Microsoft Teams Guest Access Exposes a Cross-Tenant Security Gap, Allowing Attackers To Slip Past Defender Protections

Microsoft Teams Guest Access Exposes a Cross-Tenant Security Gap, Allowing Attackers To Slip Past Defender Protections

By LinkedInEditors
Publication Date: 2025-11-29 18:28:00

A newly documented security gap in Microsoft Teams’ guest access architecture is raising alarms across the enterprise collaboration ecosystem, exposing how cross-tenant communication can be manipulated to bypass Microsoft Defender for Office 365 protections and leave employees vulnerable when interacting with external organizations.

Security analysts at Ontinue, a managed detection and response provider, say the issue stems from an overlooked architectural quirk: when a Microsoft Teams user joins another organization’s tenant as a guest, they temporarily fall under the host tenant’s security policies—not their own company’s. For attackers, this opens a strategic foothold for phishing, malware delivery, and social engineering campaigns that circumvent even well-configured corporate defenses.

“Collaboration…