Are Microsoft's default security and compliance tools Teams good enough?
Microsoft Teams is a rapidly growing communication and collaboration platform for businesses. By the end of 2018, Microsoft Teams had surpassed Slack to become the market leader. Today, more than 329,000 companies use it.
Microsoft Teams is an open platform offering a wide range of collaboration options from any device. This inevitably leads managers IT (CISOs, CIOs, etc.) to consider compliance and security issues.
Companies deploying Teams must ensure that they are as protected as possible during the transition to Microsoft Teams.
Loss of sensitive data
The highly collaborative benefits that employees enjoy can be a major headache for security and compliance teams. Sure, fingertip file sharing is great for workflows, but how do you ensure that sensitive data isn't shared? Preventing data leakage or loss is key to controlling risk with teams.
Although Microsoft Office 365 offers basic features DLP (Data Loss Prevention), they are often not effective enough. Content is typically inspected after it is sent, rather than in real time. Content cannot be blocked or hidden through policies or at the organizational level. If you want to detect and protect sensitive data from leaks, you may want to consider a third-party solution, such as SphereShield.
Advanced tools DLP typically offer built-in rule templates that prevent the sharing of data such as Social Security numbers, credit card numbers, and identification numbers. Additional rules specific to your organization (such as a confidential project name) can always be added. You may want to invest in a solution such as SphereShield, which is tailored for Microsoft teams and can inspect content based on features specific to Teams or integrate with DLP that may not cover Teams.
External users
Working with external business partners can be a dangerous proposition if left unchecked. Knowing who can join these messaging applications is essential to avoid data loss and to remain compliant with regulations.
Microsoft Teams allows users outside your organization to communicate with your employees. You have control over which domains can communicate with users in your organization, but that's about it. You don't have granular control.
![]()
These email policies are not sufficient. They are applied per user (not per group) and are not context sensitive. They do not change based on participants or scope. For example, if settings are made to block a user's file sharing capabilities, they will not be able to share files either internally or externally. This means that you cannot prevent an employee from communicating with external users in a specific and tailored way.
When federating with external companies, you can control two aspects
Who can communicate with whom?
How can they communicate?
The SphereShield Ethical Wall can be used for this purpose. Policies can be applied on users, groups or domains (this solves the "who" part). In addition, granular modality policies can be used to control communication features such as instant messaging, file transfer, teleconferencing, audio, video, etc. Ethical wall strategies can be created to control both intra-organisational communication and inter-organisational communication.
Offline Archiving eDiscovery
Most companies today are subject to compliance regulations that require them to archive information in an accessible manner. This can sometimes be even more challenging for international organizations. Different data laws and consent requirements impact the management of cross-border e-discovery. To address certain security and compliance issues—which we’ve already discussed in this article—Microsoft offers an e-discovery module for O365 that also scans Microsoft Teams. However, advanced e-discovery is not free and requires the E5 license.
In addition, even if you invest in the license, you may want to consider archiving the data on-premises rather than in the cloud. This decision should depend on the sensitivity of the information processed by your company. If you wish to store eDiscovery archives on-premises, you must invest in an alternative solution to Microsoft.
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 139 articles, all of which are freely available.



