Microsoft 365 Teams Global meeting policy has cloud meeting recording disabled by default (AllowCloudRecording=false).
Risk
Recording allowed by default enables uncontrolled capture of meetings, threatening confidentiality. Files and transcripts persist in collaboration stores and can be broadly shared, leading to insider exfiltration, accidental leakage, and long-lived exposure of sensitive discussions.
prowler m365 --checks teams_meeting_recording_disabled
Recommendation
Adopt a stance of no default recording and grant recording only to specific roles or groups per least privilege. Require explicit consent, restrict sharing to need-to-know, and apply retention and access controls. Periodically review policies as part of defense in depth to minimize data exposure.
Remediation
Set-CsTeamsMeetingPolicy -Identity Global -AllowCloudRecording $false
- Sign in to Microsoft Teams admin center: https://admin.teams.microsoft.com
- Go to Meetings > Meeting policies
- Select Global (Org-wide default)
- Under Recording & transcription, set Cloud recording to Off
- Click Save
Source Code
Resource Type
NotDefined