A newly uncovered vulnerability in Microsoft Teams puts millions of corporate users at risk of sophisticated malware attacks that can bypass even premium security defenses.
Security researchers warn that attackers can leverage Microsoft’s “chat with anyone” feature to lure users into unprotected tenant environments, sidestepping all Defender for Office 365 safeguards.
Flaw at the Core of Teams’ Guest Collaboration
The root cause of the vulnerability is a significant architectural gap in how Teams handles cross-tenant guest access.
When an employee accepts a chat invitation to another organization’s Teams tenant, they leave the protection of their own company’s security stack.
Instead, their chat activity and files are governed solely by the defenses, if any, implemented by the external tenant.
Most organizations, researchers note, wrongly believe that Defender for Office 365 universally protects their users.
In reality, that protection does not extend into external or guest environments. An attacker setting up a Microsoft 365 tenant, even with a minimal Teams Essentials or Business Basic license, can disable or entirely lack defenses like Safe Links scanning, malware detection, or real-time threat analysis.

The risk is compounded by Microsoft’s November 2025 introduction of feature MC1182004, which enables Teams users to initiate chats with any external address by default, with no opt-in or explicit approval required from organizations.
Attackers can exploit this by sending convincing chat invitations under the guise of a legitimate business contact.
Once the target user enters the attacker’s tenant, any links, files, or malware sent to them evade the protective scrutiny of Defender for Office 365 – because those policies are only enforced in the user’s home tenant, not the resource tenant.
Victims’ organizations are left in the dark about these interactions, undermining costly cybersecurity investments.
Reports by Ontinue highlight that most organizations accept guest invitations from any Microsoft 365 tenant worldwide, further broadening the potential attack scope.
To mitigate the risk, security teams must:
| Mitigation Step | Explanation |
|---|---|
| Restrict B2B Guest Invitations | Use Entra ID External collaboration to allow only trusted domains. |
| Set Granular Cross-Tenant Access Policies | Block or limit B2B collaboration by default; allow only approved domains. |
| Limit External Teams Communication | Use Teams Admin Center settings to restrict chats with external domains. |
| Turn Off MC1182004 (Chat with Anyone) Feature | Possible via PowerShell, but only blocks outbound invitations, not inbound from attackers. |
This vulnerability is not a technical defect in Teams, but a result of how Microsoft’s architecture treats guest access.
Security boundaries follow the resource tenant, meaning security teams must proactively lock down guest access and cross-tenant collaboration if they want to shield users from stealthy phishing and malware attacks.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates