SOLVED

Request Change to Microsoft Teams documentation

%3CLINGO-SUB%20id%3D%22lingo-sub-1552923%22%20slang%3D%22en-US%22%3ERequest%20Change%20to%20Microsoft%20Teams%20documentation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1552923%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EApologies%20if%20this%20is%20the%20wrong%20location%2C%20but%20how%20does%20one%20go%20about%20requesting%20a%20change%20to%20Teams%20official%20documentation%3F%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EUnfortunately%2C%20the%20company%20I%20work%20for%20hasn't%20%3CU%3Eyet%3C%2FU%3E%20(it's%20planned)%20sent%20myself%20or%20the%20local%20IT%20team%20on%20official%20Microsoft%20training%20for%20Teams%2C%20but%20we%20have%20been%20requested%20to%20implement%20Team%20in-house%20ASAP%20and%20without%20any%20third%20party%20%2F%20consultation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20something%20I%20am%20aware%20that%20is%20very%20common%20in%20the%20IT%20space%2C%20and%20thus%20it's%20the%20reason%20why%20so%20many%20of%20us%20rely%20on%20good%20documentation.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20without%20further%20ado%20we%20started%20reading%20the%20docs%20from%20Microsoft%20and%20got%20to%20the%20point%20of%20external%20%2F%20guest%20collaboration%2C%20and%20luckily%20we%20(myself%20and%20my%20team)%20naturally%20err%20on%20the%20side%20of%20caution%20when%20it%20comes%20to%20security%2C%20and%20often%20find%20ourselves%20challenging%20documentation%20as%20it's%20quite%20often%20written%20on%20the%20side%20of%20%22getting%20it%20done%22%2C%20rather%20than%20getting%20it%20done%20%22securely%22.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20we%20know%2C%20Teams%20is%20a%20large%20interconnected%20system%20made%20up%20of%20various%20components%3B%20Teams%2C%20Office%20365%20Groups%2C%20Sharepoint%20sides%2C%20Azure%2C%20OneDrive%2C%20etc.%20The%20last%20thing%20we%20wanted%20to%20do%20was%20to%20allow%20%22guests%22%20into%20our%20system%20and%20have%20a%20problem%20of%20Confidentiality%20on%20our%20hands!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20were%20therefore%20surprised%20to%20read%20the%20following%20'Checklist'%20on%20how%20to%20Enable%20Guest%20Access%20in%20Microsoft%20Teams%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fguest-access-checklist%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fguest-access-checklist%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20are%20a%20few%20areas%20in%20this%20doc%20which%20very%20much%20fall%20into%20the%20%22getting%20it%20done%22%20camp%2C%20rather%20than%20getting%20it%20done%20%22securely%22%20camp.%20For%20examples%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%26nbsp%3BMake%20sure%20that%20the%20Let%20group%20owners%20add%20people%20outside%20the%20organization%20to%20groups%20check%20box%20is%20selected.%20-%20For%20the%20Office%20365%20Group%20settings.%3C%2FP%3E%3CP%3E2.%26nbsp%3B%3CSPAN%3EMake%20sure%20that%20the%20option%20is%20set%20to%26nbsp%3B%3C%2FSPAN%3EAnyone%26nbsp%3Bor%26nbsp%3BNew%20and%20existing%20guests.%20-%20For%20SharePoint%20site%20sharing%20settings.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20question%20%2F%20point%20is%20that%20what%20have%20these%20got%20to%20do%20with%20allowing%20Guests%20into%20the%20system%3F%20The%20answer%20is%20that%20%3CSTRONG%3Eneither%20of%20these%20settings%20are%20needed%20for%20Guest%20access%20to%20Teams%3C%2FSTRONG%3E%20%3CSTRONG%3Edespite%20the%20article%20alluding%20that%20they%20are%3C%2FSTRONG%3E%2C%20but%20instead%20these%20settings%20are%20needed%20for%20sharing%20files%20whilst%20within%20Teams.%20If%20of%20course%20you%20do%20not%20want%20to%20allow%20guests%20to%20share%20files%20with%20internal%20users%20then%20do%20NOT%20set%20these%20two%20options.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20I%20very%20much%20see%20this%20as%20hang%20up%20of%20days%20which%20I%20hoped%20where%20long%20forgotten%2C%20but%20clearly%20not.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThose%20days%20being%20%3D%20Microsoft%20(everything%20is%20turned%20on%20by%20default%20and%20you%20have%20to%20know%20it%20exists%20to%20lower%20your%20risk)%20Vs%20Linux%2C%20etc%20(it's%20generally%20turned%20off%20unless%20you%20need%20it%2C%20in%20which%20case%20you%20turn%20it%20on).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20this%20interconnected%20day%20and%20age%20it%20would%20be%20nice%20to%20see%20Microsoft%20err%20on%20the%20side%20of%20caution%20too%2C%20and%20perhaps%20that%20is%20still%20allowing%20the%20options%20to%20allow%20sharing%20for%20everyone%2C%20but%20explain%20more%20clearly%20as%20to%20what%20this%20does%20and%20the%20associated%20risks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20searched%20the%20internet%20to%20find%20more%20information%20on%20these%20check%20boxes%20and%20unfortunately%20it%20comes%20down%20to%20blogs%20to%20determine%20the%20real%20changes%20these%20settings%20make%20in%20the%20back-end.%20I%20don't%20feel%20that%20that's%20the%20correct%20answer%20for%20this.%20-%20I%20believe%20it's%20up%20to%20those%20that%20create%20the%20systems%20and%20services%20to%20think%20long%20and%20hard%20about%20what%20an%20option%20does%20and%20really%20give%20the%20end%20user%20%2F%20admin%20the%20correct%20and%20up-to-date%20information%20to%20make%20the%20correct%20decision.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20not%20a%20rant%2C%20but%20an%20observation%20that%20I%20know%20a%20lot%20of%20my%20peers%20would%20agree%20with%2C%20and%20I%20believe%20that%20we%20all%20have%20shared%20responsibility%20to%20help%20everyone%20out%3B%20be%20that%20a%20large%20company%20with%20lots%20of%20trained%20staff%20or%20a%20small%20company%20with%20limited%20budget.%20Security%20is%20paramount%20and%20it's%20very%20much%20linked%20to%20education%20and%20awareness%20through%20good%20documentation.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks%20for%20your%20time.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJohn%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1552923%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdministrator%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EBest%20Practices%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EFiles%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESettings%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1553486%22%20slang%3D%22en-US%22%3ERe%3A%20Request%20Change%20to%20Microsoft%20Teams%20documentation%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1553486%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20leave%20feedback%20directly%20under%20(most)%20Docs.com%20articles%2C%20just%20scroll%20to%20the%20bottom%20of%20the%20page%20and%20use%20the%20corresponding%20controls.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThat%20said%2C%20those%20two%20settings%20are%20needed%20if%20you%20want%20to%20have%20the%20%22full%22%20Guest%20experience%20enabled.%20In%20other%20words%20this%20is%20the%20%22supported%22%20configuration.%20It%20doesn't%20mean%20it's%20the%20only%20configuration%20that%20will%20work%2C%20but%20it%20is%20how%20Microsoft%20designed%20the%20product%20and%20how%20they%20expect%20it%20to%20be%20configured.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

