NEWS
KnowBe4 Now Filters Phishing Inside Microsoft Teams Chat
KnowBe4 Messaging Security is live in Defend, scanning Microsoft Teams chats while Microsoft still defaults to allowing every external domain.
KnowBe4’s Messaging Security for Microsoft Teams is live inside Defend, scanning tenant chats and flagging the same open external-access defaults Microsoft still ships. The company announced the product on May 28, 2026, and said it would be available in June 2026.
The filter is not a new kind of detector so much as a bill for leaving federation wide open. Staff already treat a Teams ping as safer than a cold email, and attackers have followed that trust onto the same tenant.
KnowBe4 Put Teams Filtering Inside Defend
The May 28 launch of KnowBe4 Messaging Security promised one console for email and chat, starting with Teams. By September 1, 2026, the company had published setup steps that place the work inside Defend, not a separate chat box.
Admins connect a Microsoft 365 account, accept API permissions, and turn on two switches. Message Security scans Teams chats and dumps flagged items onto a Recent Messages list with sender, recipient, time, and a classification. Security Posture watches tenant settings that fail KnowBe4’s preferred baseline.
Message Security Flags Suspicious Chats
The dashboard counts messages scanned and threats found, then opens a detail pane with the body, any links, a URL reputation score, and the reasons for the tag. Filters start on Dangerous mail and hide phishing-simulation tests, so the first view is the queue an admin would actually triage.
KnowBe4 said the same classification tags and risk levels already used for inbound email now apply to Teams, and that a shared global list can block an actor in both channels at once. Admins can run detections in report-only mode before they turn on automated blocking.
KnowBe4 Messaging Security has been launched with the goal of enhancing, not hindering, teamwork. This provides organizations with a single, unified console that seamlessly secures both email and chat environments, starting with Microsoft Teams.
Greg Kras, Chief Product Officer, KnowBe4
The company posted the same pitch on X the day of the launch.
https://x.com/KnowBe4/status/2060072890066686097
Posture Checks Four Teams Settings
The Microsoft Teams Message Security integration is the other half of the SKU. It is a scorecard of Microsoft knobs, with PowerShell snippets and links to Microsoft docs when a check fails. A green badge appears after a fix lands.
KnowBe4, which says it is trusted by more than 70,000 organizations and draws on 15 years of behavioral data, is extending Defend rather than asking security teams to learn a new product name. The marketing label is Messaging Security. The place it actually lives is the Defend settings page.
The Default That Lets Anyone Start a Chat
Microsoft’s own admin docs still allow all external domains by default. That setting lets people in the tenant find, call, chat, and meet with Teams users in any domain, as long as the other side also has external access on.
The organization setting and the user policy both start on. A person cannot use external access unless both layers allow it, which sounds like a brake until you notice both layers arrive already open. Admins can later switch to an allow list, a block list, or a full block of every external domain.
People from a blocked domain can still join meetings as anonymous users if anonymous join is allowed, so shutting the chat door does not shut the meeting door. Microsoft also lets a tenant block named people, up to 200 addresses, but that list starts off.
KnowBe4’s own Phishing Threat Trends Report Volume 7 ties the Teams spike to Chat with Anyone, a default path that lets someone start a chat with any email address, even if the other person has no Teams license. The product KnowBe4 is selling is, in large part, a warning light over that factory setting.
What CISA Already Requires for External Access
CISA’s Microsoft 365 Teams baseline already tells civilian agencies to set external access only on a per-domain basis. Policy MS.TEAMS.2.1v2, added February 11, 2026, uses SHALL, not SHOULD. The rationale is blunt: the default lets members talk to all external users, and that unrestricted path is a phishing and data-loss problem.
A sister rule, MS.TEAMS.2.2v2, says unmanaged users shall not be allowed to start contact with internal users. That is the consumer-Teams and free-account problem in policy language. KnowBe4’s posture view is checking some of the same ground.
POSTURE CHECKS KNOWBE4 RUNS ON TEAMS
- Restrict external access: Flags tenants that still let any domain federate, which is Microsoft’s shipped default.
- Deny consumer access: Looks for unmanaged Teams accounts that can reach staff, a separate toggle from guest access.
- Deny trial tenants: Warns if trial-only Microsoft 365 tenants can search and chat, a path attackers use for cheap throwaway orgs.
- Deny guest messaging: Scores guest-chat settings that sit beside federation and are easy to leave loose for partners.
Microsoft already defaults trial-only federation to Blocked, so that KnowBe4 check is for tenants that turned it back on. The other three checks are the ones most likely to fail on a fresh Teams rollout.
Helpdesk Lures Now Ride External Teams Chat
Jack Chapman, KnowBe4’s SVP of Threat Intelligence, said the inbox is no longer the only front line for coordinated social engineering. Volume 7, published April 30, 2026, reviewed campaigns from more than 3,000 unique threat actors and found an 41% rise in Microsoft Teams attacks across October 2025 to March 2026.
The same report put 17.38% of those Teams attacks in a multi-channel pattern that starts in email and then jumps into chat to deliver the payload. Average thread length in a Teams attack grew from 2 messages to 6. Internal team impersonation showed up in 30% of attacks from those actors in Q1 2026.
