Forum Discussion
Thomsch
Dec 22, 2020Iron Contributor
Only owners can post messages - but users can create channel meetings
We have a department team with a "General" channel. Only owners are allowed to post messages there. But by accident a user created a channel meeting at this "General" channel. Since it is a "only own...
Khgr99
Nov 08, 2022Copper Contributor
I am not sure why this thread is not getting more attention. Not only does this bypass security, but it also does not allow the owner to delete the posting on the channel. Non owners can now start a thread and reply to it on an all staff team. Microsoft, please fix this vulnerability. This is not how it should work by design. If the settings in Teams are set to now allow members to post, this feature needs to follow the security setup. If the Team is set up so that owners can delete messages, this feature should follow the Teams security that is set. This issue could be a significant issue for large all staff Teams. Members can directly communicate with all staff with no security to block them from doing so.