Hi all, 

 

Apologies if this is the wrong location, but how does one go about requesting a change to Teams official documentation? 

Unfortunately, the company I work for hasn't yet (it's planned) sent myself or the local IT team on official Microsoft training for Teams, but we have been requested to implement Team in-house ASAP and without any third party / consultation.

 

This is something I am aware that is very common in the IT space, and thus it's the reason why so many of us rely on good documentation.

 

So, without further ado we started reading the docs from Microsoft and got to the point of external / guest collaboration, and luckily we (myself and my team) naturally err on the side of caution when it comes to security, and often find ourselves challenging documentation as it's quite often written on the side of "getting it done", rather than getting it done "securely". 

 

As we know, Teams is a large interconnected system made up of various components; Teams, Office 365 Groups, Sharepoint sides, Azure, OneDrive, etc. The last thing we wanted to do was to allow "guests" into our system and have a problem of Confidentiality on our hands!

 

We were therefore surprised to read the following 'Checklist' on how to Enable Guest Access in Microsoft Teams: https://docs.microsoft.com/en-us/microsoftteams/guest-access-checklist

 

There are a few areas in this doc which very much fall into the "getting it done" camp, rather than getting it done "securely" camp. For examples:

 

1. Make sure that the Let group owners add people outside the organization to groups check box is selected. - For the Office 365 Group settings.

2. Make sure that the option is set to Anyone or New and existing guests. - For SharePoint site sharing settings. 

 

My question / point is that what have these got to do with allowing Guests into the system? The answer is that neither of these settings are needed for Guest access to Teams despite the article alluding that they are, but instead these settings are needed for sharing files whilst within Teams. If of course you do not want to allow guests to share files with internal users then do NOT set these two options.

 

Unfortunately I very much see this as hang up of days which I hoped where long forgotten, but clearly not. 

 

Those days being = Microsoft (everything is turned on by default and you have to know it exists to lower your risk) Vs Linux, etc (it's generally turned off unless you need it, in which case you turn it on).

 

In this interconnected day and age it would be nice to see Microsoft err on the side of caution too, and perhaps that is still allowing the options to allow sharing for everyone, but explain more clearly as to what this does and the associated risks.

 

I searched the internet to find more information on these check boxes and unfortunately it comes down to blogs to determine the real changes these settings make in the back-end. I don't feel that that's the correct answer for this. - I believe it's up to those that create the systems and services to think long and hard about what an option does and really give the end user / admin the correct and up-to-date information to make the correct decision.

 

This is not a rant, but an observation that I know a lot of my peers would agree with, and I believe that we all have shared responsibility to help everyone out; be that a large company with lots of trained staff or a small company with limited budget. Security is paramount and it's very much linked to education and awareness through good documentation. 

 

Many thanks for your time.

 

John

 

 

1 Reply
Highlighted
Best Response confirmed by ThereseSolimeno (Microsoft)
Solution

You can leave feedback directly under (most) Docs.com articles, just scroll to the bottom of the page and use the corresponding controls.

 

That said, those two settings are needed if you want to have the "full" Guest experience enabled. In other words this is the "supported" configuration. It doesn't mean it's the only configuration that will work, but it is how Microsoft designed the product and how they expect it to be configured.