Microsoft's pursuit of incrementally improving Teams has hit a snag, as researchers warn that a newly launched feature has created a worrying security risk.
The recently introduced guest chat feature has been found to potentially allow malicious actors to bypass standard security protections and deliver malware or phishing attacks directly to unsuspecting users.
The discovery, made by security firm Ontinue, is what experts are calling a “fundamental architectural gap” in the platform's design.
Microsoft has declined to respond to media inquiries about the vulnerability since its discovery; however, the potential ways the issue can manifest have been outlined by the researchers.
The Feature Behind the Flaw
This vulnerability stems from a major new feature that Microsoft launched in November 2025 to make Teams far more useful for communicating with people who don’t use the platform or even have Microsoft accounts.
The update extends Teams’ use from an internal collaboration tool into something closer to a universal messaging platform that can reach anyone with an email address.
Previously, bringing external participants into Teams conversations required navigating a cumbersome administrative process. Guest access needed to be configured at the tenant level, IT departments had to approve external users, and security groups required careful adjustment to maintain proper controls.
Microsoft’s solution was to strip away virtually all of these barriers. The new feature allows any Teams user to send an invitation link directly to anyone’s email inbox. Once the recipient clicks that link, they can immediately start chatting within the Teams interface—no app installation required, no admin approval needed, and no Microsoft account necessary.
By removing the Microsoft account requirement, the platform could compete more directly with other messaging applications while still serving as the backbone for enterprise collaboration.
However, the ease of access that makes the feature attractive to users also created the security vulnerability researchers have now identified.
How Attackers Exploit the Architectural Gap
The attack method exploits a fundamental design decision about how security controls apply when users communicate across different Teams environments.
When someone accepts a guest chat invitation and joins a conversation, they do not operate under their own organization’s security protections.
"When users operate as guests in another tenant, their protections are determined entirely by that hosting environment, not by their home organization,"
Ontinue security researcher Rhys Downing said in a report.
This is where the danger lies, as in practice, a malicious actor can set up a Teams account with deliberately minimal security controls. They can configure their environment to lack the protective measures most organizations implement as standard—no malware scanning on file uploads, no link protection, no data loss prevention policies, and no threat detection systems.
With this intentionally vulnerable environment in place, the attacker can then send guest chat invitations that appear to come from Microsoft’s legitimate email infrastructure. When a victim accepts the invitation, they enter the attacker’s Teams environment and immediately become subject only to the security controls the attacker has chosen to implement.
The victim can now receive malicious files or phishing links without triggering alerts. Since the communication happens outside the victim’s own Teams tenant, their organization’s security infrastructure—email filters, endpoint protection, secure gateways, and monitoring tools—cannot inspect what is being shared in the conversation.




