Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

The enemy within: how to stop a simple Teams message taking down your business | TechRadar

How organizations can prevent Microsoft attacks Discover insights about the enemy within: how to stop a simple teams message taking down your business | techrad

TechnologyInnovationBest PracticesGuideTutorial
The enemy within: how to stop a simple Teams message taking down your business | TechRadar
Listen to Article
0:00
0:00
0:00

The enemy within: how to stop a simple Teams message taking down your business | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

The enemy within: how to stop a simple Teams message taking down your business

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Microsoft recently warned that attackers are impersonating IT help desks on Teams to gain access – and if that sounds bad, well, it’s just the opening move.

The attack begins when an employee gets a message from an external user claiming to be part of the company’s third-party IT support. A common-enough setup, and the kind of thing you might expect in a normal working day.

Perhaps the employee is expecting a similar message for an outstanding ticket – and so they engage with the user and, when prompted, grant remote access.

Once attackers have that foothold, they can progress to execute a full tenant lockdown using only Microsoft's own legitimate features, without ever deploying traditional ransomware. It won’t look like malware, and that means traditional defense systems won't catch it.

A real-time chat in a sanctioned collaboration tool, with a plausible IT support pretext is hard for busy employees to spot. For hackers, it’s a simple way to gain access to privileged and confidential data.

Microsoft warns of Teams external IT impersonation attacks

Why your help desk is still your biggest security risk

Most ransomware attacks are opportunistic. Here’s how you can stop attackers

All they need is a few user-approved clicks and they have gained access to Quick Assist, registry persistence, lateral movement across the victim's environment and eventual data exfiltration over HTTPS. All without triggering suspicion.

Data theft is just the opening move. Once attackers have privileged access through this kind of social engineering, the same foothold opens the door to full tenant ransom scenarios. Attackers can encrypt One Drive and Share Point content at scale, locking legitimate administrators out of the tenant by hijacking Global Admin accounts and conditional access policies.

They can hijack native M365 features like sensitivity labels to render data inaccessible.

IT decision makers may believe they're covered against this kind of theft or lockout because they have ransomware protection in place, but the reality is that many are more exposed than they know.

This attack class is effectively invisible to standard endpoint protection software, because the encryption that locks companies out of their critical data is performed by Microsoft's own features, not malicious code.

The four shifts reshaping Microsoft 365 security and resilience

Closing the security blind spots that are a prime entry point for attacks

5 frightening AI-powered threats that could hit your business hard

During that period of time, critical business activities are likely to be disrupted or even halted completely, leading to potentially major financial and reputational losses.

Overall, the Microsoft Teams help desk impersonation attack works because it weaponizes the trust organizations put in systems like Microsoft 365. That level of often-blind trust puts organizations at risk, because native M365 controls were built for administration, not for resilience against real-time social engineering.

Clearly, the risk posed by this kind of social engineering attack is significant. It highlights the fact that Microsoft 365 has become critical infrastructure that demands a dedicated operational control plane, not just admin tooling. Businesses cannot simply plug, play, and walk away, hoping the system will protect itself. They need to have a deep level of insight into what’s going on across their tenant, who has access, and whether anything unusual or suspicious is taking place.

As a result, visibility into privileged role assignments, configuration drift, and admin activity in real time is no longer optional. It's the difference between a contained incident and a business-stopping event.

Organizations need an operating layer that provides that continuous visibility across thousands of configuration attributes and follows a least-privilege administration protocol. Spotting configuration drift, privilege changes, and anomalous activity is only possible when you know what 'normal' looks like, and that requires years of telemetry across complex, real-world tenants.

This approach can help build in tenant resilience within the Microsoft 365 environment, reducing the damage that a single human slip can cause, and ringfencing malicious access quickly after a breach.

Another key consideration is the introduction of next-gen technology to improve defensive intelligence, speed, and granularity. An AI-enabled operating layer can surface anomalous configuration drift and privilege changes the moment they happen, not days later in a log review.

By drawing on proprietary tenant context - permissions, role assignments, configuration history, and behavioral baselines built from millions of real-world events - AI can surface malicious activity that generic tooling would miss entirely.

In cases like these, a rapid response is crucial. The quicker controllers are alerted to the danger, and the quicker entry is revoked for the suspicious user, the lower the chance of either a data breach or a lockout.

At root, the Teams attack exploits the oldest cybersecurity risk in the book: human error. No organization's staff are error-proof, which means additional defensive help is required to preserve the integrity of critical M365 tenants.

In reality, the addition of a powerful, intelligent control layer is the only way businesses can prevent a single approved remote session from escalating into domain-wide compromise.

We feature the best Active Directory documentation tools.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

You must confirm your public display name before commenting

1 Harlan Coben's I Will Find You ending explained: everything that happens in the Netflix crime drama

2 Harlan Coben's I Will Find You review: easily the weakest in Netflix's hit whodunnit franchise to date

3 Rivian decides to ditch AM/FM radio tuners in the R2

4 Two-thirds of office workers admit to secretly using banned AI tools

5A basic security flaw let a security researcher access internal FIFA systems

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.