Microsoft has launched a new bot protection capability in Microsoft Teams, giving IT administrators and meeting organizers stronger control over external bots attempting to join meetings.
The update responds to mounting privacy and security concerns tied to the rapid adoption of AI-powered meeting assistants.
As AI note-taking bots become standard fixtures in corporate meetings, a troubling side effect has surfaced: bots joining sessions without explicit user consent.
Several organizations that integrate third-party meeting tools have reported that the associated bots continue to auto-join future meetings, raising unintended surveillance risks, especially in discussions involving confidential or sensitive information.
Microsoft Teams Adds Bot Protection
This announcement follows Microsoft’s earlier rollout of a workplace presence feature that automatically updates a user’s location status when connecting to organizational Wi-Fi, reflecting the company’s broader push toward context-aware Teams functionality.
Microsoft has introduced a dedicated policy, “Manage external bots and their access to meetings,” now live in the Teams Admin Center. Administrators can assign this policy at the user or group level, with two configuration modes:
- Require approval before joining (default): Teams flags suspected bots, redirects them to the meeting lobby, and mandates organizer approval before admission.
- Do not detect bots: Fully disables detection.
Bot detection ships enabled by default across all tenants, so organizations get baseline protection without manual setup.
According to Microsoft’s technical breakdown, the detection engine relies on a mix of behavioral and infrastructure signals to distinguish bots from human participants with improved accuracy.
Alongside detection, Microsoft launched the Teams Bot Identification Program, allowing Independent Software Vendors that build Teams-integrated meeting tools to register their bots.
Registered providers embed a self-identification marker in join requests, allowing Teams to classify them as verified participants rather than flagging them as suspicious.
When the policy is active, detected bots are placed into the meeting lobby and visually separated from human attendees.
Organizers see two distinct categories: a “Waiting” group containing verified participants and registered bots, and a “Suspected Threats” group containing unregistered or system-flagged bots.
This segmentation lets organizers triage lobby requests at a glance instead of manually scanning the full participant list. Microsoft has also built in deliberate friction to prevent accidental admissions.
There is no one-click “Admit” option for flagged bots; confirmation prompts appear whenever an admission includes a bot, and warning dialogs trigger when an organizer selects “Admit All” while bots remain in the queue.
This new framework effectively retires Teams’ existing CAPTCHA verification system, with the CAPTCHA policy slated for full removal from the Admin Center by late August 2026. Microsoft has outlined further expansions to the bot management ecosystem.
Planned additions include allow lists for pre-approved bots, organization-wide policies to block all external bots outright, admin audit logs and detection reports, and more granular controls tailored to varied security postures.
The feature reached global general availability in early-to-mid June 2026, with GCC environments receiving the rollout on the same timeline.
Microsoft recommends administrators configure the “Who can admit from lobby” setting to restrict admission rights to organizers and co-organizers only, closing off any pathway for unintended bot admission by non-host participants.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
