PUBlished on
June 27, 2023
updated on
November 5, 2025

Microsoft Teams Phishing Exploit

CHRIS FULLER & THANH DIP

The phishing exploit in Microsoft Teams, as revealed by Max Corbridge and Tom Ellson from JUMPSEC’s Red Team, is a significant and subtle vulnerability inherent in the platform’s default configuration. This means most organizations using Microsoft Teams are vulnerable unless they have taken explicit steps to prevent it. The exploit takes advantage of the feature that allows communication between different tenants in Teams, enabling malicious actors to impersonate trusted external contacts and launch devastating phishing attacks.

This blog details what exactly the exploit is and how to implement proactive measures based on your unique Teams instance that will minimize risk without causing any surprise disruptions to business operations. With complete visibility and control of their Microsoft application suite, Obsidian customers can easily leverage our platform to limit the likelihood and blast radius of a security incident related to this vulnerability.

Understanding the Microsoft Teams Exploit

This Teams phishing exploit is particularly concerning due to the potentially damaging level of access it provides and the subtle nature which makes it difficult to detect. The default configuration of Teams allows tenants to communicate freely, even without mutual allowance. This enables an external party to contact your organization, potentially impersonating trusted individuals or entities in order to carry out a phishing attack. Unless explicit steps are taken to mitigate this vulnerability, the danger will be present for organizations leveraging Teams.

Mitigating the Exploit with Microsoft Teams Settings

The appropriate mitigation method will be dependent on your organization’s unique risk tolerance levels and Teams use cases. It boils down to a simple question – do you need communication with external tenants for any reason?

Selective Accessibility: Control external domain communication

For organizations requiring external tenant communication but only with select domains, a strategy of selective accessibility can help minimize risks without slowing down business.

To configure your settings:

Streamline Your Security with Obsidian

Obsidian can support your organization in maintaining a secure Teams environment. As a leading suite of productivity applications inclusive of Teams, Microsoft 365 handles a wide variety of your organization’s critical business data, putting it at high risk for malicious attackers, insider threats, and accidental exposure. Obsidian protects Microsoft 365 by helping security teams harden configurations, manage privileged access, and identify potential threats quickly. Schedule a demo today to see for yourself.

Frequently Asked Questions (FAQs)

What is the Microsoft Teams phishing exploit and why is it dangerous?

The Microsoft Teams phishing exploit takes advantage of Teams’ default settings that allow unrestricted communication between different organizational tenants. Attackers can exploit this feature to impersonate trusted external contacts and deliver convincing phishing messages. Its stealthy nature and the high level of access possible make it particularly difficult to detect, increasing the risk of successful attacks.

How can organizations mitigate the Microsoft Teams phishing exploit risk?

Organizations can mitigate this risk by changing Teams’ external access settings. If external communication is unnecessary, it’s best to block this capability entirely. If business requires external communication, organizations should restrict access to only approved domains using the Microsoft Teams Admin Center, which limits opportunities for malicious third parties to exploit the platform.

What steps should I take in the Microsoft Teams Admin Center to manage external access?

In the Microsoft Teams Admin Center, navigate to ‘Users’ > ‘External Access’. Here, you can opt to block all external communications or specify allowed domains with which your organization can interact. Additionally, you can list domains under ‘Blocked Domains’ to explicitly restrict any untrusted or suspicious domains from contacting your users.

How does Obsidian help with securing Microsoft Teams against phishing exploits?

Obsidian provides enhanced visibility and security controls for Microsoft 365 apps, including Teams. The platform assists security teams in identifying vulnerabilities, enforcing best practices in configuration, monitoring privileged access, and detecting potential threats quickly. This comprehensive oversight helps limit the likelihood and impact of phishing attacks leveraging the Teams exploit.

You May Also Like

Get Started

Start in minutes and secure your critical SaaS applications with continuous monitoring and data-driven insights.

get a demo