On October 31, 2025, Microsoft announced a new feature in Microsoft Teams that allows users to start a chat with anyone that has an email address. This feature is enabled by default, and no opt-in is required.
In November 2025, security researchers from Ontinue discovered that “A critical security gap in Microsoft’s B2B guest collaboration allows attackers to bypass all Defender for Office 365 protections by inviting users into malicious tenants.” Their report can be found here.
This document covers some the capabilities of HEC in regards to Microsoft Teams, and the preventative measures organizations must take to close gaps in security coverage, most notably including:
- User training
- URL filtering
- DLP
- Protection against downloading of malicious files