Microsoft Teams: Add multiple steps when building a workflow from scratch
🚨 The Signal: Teams workflows can now include multiple steps, increasing automation complexity. This expands potential attack surfaces for malicious workflows and data exfiltration, requiring stricter governance.
The Impact
Admins and Security Teams are affected by increased risk from complex workflows potentially exfiltrating data or executing malicious actions.
- Security Teams: Risk of data exfiltration via multi-step workflows.
- Admins: Increased complexity in managing and auditing workflow permissions.
- End Users: Potential for social engineering via malicious workflow prompts.
- Compliance Teams: New vectors for data leakage requiring updated policy enforcement.
The Action
- Review and update existing Power Automate DLP policies to specifically address Teams workflow connectors.
- Implement stricter controls on custom connector creation and usage within Power Automate.
- Audit existing Teams workflow permissions and review for least privilege.
- Educate users on the risks of executing untrusted workflows and reporting suspicious activity.
- Monitor Power Automate audit logs for unusual workflow creations or executions.
Domain: Teams · Impact: high · Workload: Teams · Essential Eight: Application Control · ISM: ISM-0843, ISM-1490, ISM-1544, ISM-1582, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1870, ISM-1871