Forum Discussion

SamG_A's avatar
SamG_A
Copper Contributor
May 25, 2020
Solved

Backdoor for Guest Users to see unauthorized Private Channel Files within a Team

Hi   I have a situation where Guest users can see content they have not been given access to.   Situation:  - I have an MS Team - It has two Private Channels: Alpha and Bravo - A guest users i...
  • SamG_A's avatar
    SamG_A
    May 26, 2020

    @adam deltinger  We resolved the issue.

     

    Team Bravo was originally created before Private Channels came into existence last year. The original channel was a public channel.

     

    After private channels came out the follow happened:

    • a new private channel was created with a similar name
    • the Files content was copied across
    • the old public channel was deleted in Teams

     

    Unbeknownst to us, the public channel Files content is not deleted from Sharepoint when a channel is deleted in Teams.

     

    What was happening is that new guest users were able to access this residual public channel content. It appeared like current private team content because it had the same name and content up to the date is was migrated.

Resources