Users still can call& join external Teams users; even though External Access is set to “Block all external domains”?

Amruth Sai 0 Reputation points
2026-03-16T19:45:47.3533333+00:00

I have configured the following setting in the Teams Admin Center:

Teams Admin Center → External collaboration → External access → Teams and Skype for Business users in external organizations → Block all external domains

My understanding is that this should prevent all external communication ( group meetings and 1:1), including calls and chats, with users in other Microsoft 365 tenants.

However, I am still able to join call to an external Teams user meeting initiated and they can also call me. I am trying to understand why this is happening.

Microsoft Teams | Microsoft Teams for business | Meetings and calls | Other

3 answers

Sort by: Most helpful
  1. Ruby-N 13,320 Reputation points Microsoft External Staff Moderator
    2026-03-18T22:54:09.66+00:00

    Dear @Amruth Sai

    Thank you for taking the time to summarize each setting so clearly. I appreciate the effort you put into reviewing the configuration points, and I am glad the earlier guidance was helpful. I went through all four of your notes and would like to clarify each one, so the behavior of Teams becomes fully clear and predictable.

    1/ External access: Block all external domains

    Your understanding is correct. When External access is set to Block all external domains, users in your organization cannot start or receive federated one‑to‑one chats or calls with other Microsoft 365 organizations. This setting controls chat and calling federation only. It doesn’t affect whether someone can join a meeting through a meeting link.

    2/ Joining meetings hosted by other organizations

    This part is also correct. The setting People can join external meetings hosted by inside the meeting policy decides whether signed‑in users in your organization are allowed to join meetings created in other tenants.

    If this is set to No one, users can only join meetings hosted inside your own organization.

    One important note is that this applies only to signed‑in users. A user can still join an external meeting anonymously if they sign out and the external organizer allows anonymous joining.

    3/ Allowing external or anonymous attendees to join meetings you host

    Your summary is on the right track. There are two layers that work together.

    • The first layer is the organization‑wide setting Anonymous users can join a meeting. The current Microsoft recommendation is to keep this enabled and manage anonymous participation through meeting policies.
    • The second layer is the meeting policy assigned to your organizers or each meeting’s Meeting options. When Who can bypass the lobby is set to People in my organization, any external or anonymous attendee will remain in the lobby until someone from your organization admits them. This gives full control while still allowing you to admit external participants when needed.

    4/ About not seeing the “block specific users” option

    What you are seeing is expected with the updated security experience. When Allow my security team to manage blocked domains and blocked users is enabled, all domain and user blocking moves to the Microsoft Defender portal. It is managed under the Tenant Allow/Block List for Teams senders.

    This is why the option shown in earlier screenshots does not appear in your Teams Admin Center. Nothing is missing in your tenant. The user interface is simply using the new model.

    If you want to block a specific external domain or user, you can follow these steps:

    • In Teams Admin Center, go to External collaboration settings > Enable Allow my security team to manage blocked domains and blocked users.

    User's image

    • Open the Microsoft Defender portal (Microsoft 365 admin center > Security).
    • Go to the Tenant Allow/Block List.
    • Add the external domain or email address under Teams senders.

    User's image

    New chats, calls and meeting invitations from those entries will be blocked.

    This article provides further guidance on the topic: Block domains and addresses in Microsoft Teams using the Tenant Allow/Block List - Microsoft Defend…

    I hope this explanation provides the clarity you were looking for. If there is anything else you would like to review or confirm, I am always here to help.

    Thank you for your detailed follow-up, as well as your patience and understanding throughout this troubleshooting process.  

    Was this answer helpful?

    3 people found this answer helpful.

  2. Ruby-N 13,320 Reputation points Microsoft External Staff Moderator
    2026-03-16T21:57:52.8+00:00

    Dear @Amruth Sai

    Thanks for providing the details about the behavior you're seeing. I understand how important it is to ensure external communication is controlled in the way your organization expects. 

    The “Block all external domains” setting only blocks federated chat and one‑to‑one calls. It does not stop users from joining meetings by clicking a link. Meeting access depends on the organizer’s tenant policies, including whether anonymous join is allowed. If anonymous join is enabled in the host tenant, your users can still join anonymously even when external domains are blocked. 

    Users may still join or be contacted through other paths. Guest users can chat, call, and join meetings because they are treated as internal users in the host directory. Also, unless restricted, users are allowed to join meetings hosted by external organizations by default. 

    If your goal is to fully prevent external communication, including joining external meetings or being contacted by external tenants, the following steps provide a complete approach. These settings complement each other and work best when configured together. 

    Step 1: Maintain External Access as blocked 

    I know this setting is already enabled on your side, but it would be helpful to double‑check that it is configured correctly. 

    This stops federated chat and one‑to‑one calls.  

    • Open Microsoft Entra admin center > Go to External identities > Select Cross-tenant access settings > Under External collaboration settings, set Allow invitations only to the specified domains. 

    User's image

    Verify that both the organization’s global setting and any user‑level policies reflect the same configuration to avoid conflicts. 

    User's image

    Additionally, you can also block specific external users from collaborating with your organization. When someone is added to the blocklist, they can no longer participate in one‑to‑one or group chats with your users. If a chat already exists, the blocked user will be removed. This feature is off by default. 

