Skip to main content
Kumonix - Microsoft Solutions Partner
All articles

Microsoft Teams Phishing: The Impersonation Risk Most Firms Haven't Trained For

Attackers are impersonating IT teams and vendors within Teams chats. Learn what law firms and professional services firms must secure this month to reduce risk

Kumonix Team 5 min read

Most firms have run phishing awareness training at some point. Nearly all of it covers email. Almost none of it covers Microsoft Teams, and that's becoming a problem, because Teams is where a growing number of impersonation attempts are actually landing.

This isn't a hypothetical risk. Microsoft's own security guidance has flagged phishing and impersonation attempts increasingly arriving through Teams chats and external contact requests, not inboxes. Someone messages a member of staff, appearing to be internal IT support, a known vendor, or even a colleague, and asks them to confirm a login, share a code, or click a link. It looks routine. That's exactly why it works.

Why Teams Is A Softer Target Than Email

Staff have had years of exposure to email phishing training. They've learned, at least partly, to check sender addresses, hover over links, and be wary of urgency. That instinct doesn't automatically carry over to Teams.

Teams feels internal by default. The interface is familiar, it's where colleagues genuinely message each other all day, and most staff have never been told that someone outside the organisation can message them there too. So a chat request from "IT Support" gets a level of trust an equivalent email never would.

That's the actual vulnerability. It's not a flaw in Teams itself. It's a gap between how staff have been trained to behave in one channel and how they actually behave in another.

What This Looks Like In Practice

The pattern is fairly consistent. An external account, sometimes a compromised guest account, sometimes a newly created one designed to look plausible, sends a message posing as internal support, a supplier, or a partner firm. The display name is close enough to convincing. There's often a small tell, a slightly wrong name format, no profile photo, a message that arrives outside normal hours, but nothing that jumps out unless someone is specifically looking for it.

The ask is usually simple: confirm a login, approve a device, click through to "verify" an account. It's the same social engineering playbook as email phishing, just delivered somewhere staff aren't expecting it and haven't been told to question.

The Settings Most Firms Have Never Touched

Here's the part that's genuinely fixable, and quickly. Teams has external access and guest access controls that determine who outside your organisation can find, message, or add your staff to chats. In most tenants we look at, these settings are either left at their default, wide-open configuration, or were set once during initial rollout and never revisited since.

A few things worth checking directly:

External access, which controls whether users from other Microsoft 365 organisations can find and message your staff at all. If this is unrestricted, anyone with a business Microsoft 365 tenant can attempt contact.

Guest access, which governs accounts added directly into your tenant for a specific project or client relationship. These often outlive the reason they were created and are rarely reviewed afterwards.

Conditional Access policies, which can require additional verification for sign-ins or actions that look unusual, regardless of which app the request came through.

Microsoft Defender for Office 365 also extends some phishing and link protection into Teams, but it needs to be explicitly configured. It isn't automatically doing the same job in Teams that it does in Outlook.

What To Fix This Week

You don't need a project plan for this. Start with the Teams admin centre and review your external access and guest access settings directly, tightening them to only what your firm actually needs, rather than the default.

Brief staff specifically on Teams impersonation, not as a repeat of the email training, but as its own short conversation. The message is simple: IT will never ask you to confirm a login or share a code over Teams chat, and if a message claims otherwise, verify it another way before responding.

Set a habit of reviewing guest and external accounts quarterly, so this doesn't quietly drift back open again in twelve months.

None of this takes long. It takes someone deciding it's worth checking, which is usually the actual gap, not the technology.

If you want a second pair of eyes on your Teams external access settings, that's a quick, focused conversation, not a big engagement. Happy to run through it with you.

Next article

Microsoft Intune Explained for Businesses

Read the next article

Ready to transform your business?

Let's discuss how our Microsoft solutions can drive your business forward. Get a free consultation and discover what's possible.