Threats · 148 days ago
External Teams collaboration can become an entry point for full enterprise compromise. The standard response misses that this is not just social engineering. Once a user grants remote support, attackers can operate through legitimate admin tools and look like routine IT activity while they move laterally and stage data for exfiltration.
Microsoft says intruders are impersonating helpdesk staff in cross-tenant Teams chats, then using Quick Assist or similar remote support tools to get in. From there they have used trusted vendor-signed applications, Windows Remote Management, and other normal admin protocols to reach higher-value systems, including domain controllers, and to move data out through external cloud storage.
The risk persists because the abuse sits inside approved collaboration and support workflows. Tool-based detection alone will miss parts of this chain unless endpoint, identity, and collaboration telemetry are correlated.
2 sources covering this story
Microsoft: Teams increasingly abused in helpdesk impersonation attacks
Microsoft is warning of threat actors increasingly abusing external Microsoft Teams collaboration and relying on legitimate tools for access and lateral movement on enterprise networks.
Threat actors are abusing external Microsoft Teams collaboration to impersonate IT helpdesk staff and convince users to grant remote access.
Part of the PlainSec briefing for 2026-04-18