Microsoft Teams: Enable agents for existing applications in your organization

🚨 The Signal: Admins can now enable third-party application agents directly within Teams Admin Center. This introduces new integration points for existing software, potentially expanding the attack surface and requiring careful security review of agent permissions and data access.

The Impact

Admins and Security Teams are affected by new agent integrations, increasing the risk of unauthorized data access or privilege escalation if not properly managed.

  • Admins: Must review and approve new agent permissions carefully to prevent over-privileged access.
  • Security Teams: Need to assess the security posture of third-party agents and their data access.
  • End Users: May interact with new agents, increasing potential for social engineering if agents are compromised.

The Action

  1. Review existing third-party applications for agent availability in Teams Admin Center.
  2. Assess the permissions requested by any Teams agent before enablement.
  3. Implement a policy for vetting and approving new Teams agents, including data access and scope.
  4. Monitor audit logs for agent-related activities and permission changes.
  5. Educate users on identifying legitimate Teams agents versus potential phishing attempts.

Domain: Agentic-AI · Impact: high · Workload: Teams · Essential Eight: Application Control, Restrict Administrative Privileges · ISM: ISM-0445, ISM-0843, ISM-1175, ISM-1380, ISM-1490, ISM-1507, ISM-1508, ISM-1509, ISM-1544, ISM-1582, ISM-1647, ISM-1648, ISM-1650, ISM-1656, ISM-1657, ISM-1658, ISM-1659, ISM-1660, ISM-1686, ISM-1688, ISM-1689, ISM-1870, ISM-1871, ISM-1883, ISM-1897, ISM-1898