Teams Meeting Lobby: Alleen Organization Members Bypassen
π 2025-10-30
β’
β±οΈ 7 minuten lezen
β’
π΄ Must-Have
πΌ Management Samenvatting
Het configureren van Teams meeting lobby zodat alleen organization members automatisch worden toegelaten (AutoAdmittedUsers is EveryoneInCompany) zorgt ervoor dat alle external participants (guests, federated, anonymous) in de lobby wachten totdat de meeting organizer hen explicit admitted, waardoor meeting security wordt verbeterd en ungeautoriseerde access wordt voorkomen.
Aanbeveling
IMPLEMENT
Risico zonder
Medium
Risk Score
6/10
Implementatie
3u (tech: 1u)
Van toepassing op:
β Microsoft Teams β M365
Teams meeting lobby is een security control die bepaalt WIE automatisch meetings kan joinen vs. WIE moet wachten voor organizer approval. Zonder proper lobby restrictions: EXTERNAL PARTICIPANTS krijgen instant meeting access zonder verification waarbij: competitors kunnen meetings joinen zonder check, ungeautoriseerde guests infiltreren discussions, recording bots kunnen data harvesten; EAVESDROPPING RISKS waarbij: uninvited external attendees confidential discussions horen, meeting recordings worden gemaakt door ungeautoriseerde parties, business intelligence leaks naar externe partijen; NO ACCOUNTABILITY omdat: organizer niet weet wie meeting joined (automatische admission is no review), external attendees kunnen anonymous blijven (minimal identity verification), audittrail incomplete (who really attended?). Real-world scenarios: Sales meeting met customers β Competitor analyst joins via guessed meeting link β Overhears pricing strategy discussions, Executive strategy meeting β External party joins uninvited β Records entire discussion β Corporate intel leaked, Confidential HR discussion β Ungeautoriseerde employee joins β Privacy violations. Lobby control mitigates dit door: Organization members (employees) bypass lobby automatische (convenience), External participants (guests, federated, anonymous) moet wait in lobby (security), Organizer expliciet admits elke external attendee (verification), Rejected participants kan niet join (access denied). Dit balances productivity (internal fast join) met security (external controlled admission).
PowerShell Modules Vereist
Primary API: Teams PowerShell Connection:Connect-MicrosoftTeams Required Modules: MicrosoftTeams
Implementatie
Deze control configureert Teams Meeting Policy setting AutoAdmittedUsers is EveryoneInCompany (of EveryoneInSameAndFederatedCompany if federated partners trusted). Effect per participant type: ORGANIZATION MEMBERS (employees met M365 license binnen tenant): Bypass lobby automatic, Instant meeting join, No waiting; EXTERNAL PARTICIPANTS mΓΌssen wachten: Anonymous users (no auth): Lobby, Organizer moet admit, Guests (B2B invited users): Lobby, Organizer verification vereist, Federated users (external org M365): Depends - met EveryoneInCompany is lobby, met EveryoneInSameAndFederatedCompany is bypass (if vertrouwde federation); LOBBY WORKFLOW: External participant joins meeting β Enters lobby (waiting room), Organizer sees notification: '[Name] is waiting in lobby', Organizer admits (allow) of denies (reject), Admitted participant joins meeting, Rejected gets access denied message. Best practice configuration: AutoAdmittedUsers is EveryoneInCompany (STRICTest - zelfs federated moet wait), Alternative (if heavy federated collaboration): EveryoneInSameAndFederatedCompany (trust federated orgs), AVOID: Everyone (no lobby control - security risk), Per-meeting override: Organizers can adjust per specific meeting if needed. aanvullend lobby settings: AllowPSTNUsersToBypassLobby is False (dial-in users wait too), AutoAdmittedUsersType governs behavior. Implementation via Teams admin center β Meeting policies.
Teams admin center β Meetings β Meeting policies
Select Global policy (applies to alle users) of Maak aan specific policy
Participants & guests section:
- automatisch admit people: People in my organization (aanbevolen)
Alternative: People in my organization en vertrouwde organizations (if federated)
AVOID: Everyone (no lobby control)
- Dial-in gebruikers kunnen bypass lobby: Off (PSTN users wait too)
Save policy
Test: External participant joins meeting β zou moeten wait in lobby
Train organizers: hoe to admit van lobby (click 'Admit' button)
Connect-MicrosoftTeams
Configureer Global policy: Set-CsTeamsMeetingPolicy -Identity Global -AutoAdmittedUsers 'EveryoneInCompany'
Alternative voor federated: Set-CsTeamsMeetingPolicy -Identity Global -AutoAdmittedUsers 'EveryoneInSameAndFederatedCompany'
Verify: Get-CsTeamsMeetingPolicy -Identity Global | Select AutoAdmittedUsers
Vereisten
Microsoft Teams licentie (M365 E3/E5, Business Premium)
Teams Administrator of Globale beheerder rechtenistrator rol
Organizer feedback: Is lobby workflow manageable? ook veel admits?
beveiligingsincidenten: Ungeautoriseerde meeting joins (zou moeten zijn 0 met lobby)
User complaints: External participants delayed door lobby? (acceptable trade-off)
Compliance en Auditing
Lobby regelt dragen bij aan meeting security compliance: CIS Microsoft 365 Foundations Benchmark - control 4.1.3 (Zorg ervoor dat meeting lobby is geconfigureerd appropriately), BIO 11.02 (Toegangsbeveiliging - Access verification), ISO 27001:2022 A.11.1.5 (Segregation - Physical en logical separation), NIS2 Artikel 21 (Toegangscontrole en authenticaties voor vergaderingen met gevoelige informatie). Lobby control voorkomt ungeautoriseerde access tot business discussions.
Remediatie
Gebruik PowerShell-script lobby-org-only.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
CIS M365: Control 4.1.3 (L1) - Zorg ervoor dat meeting lobby geconfigureerd to restrict external participants
BIO: 11.02.01 - Toegangsbeveiliging - Verification van deelnemers
ISO 27001:2022: A.11.1.5 - Segregation - Organization vs external separation
NIS2: Artikel - Toegangscontrole en authenticaties voor meetings
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).
Medium: MEDIUM RISICO: External participants zonder lobby control is ungeautoriseerde meeting access. Competitors, uninvited guests, recording bots kunnen meetings joinen zonder verification. Business confidential discussions exposure. Recent: Zoom-bombing equivalents in Teams waarbij ungeautoriseerde parties disrupt/record meetings. Lobby control is organizer gate-keeps external access (verification voordat admit).
Management Samenvatting
Configureer Teams lobby: AutoAdmittedUsers is EveryoneInCompany. Organization members bypass lobby (convenience), external participants wait voor organizer admission (security). Voldoet aan CIS 4.1.3, BIO 11.02. Implementatie: 1-3 uur inclusief organizer training. aanbevolen voor alle organizations met external meeting participants.