How to train staff to spot phishing in Microsoft Teams chats

How to train staff to spot phishing in Microsoft Teams chats: external chat risks, the verify-the-person reflex, and the admin settings that shrink the attack surface.

Most phishing training lives in the inbox, so most staff have learned to glance at an email sender with mild suspicion. Then the attack moves to Microsoft Teams - where the message sits next to real colleagues, the sender has a display name like "IT Helpdesk" or "Accounts", and the whole interface whispers "internal, therefore safe". Training staff to spot phishing in Teams chats closes the channel where email training has no coverage.

TL;DR

Why this matters

Teams has quietly become an attack surface for the same reason it became a collaboration tool: it is where people are reachable and responsive. An email can sit unread for hours; a Teams chat pops up on screen and feels like a colleague tapping your shoulder. Attackers use this in two ways. First, external chats: by default, Microsoft Teams permits users to chat with people outside the organisation using Microsoft identities - other Microsoft 365 organisations, and even Teams users not managed by any organisation. A stranger with a consumer Teams account can message your staff directly if your tenant and their account both allow it. Second, pretexting inside the channel: an attacker who knows names and roles - from LinkedIn, from a breached mailbox, or from a supplier relationship - sends a chat that reads like it came from IT, HR or the CFO.

The financial mechanics are the same as email phishing: steal a password, harvest a payment, or deliver malware. The difference is human. Staff have been conditioned that email is dangerous and Teams is internal. Nobody conditioned them otherwise, because nobody trained them otherwise.

Who this is for

MSPs training client workforces on Microsoft 365, and internal IT or people teams at businesses that run Teams as their main chat platform. Everything below works without changing a single admin setting - though the last section covers the settings worth changing.

What Teams phishing looks like

Before you can teach the spot, staff need to see the shapes it takes:

What all of them share: the sender is either external, unverified, or asking for something the real person would never ask for through chat.

The Teams reflex: verify the person, then the link

Email training taught people to inspect the sender. Teams needs a two-step reflex because sender identity is weaker here:

  1. Treat unknown senders as external by default. If the person is not someone you have chatted with before, pause. A familiar display name is not verification - display names and profile photos are whatever the sender sets them to.
  2. Check the domain behind the name. Teams shows the organisation or account behind external contacts. If the name says "David from IT" but the account is a consumer or unknown-organisation account, that mismatch is the alarm.
  3. Verify out-of-band. For anything involving money, credentials or access, confirm with the real person through a channel you already trust - a call, a message in a channel you both use, a walk to their desk. Attackers cannot intercept the conversation they do not know about.
  4. Apply the same link discipline as email. Hover or long-press before clicking, read the full domain, and never sign in from a link in a chat you did not initiate. If IT genuinely needs you to do something, it will survive you opening the portal yourself.
  5. Report suspicious chats. Tell IT or the MSP before deleting. If it is an external user, your admin can block them tenant-wide so the next person never sees the chat.

That is the whole habit: unfamiliar sender, mismatch or urgency, verify out-of-band, report.

How to train it

  1. Add it to the curriculum. Your security awareness training should include a short Teams-specific module: the shapes above, the reflex, two worked examples. Under fifteen minutes.
  2. Run a Teams simulation. If your platform supports Teams-based simulations, run one after the module - an external chat from a fake helpdesk is the highest-value test. If your platform is email-only, at least run a mock chat drill with a script and a volunteer. Either way, keep it blame-free.
  3. Teach the escalation path. Every staff member should know, without looking it up, who they report a suspicious chat to and what happens next. A report that goes to a generic inbox and dies there trains people to stop reporting.
  4. Reinforce on cadence. Fold Teams lures into your ongoing phishing simulations calendar so the reflex gets exercised between formal refreshers.
  5. Watch the metric that matters. Click rates tell you about the test; report rates tell you about the culture. Rising reporting with falling clicks is the signature of a workforce that is actually spotting things.

The admin settings that shrink the attack surface

Training covers the humans; a few Teams admin settings cover the plumbing. Microsoft's own external access documentation is the source for each of these:

One caveat: tightening external access does not remove the internal impersonation risk once an attacker has a foothold in someone's mailbox or account. That is why the human reflex - verify out-of-band for money and credentials - stays the primary defence.

Common mistakes

What to do next

If the client's Teams posture is unknown, a gap assessment will show how much of the channel is open and what it is worth closing first. Then put the training cadence behind it and report on it: human risk reporting turns click and report data into something you can show a board - including how the Teams channel is tracking against email.

FAQ

Can strangers message my staff on Teams?

Yes, by default. Teams' external access allows chat with users at other organisations (and consumer Teams accounts, and Skype) unless you restrict it to specific domains or turn those options off.

How do staff tell if a Teams message is external?

Check the account or organisation behind the display name - Teams surfaces it for external contacts. If the name and the account disagree, treat the message as hostile until verified.

Is Teams phishing as common as email phishing?

Email remains the higher-volume channel, but Teams is attractive precisely because it is under-defended by habit: messages feel internal, arrive in real time, and rarely get the scrutiny email gets. The right comparison is not volume, it is how little your staff currently check there.

What should staff do when they get a suspicious Teams chat?

Do not click. Do not reply. Report it to IT or the MSP, and let the admin block the user or domain so colleagues are protected.

Does blocking external domains break legitimate collaboration?

Only for domains you remove. Switching to an allow-list of partner domains keeps your real external contacts working while cutting out everyone else.

Can we simulate Teams phishing attacks?

If your awareness platform supports Teams-based simulations, yes - a fake-IT-helpdesk chat is the standard test. If not, a scripted tabletop drill gets the reflex started.

One last thing

Ask your client one question: does anyone in the business actually need to chat with consumer Teams or Skype accounts? If the answer is no, that switch in the Teams admin center removes an entire class of stranger-messages before a single training slide is shown.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.