Microsoft Teams grows organically. A project starts, someone creates a team. A department needs a channel. Six months later you have 200 teams, half of them inactive, nobody knows what's in them, and sensitive information is scattered across channels that the wrong people can access.
Teams governance isn't about locking everything down — it's about having enough structure that Teams remains useful and doesn't become a security and compliance liability.
By default, any user can create a new team. Consider restricting team creation to a specific security group — typically IT, department heads, or project managers. This doesn't prevent collaboration; it just means someone with context approves new teams.
Where: Teams Admin Centre → Teams policies → Who can create teams
Guest access lets external users join teams and access files. Decide whether this is appropriate for your organisation, and if so, which teams can have guests. At minimum, ensure guests can't access company-wide teams or channels containing sensitive information.
External access lets Teams users in other organisations chat and call each other without being added as guests. This is less risky than guest access (no file access) but should still be reviewed — you may want to whitelist specific trusted organisations rather than allowing all domains.
Control which third-party apps users can install in Teams. Every Teams app is requesting access to data — channel messages, user information, sometimes files. Restrict app installation to IT-approved apps, or at minimum block apps from unknown publishers.
Set inactive teams to expire automatically after a period (typically 90 or 180 days). Team owners receive renewal reminders. If they don't respond, the team (and its associated Group, SharePoint site, and mailbox) is deleted. This keeps the environment clean without manual auditing.
Enforce a naming convention for teams — prefix by department, project code, or year. Makes teams findable and signals their purpose. Configure in Azure AD → Groups → Naming policy.
Require every team to have at least two owners. Single-owner teams become ungovernable when that person leaves. Azure AD can alert you to teams with missing or single owners.
For regulated industries (financial services, legal), information barriers prevent communication and collaboration between groups that shouldn't be interacting — for example, an investment bank preventing communication between research analysts and traders. Requires E5 compliance licences.
M365Clarity scans Teams governance settings including guest access, external federation, app permission policies, and meeting recording settings, and flags anything that needs attention as part of its standard tenant scan.
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →Related articles