    • Open Teams admin center and go to External collaboration settings > External access. 
    • Turn on Block specific users from communicating with people in my organization. 
    • Select Block a user > Enter the external user’s email address and select Apply. 

    User's image

    Step 2: Restrict joining external meetings 

    • Create or update a meeting policy so that the option “People can join external meetings hosted by” is set to “No one”.  

    This ensures that users cannot join meetings hosted by other tenants when signed in with their work account.  

    • The policy can be found under Teams admin center > Meetings > Meeting policies > Meeting join and lobby. 

    User's image

    Step 3: Disable anonymous join 

    • In Teams admin center, go to Meetings > Meeting settings > Turn off “Anonymous users can join a meeting”.  

    User's image

    This prevents users from entering meetings anonymously.  

    When anonymous join is disabled on your side and external meeting join is restricted, users will not be able to join external meetings through an anonymous link. 

    Step 4: Review guest access 

    • If your organization does not allow any form of cross‑tenant collaboration, turn off Teams guest access in the Teams admin center under External collaboration settings > Guest access. 

    User's image

    Consider removing existing guest accounts as well, because guests can continue to participate in chat, calls, and meetings as long as their accounts remain active.  

    • To remove existing guest users, open Microsoft Entra admin center: Go to Identity > Users > External users and remove any unwanted guest accounts. 

    Step 5: Allow time for policy propagation 

    After applying the changes, allow up to 24 hours for the policies to fully propagate across all clients before re‑testing. 

    Step 6: Contact Microsoft Support 

    After reviewing all the steps above and the issue still persists, I sincerely recommend that you create a support ticket via Microsoft 365 Admin Center > Support > Help & Support for further investigation.  

    A technical support engineer can perform a remote session to investigate the situation, verify the backend configurations, and run any necessary synchronization tools to resolve the problem. If the issue requires further attention, they can escalate it to a specialized team for deeper analysis.    

    As community moderators, we kindly ask for your understanding that our access to internal development details is limited. Our primary role is to guide users toward the appropriate resources and support channels. While we may not have visibility into performing deeper backend analysis, we’ll continue doing our best to support you within the scope of our responsibilities.  

    I hope this information is helpful. If you have any questions or need further support, please don’t hesitate to reach out at any time. 

    Thank you for your patience and understanding. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have any extra questions about this answer, please click "Comment".            

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


  3. AI answer

    2026-03-16T19:46:02.42+00:00

    "Block all external domains" in Teams external access only controls federated chat and meetings between Microsoft 365 organizations. It does not block every way an external user can join or interact with meetings.

    The behavior described can occur for these main reasons:

    1. Anonymous join is still allowed
      Even if all external domains are blocked, external participants can still join meetings as anonymous users if anonymous join is enabled:
      • At the organization level in Teams meeting settings.
      • In the meeting policies assigned to the organizers.
      The resolution pattern in the documentation shows that to block all external participants, both of these must be disabled:
      1. Disable anonymous join in the organization meeting settings.
      2. Block external access.
      3. Turn off guest access.
      If anonymous join is on, external users whose domains are blocked will still be able to join as anonymous participants. This matches the note that if the organizer’s domain is blocked or not allowed in the external access settings of the external participant’s org, they can only join as anonymous users.
    2. Guest access is different from external access
      External access (federation) and guest access are separate features:
      • External access: chat/meetings with users in other Microsoft 365 organizations who stay signed in to their own tenant.
      • Guest access: users are invited as guests (B2B accounts) into the tenant and join teams/channels.
      Blocking all external domains in external access does not disable guest access. If the external user has been added as a guest in the tenant, they can still be invited to and join meetings as guests unless guest access is turned off.
    3. External meeting participation is also controlled by meeting policies
      Meeting policies can allow external/anonymous users to join meetings even when external access is blocked. For example:
      • "Anonymous users can join a meeting" set to On.
      • "People can join external meetings hosted by" set to Anyone.
      These settings are per-organizer and can override the intent of blocking external domains if not aligned.
    4. External access policies and granular domain controls
      External access policies can be scoped per user or group and may:
      • Enable federation access for specific users even if the org-wide default is more restrictive.
      • Use granular domain lists that differ from the organization settings.
      If a custom external access policy is assigned to certain users with federation enabled or with different domain rules, those users can still communicate externally despite the org-wide "Block all external domains" setting.
    5. External users joining as anonymous when their domain is blocked
      The documentation explicitly notes that if a meeting organizer’s domain is blocked or not allowed in the external participant’s organization, the external participant can still join as an anonymous user when anonymous join is enabled. This explains why calls/meetings can still occur even when domains are blocked.

    To align behavior with the expectation of no external communication:

    1. In the Teams admin center:
      • Go to MeetingsMeeting settings and disable anonymous join.
      • Go to UsersExternal access and keep Teams and Skype for Business users in external organizations set to Block all external domains.
      • Go to UsersGuest access and set Allow guest access in Teams to Off if guests should not be allowed.
    2. Verify external access policies:
      • Under UsersExternal access → Policies, ensure no custom policy is granting federation or different domain rules to specific users.
    3. Confirm that meeting policies assigned to organizers do not allow anonymous users to join or external meeting chat if the goal is to fully block external participants.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.