), mics/cameras hard-off, chat off or in-meeting-only, reactions off. For structured events: green room so nothing is visible until showtime.
  4. Exfiltration — recording off, watermarking over video+shared content (Premium; watermarks carry the viewer's email — screenshots become attributable), restrict copy/forward of chat/captions/transcript (Premium), and end-to-end encryption for the paranoid tier.

E2EE's honest trade sheet

Meeting e2ee (policy-enabled, organizer-selected, or label-enforced with Premium) moves key custody to the endpoints: the service can no longer see media — which also disables everything that needs service-side media access: recording, transcription, Copilot, live captions, companion joins. E2EE is for meetings whose content must never exist server-side, accepted feature cost and all. Watermark + no-recording covers most 'sensitive' needs at far lower friction.

Sensitivity labels as the enforcement rail (Premium)

Meeting labels bundle the rings into one click: a 'Highly Confidential Meeting' label can force lobby-for-everyone, watermarks, no recording, e2ee, no chat copy. Organizers stop configuring security; they classify, and the label configures. That's the only model that survives busy executives.

What to watch (proofs)

  • The outer ring's stance: scanned TeamsMeetingPolicy anonymous/lobby columns across ALL instances + TeamsMeetingConfiguration — your true exposure, versioned nightly.
  • Ring 2 working: attendance report shows lobby-admitted-at timestamps; an anonymous test join (private browser) is the two-minute acceptance test after any change.
  • Watermark/e2ee actually on: in-meeting indicators (shield/watermark visible) + the meeting options object via Graph — and for label-enforced, the label's meeting settings in Purview.
  • The audit trail: meeting join events, recording-started events, and (Premium) advanced monitoring surfaces in TAC — who joined which hardened meeting, from where.

PowerShell for this concept

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.