Microsoft Teams external communication policy was modified
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Microsoft Teams
ATT&CK Tactic
Exfiltration (TA0010), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Exfiltration Over Alternative Protocol (T1048)
Severity
Informational
Description
Microsoft Teams external communication policy was modified.
Attacker's Goals
Attackers may modify the external communication policy to enable data exfiltration or to hide their activities.
Investigative actions
Determine if it is within the user's role to modify the policy.
Verify whether the modification of the policy is both legitimate and necessary.
Follow further communication with the external tenant or allowed tenants.
Correlate the event with its sign-in event to get additional information on the identity performing the action using the session ID.
Variations
Was this helpful?
