LearnMicrosoft Teams › 11 · Security

Hardening high-stakes meetings

Board results, M&A calls, incident bridges: a repeatable pattern — classify, restrict, watermark, verify — turns 'please be careful' into configuration that survives stressed organisers.

The pattern (make it a template, not a memo)

  1. Classify: a meeting sensitivity label ('Board-Confidential') that ENFORCES the rest — organisers pick a word, not fourteen toggles (meeting-security concept's label rail; Premium).
  2. Restrict entry: lobby for everyone except named roles; anonymous join off; identity verification for unverified joiners; no dial-in for the truly sensitive (PSTN legs are unverifiable).
  3. Restrict capability: named presenters only; attendee mic/cam off; chat off or in-meeting-only (the persistent thread is an exfil channel); no recording/transcription — or MANDATED recording for regulated bridges; decide, don't default.
  4. Mark and bound the artifacts: watermarking over video and content (screenshots become attributable); restricted copy of chat/captions; e2ee only when its feature costs (no recording/captions/Copilot) are accepted — see the trade sheet.
  5. Verify then run: a 10-minute pre-meeting with the organiser: roster review, lobby staffing assigned, co-organiser named (organiser-drops-off resilience).

The threat model it answers

Uninvited entry (leaked links, invite forwarding) -> lobby+verification; insider leakage -> watermarks + copy restrictions + no-recording; ambient capture (companion phones) -> watermarks make it costly; social entry ('exec' joins by phone late) -> no-PSTN + named-presenter discipline. Residual: an authorised attendee photographing a screen — watermark is the deterrent; nothing is the prevention. Say so plainly to sponsors.

What to watch (proofs)

  • The template exists as config: the label's meeting settings in Purview + a policy census showing the hardened options land for organiser populations (Get-CsTeamsMeetingPolicy instances — nightly scan).
  • Entry discipline held: the attendance report post-meeting — every admit-from-lobby has a name and a time; anonymous or unverified entries = process breach to review.
  • Watermark/e2ee active: in-meeting indicators screenshotted at start by the co-organiser (the 30-second ritual), or options via Graph for the record.
  • Artifact leakage surface: eDiscovery check that no recording/transcript exists for no-record meetings — absence, verified, is the control working.

PowerShell for this concept

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.