Blog Post

Microsoft Teams Blog
3 MIN READ

Protecting your information and staying compliant with Microsoft Teams

Nydia Cavazos's avatar
Nydia Cavazos
Icon for Microsoft rankMicrosoft
Jan 06, 2020

Adopting Microsoft Teams in your organization brings the benefits of chat-based collaboration and an integrated hub for your calls, meetings, apps, and content. This is why there are more than 20 million daily active users of Teams.

 

But it isn’t all about productivity, we want Teams to contribute to your security and compliance requirements and you probably have a lot of questions on how this happens. You may be used to protecting email and files in Microsoft 365 and on your mobile devices, but how should you approach security and compliance as you add Teams to the mix? Did you know, for example, that Teams keeps persistent records of chat conversations by default?

 

As we enter the new year, we’ll help you answer these top-of-mind questions starting with the latest episode in our Microsoft Teams for IT series on Microsoft Mechanics, dedicated to security and compliance.

 

 

 

Make Microsoft Teams part of your information governance approach

 

If you’re new to how persistent chat works in Teams, the good news is that you have control over how persistent chat conversations are. Retention thresholds for chat to can be set to time period as short as 24 hours. In fact, there are a multitude of security and compliance controls that you can apply to Teams chat, meetings and calls. For example, you can disable screen sharing for specific users, or with information barriers via PowerShell, you can prevent illicit communications between different segments of users. In regulated sectors such as Finance, where you may be required to prove the right measures are in place to prevent insider trading, this capability can come in handy.

 

As you protect your files and emails in Microsoft 365, we help you make Teams another endpoint in your overall security and compliance strategy. This allows the policies that you set universally, inherited from services like SharePoint, OneDrive, and Exchange, to apply to Teams and take advantage of capabilities such as Data Loss Prevention, Advanced Threat Protection, organizational search and in-place hold with eDiscovery, or Communication Compliance to monitor and prevent inappropriate behaviors. You can discover Microsoft 365 controls available to you by reviewing the security and compliance scores for your tenants, which recommend controls that could help increase your scores.

 

Microsoft makes sure the Microsoft Teams service is secure and compliant in regard to data flow. Data within Microsoft data centers is encrypted at rest and in transit. We keep a robust control framework of more than 1,000 controls to meet the requirements of some of the most rigorous industry regulations and continuously review and add controls as new requirements emerge. In fact, you can find 3rd party auditor reports for Microsoft 365 and Teams services in the Service Trust Portal at aka.ms/STP.

 

These are just some of the top ways we keep you secure and compliant with Teams and in this Microsoft Mechanics episode, I’ll walk you through your options and more details.

You can follow our full playlist at aka.ms/MicrosoftTeamsforIT, which starts with an overview of Microsoft Teams for IT Admins, and with upcoming episodes that will cover how to configure security and compliance controls for Teams, upgrading from Skype for Business, and how to scale end-user adoption.

 

If you are in a government cloud service such as the US Government Community Cloud (GCC), GCC High, or Department of Defense, and don’t see some of these capabilities available yet, rest assured we are working on it, and you can stay updated at aka.ms/TeamsGovRoadmap.

 

Please give us your feedback on other questions you may have or other topics you’d like us to cover and enjoy the new year!

Nydia

Updated Aug 24, 2022
Version 4.0

14 Comments

  • Sean Ellis's avatar
    Sean Ellis
    Iron Contributor
    UserVoice at the moment seems to be a place into which to divert criticism, not to have it acted on. It's where we can be sent to complain about issues among ourselves and where nothing ever happens. I can't vote multiple times for the same thing, so how can I raise the profile of an item I've already voted on? The only way to do this is to raise the problem in other forums, which is why I am here. A serious problem is that we feel like we're not just being ignored, but that we are being actively lied to about the status of enhancements, in order to try to stop us changing to other applications. Here's my #1 example: compact mode for chat. This was raised late in 2016 (!) and immediately attracted a large number of votes. For most of the next 3 years it was the #3 issue and the #1 UI issue (it has recently been overtaken by multi-window mode.) It was marked as "Working on it" on 9 February 2017. More feedback was asked for. We told you what we wanted (more chat visible in a much smaller window), and were told "We are working on changes that will be made in the coming weeks" - in June 2017. In March 2018, 9 months later, we were given an update saying that you had implemented something which reduced the amount of visible chat on screen - the precise opposite of what was asked for. In December 2018, it was demoted to "Planned". In March 2019, a full year on, we were then asked for more feedback. We still wanted something which showed more chat in a small window. In July, you were still working on "defining the experience". None of this requires new features - it's just tweaking parameters of the CSS that sets the layout of the embedded HTML page. People (including me) prototyped this with style managers in the web client and shared our results. We achieved more in a lunchtime than had been achieved by the actual developers in literally years. You said you had designs. We asked to see them. Nothing. We told you what we wanted. You said you were working on it, then waited a year and asked the same questions again. The same thing happens for any user customisation options. It's obvious that no work has actually been done on this, and that there is zero intention of actually doing it at all. So why lie to us repeatedly about progress?
  • Hi Sean Ellis ! Thank you for the feedback =). I agree that changes in the UI, specifically the change you're proposing, would further help manage risk. I hear that you're somewhat disappointed on this UserVoice item not being prioritized yet. To decide what features to build, votes, impact to end-user, change management, capacity, and many other factors are considered. So far we have focused on delivering more robust features for meetings and accessibility (e.g. live captions or private channels), considering that SharePoint already does quite a good helping users manage risk, and under the assumption that if Guests are allowed and added to Teams, they should have access to the information being shared (otherwise why add them?). If this continues to be important, keep the votes up, we keep monitoring it. Also, be sure to raise this ask to your Microsoft Account team if this is blocking your deployment.

     

    Thank you for sharing your thoughts with me =)!

    Nydia

  • Sean Ellis's avatar
    Sean Ellis
    Iron Contributor
    A useful addition to the UI would be to allow users to easily mark sensitive channels using identifiable colors. For example, I might choose a bright red highlight color to indicate any channel which might include people outside our organization, or a green color to indicate private channels. It is then less likely that I will inadvertently share something. As it is, all channels are visually identical. However, this has been requested on UserVoice and despite being pretty popular, it was turned down. I note that pretty much every other request for meaningful customization of the UI has also been either ignored or turned down, for example options to choose text size, font, pinning channels to the side bar, better use of screen space, notification sounds, per-channel notification options, control animations, control emojis... and so on.
  • Some great high level conversation starters in there for the greener Teams customers - thanks.