Microsoft Teams to Enhance Bot Security with Lobby Labeling and Explicit Approval
Microsoft is bolstering security within its Teams platform by implementing a new feature that will clearly identify third-party bots in meeting lobbies. This enhancement, slated for release in May 2026, aims to give meeting organizers greater control over who joins their sessions and mitigate the risk of malicious bot activity.
Enhanced Bot Identification in Meeting Lobbies
Currently, bots attempting to join Teams meetings appear in the lobby alongside human participants, potentially leading to accidental acceptance. The upcoming update will distinctly label external third-party bots in the lobby, making them easily identifiable. Organizers will then be required to explicitly approve each bot’s entry into the meeting, preventing unintentional access.
“During Teams meetings, if there is an external 3P bot trying to join the meeting, organizers will be able to see a clear representation of the bots while they wait in the lobby. Organizers will be required to explicitly and separately admit these bots into the meeting, if really required,” Microsoft stated in a Microsoft Learn announcement. “This approach will ensure that no one inadvertently accepts the external bots into the meeting ensuring that the organizers have full control over the presence of these bots.”
Addressing Security Concerns
This change directly addresses concerns about malicious applications controlled by threat actors, as well as legitimate third-party bots used for tasks like note-taking or transcription. By requiring explicit approval, Microsoft aims to prevent unauthorized bots from joining meetings without attendees’ knowledge.
Broader Security Initiatives within Microsoft Teams
The bot labeling feature is part of a broader push by Microsoft to enhance security within Teams. In mid-March 2026, Teams will introduce a call reporting feature, allowing users to flag suspicious calls as potential scams or phishing attempts. New fraud-protection features will warn users about external callers impersonating trusted organizations, a common tactic in social-engineering attacks.
Since December 2025, administrators have been able to block external Teams users through the Defender portal, providing a defense against cybercrime gangs, including ransomware groups, attempting to exploit the platform for social engineering attacks.
The Rise of Teams Bots and Their Applications
Teams bots are software applications designed to interact with users through text-based conversations. They range in complexity from simple scripts automating basic tasks to sophisticated AI systems capable of learning and adapting. Microsoft highlights that bots can improve automation, availability, efficiency, and customer engagement.
Different types of bots serve various purposes within Teams, including:
- Conversational bots: Engage users in chat interactions.
- Notification bots: Send timely updates and alerts.
- Meeting bots: Assist with scheduling and managing meetings.
- Task automation bots: Automate repetitive tasks and workflows.
- Integration bots: Connect Teams with external services and tools.
As noted by MrSharePoint, these bots can significantly improve organizational efficiency and user engagement by freeing up human resources for more complex activities.
Looking Ahead
Microsoft’s continued investment in Teams security features demonstrates a commitment to providing a safe and productive collaboration environment. The upcoming bot labeling feature, alongside other recent security enhancements, will empower users and administrators to better protect against evolving cyber threats.
Worth a look