M365Clarity Blog · 7 July 2026 · Teams Phone Voice Microsoft Teams MSP

Microsoft Teams Phone Configuration: What M365Clarity Checks

Teams Phone is one of the fastest-growing parts of the Microsoft 365 stack. Organisations are retiring legacy PBX systems, porting phone numbers to Microsoft, and consolidating voice into Teams. But a Teams Phone deployment has a lot of moving parts — voice policies, emergency calling, PSTN connectivity, meeting recording governance, and external access — and most IT teams have no structured way to verify they got all of them right.

M365Clarity's Teams Phone & Voice tab addresses that. It reads your Teams configuration from the Microsoft Graph API, surfaces the specific gaps that matter, and generates an AI risk assessment from your live tenant data. Here's exactly what it checks.

What M365Clarity scans

📞 Teams Phone — Voice Policies
Checks whether Teams Phone System is licensed and voice calling policies are configured. A tenant with Phone System licences but no calling policies assigned has users who can't make or receive external calls. M365Clarity flags missing or default-only voice policy assignments.
📅 Teams Meeting Policies
Assesses the global meeting policy for settings that affect governance and security. Key checks include whether users can self-request apps (increases app sprawl risk), whether lobby bypass is configured correctly for external callers, and whether who-can-present is restricted.
👥 Guest Access
Checks whether guest access is enabled and what external users can do once invited. The most common misconfiguration is leaving guest access on the Microsoft default — which allows guests to see all Teams members, join all public channels, and share files without restriction. M365Clarity flags where the settings differ from a hardened baseline.
🌐 External Access (Federation)
Assesses whether external Teams federation is open, restricted, or blocked. Open federation allows anyone with a Teams account at any organisation to call and message your users directly — without any prior relationship or invitation. This is the Microsoft default. M365Clarity flags open federation as amber for review.
🎥 Meeting Recording Policy
Checks where meeting recordings are saved (OneDrive vs SharePoint), whether auto-expiry is enabled, and whether recording download is restricted. Meeting recordings stored in SharePoint without expiry accumulate indefinitely and are accessible to anyone with SharePoint access. OneDrive with auto-expiry is best practice.
⭐ Teams Premium Features
Detects whether Teams Premium is licensed, which unlocks intelligent recap, advanced webinar features, custom meeting templates, and watermarking. Surfaces whether the licence is present but not configured — a common situation where IT has assigned the licence without enabling the features.

The AI voice risk assessment

After scanning the six configuration areas above, M365Clarity generates an AI risk assessment using Claude, grounded entirely in your actual scan results. The assessment includes:

Example output: "External federation is open — any Teams user at any organisation can contact your employees directly without invitation. Combined with guest access on default settings, this creates an untested inbound channel. Recommendation: restrict external access to a specific allow-list of known partner domains, or switch to inbound-only to prevent unsolicited contact. Effort: low — this is a single setting change in the Teams admin centre."

Why the external access default is a risk most IT teams don't realise

The most consistently flagged finding in the Teams Phone tab is open external access (federation). Microsoft enables it by default because it makes Teams more useful out of the box — you can immediately call and message anyone at any Teams-enabled organisation without exchanging invites. That's genuinely useful for sales teams.

The governance implication is less visible. Open federation means a social engineering or phishing attempt can arrive directly in an employee's Teams chat from an unknown external account, bypassing email security filters entirely. Unlike email, there's no spam filtering, no quarantine, and no header analysis on inbound Teams messages from federated tenants.

This doesn't mean disable external access. Federation is a legitimate and useful feature. The recommendation is to review it deliberately — restrict to known partner domains where you have an actual business relationship, rather than leaving it open to the entire Teams ecosystem.

Who this is for

The Teams Phone tab is most useful for three groups:

Teams Phone not licensed? The tab detects this and shows a clear "Teams Phone System not detected on this plan" state rather than a false assessment. The meeting, guest, and external access checks still run — those are relevant to every Teams tenant regardless of whether Phone System is licensed.

How to access it

Teams Phone & Voice is available under Collaboration → Teams Phone in the M365Clarity sidebar. It's available on the Pro plan. The AI risk assessment generates on first open and is cached per scan — it regenerates automatically after a rescan or when you click Regenerate.

The six feature rows at the top of the tab reflect live scan data directly — they update immediately after every rescan without requiring AI generation.

Check your Teams Phone configuration

Scan your tenant and get a complete voice and communication governance assessment in under 60 seconds.

Run a free scan →