Microsoft Teams: Add multiple steps when building a workflow from scratch

🚨 The Signal: Teams workflows can now chain multiple actions, enabling more complex automations from a single trigger. This increases the potential for data exfiltration or unauthorized actions if not properly governed.

The Impact

Users creating multi-step workflows in Teams introduce a security risk of unintended data exposure or unauthorized actions.

  • End users: Risk of inadvertently creating workflows that exfiltrate sensitive data.
  • Security teams: Increased complexity in monitoring and auditing automated data flows.
  • Admins: Need to review and potentially update existing Power Platform DLP policies for Teams workflows.

The Action

  1. Review existing Power Platform Data Loss Prevention (DLP) policies for Microsoft Teams and Power Automate.
  2. Assess current connectors allowed in Power Platform DLP policies, especially those with high business impact.
  3. Consider implementing new DLP rules to restrict specific multi-step workflow patterns or connector combinations.
  4. Educate users on secure workflow design and the implications of connecting multiple services.
  5. Monitor Power Automate audit logs for unusual workflow activities or data transfers.

Domain: Teams · Impact: high · Workload: Teams