Calendar-invite phishing rose 49% in that window, and reverse proxies used to steal Microsoft 365 credentials rose 139%. KnowBe4 said 86% of phishing attacks it measured were AI driven. The Teams piece is the channel shift sitting next to those figures, not a side note.
The play that keeps working is boring. A flood of junk mail hits a mailbox, then a chat appears from someone claiming to be IT, offering to clean it up. The user is already in a hurry, the logo looks like work, and a warning prompt is one more click on the way to getting the day back.
Microsoft Threat Intelligence described that same helpdesk impersonation path on September 2, 2026, two months after KnowBe4’s stated ship window. The write-up says Teams already labels external tenants and shows Accept or Block prompts, and that the chain still depends on the user talking past those prompts and granting a remote-support session.
Microsoft Ships Warnings, KnowBe4 Sells the Missed Switch
Defender for Office 365 documentation describes extra Teams controls on top of the base client: near real-time warnings on known bad URLs, Safe Links at click time, and zero-hour auto purge that can quarantine high-confidence phishing in internal chats. Those tools exist. They also sit behind licenses and policy work that many tenants never finish.
KnowBe4 is pricing the remainder: a view of external chat risk, a shared block list with email, and a checklist for the federation switches Microsoft documents but does not close for you. Report-only mode is there because a chat filter that nags the wrong partner thread will get turned off by Friday.
WHERE THE TWO STACKS MEET
| Control | Microsoft default | KnowBe4 Messaging Security |
|---|---|---|
| External domains | Allow all external domains | Flags unrestricted access and offers fix steps |
| Unmanaged accounts | Admins can let them contact staff | Deny consumer access check |
| Trial-only tenants | Blocked unless an admin overrides | Deny trial tenants check |
| Cross-channel block list | Separate Teams domain blocks in Defender | One global list across email and Teams |
| Tuning before enforcement | Policy work in admin centers | Report-only mode before automated blocking |
The table is the product. KnowBe4 is not replacing Teams’ own warnings so much as wrapping the settings companies leave on Allow all external domains and the actors who already burned the email channel.
Sixty-One Percent Trust Their Teams Defenses
A KnowBe4 survey of 169 cybersecurity professionals at Infosecurity Europe 2026, released June 18, 2026, found 60% saying threats had already moved beyond email. Email was still named the biggest threat by 54%, and 83% felt confident they could stop attacks there.
That confidence dropped to 61% for Teams, 51% for social media, 50% for SMS and WhatsApp, and 40% for Slack. Half of the group lacked strong confidence in detecting threats across messaging and social platforms. The 22-point gap between email and Teams is the market KnowBe4 walked into in June.
THE CONFIDENCE DROP OFF EMAIL
- Email: 83% of those UK security staff felt able to stop attacks on the channel they still rate as riskiest.
- Teams: 61% felt the same about the chat tool sitting on the same Microsoft 365 tenant.
- Other chat: Slack sat at 40%, the weakest of the work channels they were asked about.
- Beyond email: 60% already saw attacks leaving the inbox, while 50% lacked strong confidence detecting them on messaging apps.
People still click through an external-chat warning because they think they are doing the job, talking to a vendor, or clearing a ticket. A banner that says the other person is outside the tenant does not feel like a security event when the calendar is full. That is why a filter that only shouts after the fact is late, and why the first useful control is still the domain list Microsoft ships set to everyone.
Frequently Asked Questions
Does KnowBe4 Messaging Security Require a Microsoft License?
Yes. The Defend hookup needs a qualifying Microsoft license, and KnowBe4 keeps the supported SKUs on a separate license-requirements article rather than on the Message Security setup page. Without that license, the API connection and the scanning switch do not complete.
Can Admins Scan Only Some Teams Users?
The Microsoft Teams message scanning scope menu offers Entire Tenancy, which is selected by default, or Disabled. KnowBe4’s setup article does not document a middle state that scans only selected users or groups from that screen.
How Long Do Teams Setting Fixes Take to Show?
After an admin changes Microsoft Teams settings, KnowBe4 says Security Posture results can take up to 24 hours to refresh. A green badge then marks a check that has been cleared.
Does Microsoft Block Teams Trial Tenants by Default?
Microsoft’s ExternalAccessWithTrialTenants setting defaults to Blocked, so users in trial-only tenants cannot search and contact a customer tenant unless an admin overrides it to Allowed. Two trial-only tenants can still federate with each other if both sides set the value to Allowed.
KnowBe4’s public product roadmap for July through December 2026 also lists phishing simulations that run inside Microsoft Teams, a training follow-on to the filter that shipped in June 2026. The May 28 launch note did not treat those modules as live.
-
NEWS3 months agoWarzone Leaves Xbox One and PS4 After Season 06
-
NEWS3 months agoMicrosoft AI Was Set Free to Build Its Own Frontier
-
MICROSOFT 3653 months agoMicrosoft IQ Turns Workplace Data Into a Metered Agent Brain
-
NEWS3 months agoXbox Games Showcase 2026 Split the Catalog in Two
-
MICROSOFT 3653 months agoNadella Banned Addiction Talk While Scout Kept Heartbeat
-
NEWS3 months agoModern Warfare 4 Splits Its Audience Before the October Launch
-
NEWS3 months agoInfinity Ward Bets Modern Warfare 4 on a Paid DMZ
-
NEWS3 months agoDragonwilds Hits Xbox, but Steam Saves Stay Put
