A user can record & share Teams sessions using MS Streams. When sharing the video, there is an option to "Allow everyone on your company to view this video".
This is highly misleading description. In fact when selecting this, the video is shared with everybody that has an E1+ account in the tenant. The assumption that this is "the company" is a pure assumption on Microsoft's part. In our case (multi national group) people believe this is "my company" (ACME Inc) when in fact this ACME SA, ACME GmbH and ACME Ltd. Furthermore this includes all partners (e.g. contractors) that might have an account. As a result, this leads to continuous and repeating security incidents since users may select this option by taking it's label for face value.
Request: * Correct the wording to correctly describe what this is AND * Include a admin option to remove this option alltogether
... View more