Microsoft Teams has introduced a new admin control to block external access with Teams trial-only tenants. This setting, which defaults to 'Blocked', aims to protect against malicious activities. Admins can review and update this setting using PowerShell commands. General availability of this feature started on August 15, 2024.
As communicated in MC805200 Microsoft Teams: Tenant Federation setting to control external access with trial-only tenants (June 2024), we introduced a new admin control to enable you to block external access (federation) with Teams trial-only tenants. Some malicious actors have used free Teams trials to launch phishing or abuse attacks against Teams users. With this setting you can add another layer of protection for users against some of these attacks.
Between June 2024 and August 2024, we provided a 45-day window to allow you to review and update the setting before enforcement began. Now, by default, this new setting will block external access with trial-only tenants and requires explicit action from you to continue to federate with trial tenants.
When this will happen:
General Availability (Worldwide): Available now. Blocking or allowing external access with trial-only tenants with this setting was enabled August 15, 2024. If you missed MC805200, you can still manage the setting for your organization at any time.
How this will affect your organization:
Teams PowerShell now supports the new Tenant Federation setting -ExternalAccessWithTrialTenants
with the values Allowed
or Blocked
. When set to Blocked
, all external access with users from Teams subscriptions that contain only trial licenses will be blocked. This means users from these trial-only tenants will not be able to search or reach your users via chats, Teams calls, and meetings (using the users' authenticated identity) and your users will not be able to reach users in these trial-only tenants. If this setting is set to Blocked
, users from the trial-only tenant will also be removed from any existing chats. The default setting will be to block external access with trial-only tenants.
Important Notes
in public clouds
will be blocked by default from external communication with users in other Microsoft 365 cloud environments and with Microsoft Skype for Business server users. No admin control will exist to allow cross-cloud external communication with trial tenants.
-ExternalAccessWithTrialTenants
is set to Blocked
, trial-only tenants in the Allow list will be blocked. If this setting is set to Allowed
, all domains in the Allow list will be allowed.
-ExternalAccessWithTrialTenants
setting has no impact.
-ExternalAccessWithTrialTenants
setting is set to Blocked
, trial-only tenants not in the Block list will also be blocked. If set to Allowed
, this setting has no impact.-ExternalAccessWithTrialTenants
set to Allowed
.What you need to do to prepare:
Review your settings for external access to determine if you need to change the default value for this new setting. To change this setting, install the latest PowerShell package (6.4.0) and use the Set-CsTenantFederationConfiguration
command to set the desired value when the setting is available:
Set-CsTenantFederationConfiguration -ExternalAccessWithTrialTenants "Allowed"
Set-CsTenantFederationConfiguration -ExternalAccessWithTrialTenants "Blocked"
Learn more
You may want to notify your admins about this change and update any relevant documentation as appropriate.