Microsoft Teams: Meeting recap can be shared via link

🚨 The Signal: Teams meeting recaps can now be shared via link, potentially exposing sensitive meeting content to unauthorised users if access controls are not properly managed. This increases the risk of information leakage.

The Impact

All users are affected, increasing the risk of sensitive meeting information being shared inappropriately.

  • End Users: Increased risk of inadvertently sharing sensitive meeting content.
  • Security Teams: New vector for data exfiltration and compliance breaches.
  • Compliance Officers: Greater challenge in demonstrating adherence to information protection policies.

The Action

  1. Review and reinforce existing Microsoft Teams sharing policies for meeting recordings and transcripts.
  2. Educate users on the implications of sharing meeting recap links and the importance of content sensitivity.
  3. Monitor Microsoft 365 audit logs for unusual sharing activity related to meeting recaps.
  4. Consider implementing or refining Microsoft Purview Data Loss Prevention (DLP) policies for Teams content.

Domain: Teams · Impact: high · Workload: Teams