General
This check verifies whether it is disabled for channels in Microsoft Teams to be reachable via email.
Rationale
Since the email addresses of Teams channels fall outside the organization's email domain, fewer security controls are available. This allows outsiders and thus attackers to send messages directly into the organization.
Attic Fix
A fix is available for this check! It will be offered via a ticket in Attic, which you can then accept.
Manual Instructions
Follow these steps to adjust the setting:
- Open Teams Admin > https://admin.teams.microsoft.com/
- Go to Teams > Teams settings
- Under Email integration, set the option Users can send emails to a channel email address to Off
- Click on Save
CIS Mapping
-
CIS Item: 8.1.2 (L1) Ensure users can't send emails to a channel email address
-
Profile: E3 Level 1
Comments
0 comments
Please sign in to leave a comment.