Teams Helpdesk Impersonation Turns Support Into Access

External Teams collaboration can become an entry point for full enterprise compromise. The standard response misses that this is not just social engineering. Once a user grants remote support, attackers can operate through legitimate admin tools and look like routine IT activity while they move laterally and stage data for exfiltration. Microsoft says intruders are impersonating helpdesk staff in cross-tenant Teams chats, then using Quick Assist or similar remote support tools to get in. From there they have used trusted vendor-signed applications, Windows Remote Management, and other normal admin protocols to reach higher-value systems, including domain controllers, and to move data out through external cloud storage. The risk persists because the abuse sits inside approved collaboration and support workflows. Tool-based detection alone will miss parts of this chain unless endpoint, identity, and collaboration telemetry are correlated.

Part of the PlainSec briefing for 2026-04-18

Sources