Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsIn June 2023, security firm JUMPSEC reported that it could bypass a Microsoft Teams restriction on file transfers from external tenants and deliver a malware payload in a client engagement. The finding raised a real security concern, but available sources do not establish whether that exact bypass still works in current Teams clients. Organizations should treat external Teams contact as a potential phishing route and reduce exposure with domain controls, identity protections, and user verification.
What was the Microsoft Teams external-access flaw?
JUMPSEC researchers Max Corbridge and Tom Ellson reported that external contacts were normally prevented from sending files in Teams. They said they bypassed the client-side restriction by changing recipient identifiers in a Teams message request. The file, hosted on a SharePoint domain, then appeared in the recipient’s inbox as a file. JUMPSEC said it used the method to deliver a red-team command-and-control payload during a client engagement. JUMPSEC’s advisory, published June 21, 2023, describes the reported behavior.
JUMPSEC said Microsoft validated the issue but judged that it “did not meet the bar for immediate servicing” at the time. The advisory does not establish a later fix status or provide a current reproducibility test. It is therefore accurate to describe this as a reported 2023 bypass, not as a confirmed, currently exploitable vulnerability.
Does this mean external Teams users can still send malware?
The original bypass’s current status is unresolved in the available sources. That uncertainty is different from the broader, ongoing security concern: external conversations can be used to impersonate people, deliver phishing links, or persuade employees to open malicious content.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Compatible with Nintendo Switch 2’s new GameChat mode
- Auto-Light Balance: RightLight boosts brightness by up to 50%, reducing shadows so you look your best—compared to previous-generation Logitech webcams (1)
- Privacy with a Slide: The integrated webcam cover makes it easy to get total, reliable privacy when you're not on a video call
- Built-In Mic: The built-in microphone lets others hear you clearly during video calls
- Easy Plug-And-Play: The Brio 101 works with most video calling platforms, including Microsoft Teams, Zoom and Google Meet—no hassle; it just works
Microsoft separately reported that the threat actor Storm-0324 began using Teams phishing lures in July 2023. Its report described malicious links leading to SharePoint-hosted files and said the group likely relied on the publicly available TeamsPhisher tool. Microsoft presented this as campaign activity; it did not say the campaign exploited JUMPSEC’s specific recipient-identifier bypass. Microsoft Threat Intelligence’s September 12, 2023 report covers that separate activity.
How should administrators configure external access?
Microsoft says Teams external-access settings and user policies are on by default. Administrators can allow all external domains, allow only selected domains, block selected domains, or block all external domains. Cross-organization access through federation requires both organizations to permit it. Microsoft’s external-access guidance explains the available controls.
Rank #2
- With a 78° fixed field of view, the C920e webcam displays individual users in a well-balanced frame, while also providing sufficient room to visually share projects and other items of interest.
- The C920e webcam features two integrated omnidirectional microphones that capture your audio clearly from up to one meter away, so your voice always sounds natural and clear.
- Built-in HD autofocus ensures you’re seen clearly throughout your video calls. With automatic light correction, C920e delivers optics that help you look good in all your video meetings.
- The C920e webcam features an attachable privacy screen that flips up and down to cover or expose the lens. A simple glance at the cover confirms if the lens is able to see into your space or not.
- The C920e webcam is certified for Zoom, TAA compliant and works with all popular video calling applications such as Microsoft Teams to ensure compatibility and seamless integration in the workplace.
| Organization setting | When it fits | Trade-off |
|---|---|---|
| Allow all external domains | Teams collaboration is needed with a wide and changing range of organizations. | Offers the broadest collaboration reach and the least domain-level restriction. |
| Allow selected domains | External collaboration is needed with a known set of partners. | Reduces exposure to unapproved domains, but requires maintaining the allow-list. |
| Block selected domains | A targeted restriction is needed while most external collaboration remains available. | Blocks specified domains without limiting every other external domain. |
| Block all external domains | External access is unnecessary or must be disabled as a response measure. | Provides the tightest domain-level restriction but prevents federation with external organizations. |
Start by identifying which outside organizations employees genuinely need to contact. Where practical, allow only those domains, then apply the relevant Teams user policies to limit access for the people or groups who need it. Organization-wide domain settings define the outer boundary; user policies can further scope who may use external access.
Which security layers help reduce the risk?
Protect identities and sign-ins
Microsoft recommends phishing-resistant authentication, strong Conditional Access policies, auditing, and known-device controls in response to the Storm-0324 activity. These measures make account compromise harder; they are defense in depth, not a patch for the 2023 file-transfer behavior. Microsoft’s threat report also recommends user education and relevant Defender protections.
Rank #3
- Good stability/attachment to monitor, laptop, and desktop scenarios
- Auto white balance and exposure compensation with HDR
- Integrated privacy shutter with usage indicator light
- Updatable firmware
- Fixed focus to cover 0.4m to 1.5m
Protect links and shared content
Microsoft’s Teams attack-surface guidance recommends enabling Defender for Office 365 protection for SharePoint, OneDrive, and Teams, and configuring Safe Links to check known malicious links when users click them in Teams. Product availability depends on licensing and environment; Microsoft notes that some options are unavailable in government clouds. These protections can reduce risk, but should not be treated as a guarantee that every malicious file or social-engineering attempt will be blocked.
Limit meeting control where appropriate
The same Microsoft guidance recommends restricting external meeting participants’ ability to request or give control and limiting who can present. These settings address meeting-based exposure rather than the reported file-transfer bypass, so configure them according to how your organization uses external meetings.
Rank #4
- Compatible with Nintendo Switch 2’s new GameChat mode
- HD lighting adjustment and autofocus: The Logitech webcam automatically fine-tunes the lighting, producing bright, razor-sharp images even in low-light settings. This makes it a great webcam for streaming and an ideal web camera for laptop use
- Advanced capture software: Easily create and share video content with this Logitech camera that is suitable for use as a desktop computer camera or a monitor webcam
- Stereo audio with dual mics: Capture natural sound during calls and recorded videos with this 1080p webcam, great as a video conference camera or a computer webcam
- Full HD 1080p video calling and recording at 30 fps. You'll make a strong impression with this PC webcam that features crisp, clearly detailed, and vibrantly colored video
What should Teams users do when an external message arrives?
Microsoft Support advises users to verify who is contacting them, preview suspicious external chat messages, and accept conversations only from trusted senders. Teams flags suspicious links and blocks some high-risk file types, including executables; Defender for Office 365 can apply security policy protections to Teams chats. These are useful safeguards, not proof that every dangerous file or deceptive message will be stopped. See Microsoft’s guidance on keeping Teams chats, links, and files secure and preventing spam or phishing attempts from external chats.
Quick Recap
Best Value
- Compatible with Nintendo Switch 2’s new GameChat mode
- Be Your Best Self on Every Video Call: Full HD 1080p webcam resolution provides natural image quality, so you look like the real you on all meeting apps
- Auto Light Correction: RightLight 2 technology automatically compensates for poor video lighting conditions so you can be seen clearly
- Sound Like You: The mono noise reduction mic suppresses background sound so everyone on the call can hear you easily
- Spin for Instant Privacy: Spin the webcam privacy shutter to block the camera lens when you don’t need to be on screen
- Check the sender’s identity and organization, especially when a message is unexpected or urgent.
- Preview the message and inspect links before opening them; be cautious with files or links that do not fit the conversation.
- Accept external conversations only when you recognize and trust the sender.
- Report suspicious messages through your organization’s security process rather than relying solely on Teams warnings.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

