HomeSecurityMicrosoft Teams: Administrators will block external users from Defender Portal

Microsoft Teams: Admins will block external users from Defender Portal

Microsoft is continuing its strategy for more centralized and unified security management across the Microsoft 365. According to a recent update in the Microsoft 365 Message Center, the company is preparing to strengthen the collaboration between Microsoft Teams and Microsoft Defender for Office 365, introducing a new feature expected to be released next month.

Microsoft Teams Defender Portal

Centralized block management from the Defender portal

With this new feature, security administrators will be able to control and manage blocked external Microsoft Teams users directly from the Tenant Allow/Block List (TABL) within the Microsoft Defender. This is a change that, while seemingly small, has a significant business impact.

Until now, managing external access often required moving between different management centers, which increased complexity and the risk of errors. With this consolidation, Microsoft is bringing critical security functions together in a single environment, reducing tool fragmentation.

See also: Vishing attack abuses Teams & QuickAssist to deploy .NET malware

Stronger control of external communication

The new feature, which is tied to Microsoft 365 Roadmap ID 542189, allows security teams to add specific external users or entire domains to the block list. Once an entry is added to the TABL, the restrictions are immediately applied to Microsoft Teams.

In practice, this means that blocked external users will not be able to initiate or continue any form of communication. The block covers chats, channel messages, meetings, as well as voice or video calls, significantly strengthening the defense against malicious or unwanted contacts.

Microsoft Teams: Admins will block external users from Defender Portal

Basic capabilities and operational limits

Microsoft has set specific limits for the new feature, which reflect a balance between flexibility and control. Specifically, blocking up to 4,000 domains and 200 individual email addresses. This approach allows for targeted interventions, without the need for blanket blocking that could impact legitimate partnerships.

See also: Hackers distribute ValleyRat via Telegram, WinSCP, Chrome and Teams

For organizations that work with a large number of external partners, the ability to “surgically” block individual accounts is a significant advantage, especially in cases of phishing, impersonation, or third-party account compromise.

Traceability and compliance in the spotlight

Another critical element of the upgrade is enhanced audit logging. Every block or unblock action through the Defender portal is automatically logged. This way, organizations maintain a complete history of changes, which is especially important for compliance, internal audits, and regulatory requirements.

It is also worth noting that Microsoft has assured that enabling the new feature will not affect existing Teams settings, ensuring a smooth transition and continuity in the operation of organizations.

Release schedule and conditions

The feature is expected to roll out in early January 2026 and be available globally by mid-January 2026. It will be available to organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2.

See also: Guest access to Teams can remove Defender protection

Microsoft Teams: Admins will block external users from Defender Portal

To fully leverage the integration, administrators should ensure that Microsoft Teams settings allow security teams to manage blocked domains – a prerequisite for TABL to function properly.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Another step towards the unified security stack

With this move, Microsoft confirms its strategy to bridge communication tools with threat defense platforms. The result is a more coherent and efficient security environment, which not only strengthens protection against external threats, but also reduces the administrative burden for IT and security teams. In an era where attacks are becoming increasingly complex, such integrations are becoming crucial.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS