For the complete documentation index, see llms.txt. This page is also available as Markdown.

Microsoft Teams external communication policy was modified

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Microsoft Teams

ATT&CK Tactic

Exfiltration (TA0010), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Exfiltration Over Alternative Protocol (T1048)

Severity

Informational

Description

Microsoft Teams external communication policy was modified.

Attacker's Goals

Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.

Investigative actions

  • Determine if it is within the user's role to modify the policy.

  • Verify whether the modification of the policy is both legitimate and necessary.

  • Follow further communication with the external tenant or allowed tenants.

  • Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.

Variations

Microsoft Teams external communication policy was modified by an unusual user

Synopsis

Field
Value

ATT&CK Tactic

Exfiltration (TA0010), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Exfiltration Over Alternative Protocol (T1048)

Severity

Low

Description

Microsoft Teams external communication policy was modified.

Attacker's Goals

Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.

Investigative actions

  • Determine if it is within the user's role to modify the policy.

  • Verify whether the modification of the policy is both legitimate and necessary.

  • Follow further communication with the external tenant or allowed tenants.

  • Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.

Was this helpful?