Rampant Teams phish calls

KBadejo 75 Reputation points
2026-06-23T20:20:14.3266667+00:00

Hello All,

Our org users are getting constant phish calls through Microsoft Teams.

We do not want to blanket ban all external domains from communicating.

Is there any options that can be set in external collaboration to prevent this from happening?

Microsoft Teams | Microsoft Teams for business | Meetings and calls | Audio and video
0 comments No comments

1 answer

Sort by: Most helpful
  1. Chris Duong 10,040 Reputation points Microsoft External Staff Moderator
    2026-06-23T21:30:58.9+00:00

    Hi KBadejo

    Good day. Thank you for reaching out, and I appreciate you sharing the details of your situation.

    Just a quick note before we continue: this is a user-to-user community forum, so I don’t have access to your Microsoft 365 tenant, your account, or your device to make changes directly. However, I’m here to support you the best I can within these constraints, by providing clear next steps, sharing applicable resources, and directing you to the appropriate support channels.  

    After reviewing your case, you do not necessarily need to block all external communication. Microsoft Teams provides several options that can help reduce this risk while still allowing collaboration with trusted external organizations. 

    You can follow the steps below:

    (Some of the settings below may require admin permissions. If you do not have the required admin rights, please contact your organization’s IT team for further assistance.) 

    1/ Block specific external domains or allow only trusted domains 

    If the phishing calls are coming from known external domains, you can block those specific domains instead of disabling external access completely. 

    • Go to Teams admin center > External collaboration > External access. 
    • Under Allow or block external domains, you can select Block only specific external domains and add the malicious or unwanted domains to the blocked list. 
    • User's image
    • However, if the phishing calls are coming from multiple unknown or changing domains, a more secure approach would be to select Allow only specific external domains and add only trusted partner, vendor, or customer domains to the allowed list. 
    • User's image
    • This allows your organization to continue external collaboration with approved organizations while reducing communication from suspicious or untrusted external domains. 
    • Reference: IT Admins - Manage external meetings and chat with people and organizations using Microsoft identit… 

    2/ Block specific external users or senders 

    If you are able to identify the specific external accounts involved, you can also block individual external users or sender addresses.  

    • This can be managed through the Tenant Allow/Block List in the Microsoft Defender portal, depending on your environment and available licensing. 
    • Microsoft Defender portal > Email & collaboration > Policies & rules > Threat policies > Tenant Allow/Block Lists > Teams senders 
      • Select Block, then add the external email address or domain that you want to block from communicating with users in your organization through Teams. 
      • User's image
      • This is useful when the issue is caused by specific accounts rather than an entire external domain. 
    • Reference: Block domains and addresses in Microsoft Teams using the Tenant Allow/Block List - Microsoft Defend… 

    3/ Apply more restrictive policies to specific users or groups 

    In case only certain users or departments are being targeted, you may consider applying more restrictive external access policies to those users or groups. 

    For example: 

    • Executives, Finance, or HR users can be restricted to trusted external domains only. 
    • Sales or partnership teams can continue to have broader external collaboration if required. 
    • General users can have a more limited external access policy. 

    This allows you to balance security requirements with business collaboration needs. 

    Additionally, if needed, your IT team can also raise a support ticket with Microsoft Support through the Microsoft 365 Admin Center for deeper investigation. They have access to backend configurations and can perform a more in-depth investigation. At the very least, they can provide the most effective workaround to ensure your experience remains smooth and secure.      

    I hope this information is helpful. Should you have any further questions or need additional assistance, please feel free to share them in the comment below. I'm very happy to help.  

    Thank you again for your patience and understanding. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it.

    Note: Follow the steps in our documentation to enable email notifications if you want to receive email notifications related to this topic.  

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.