PDA

View Full Version : MS Teams - Security of being on multiple teams



ExtraSlow
09-08-2022, 10:08 AM
Some questions regarding MS teams and security of files and information when accessing multiple accounts from one desktop app.
Example 1: Using desktop app installed from Company A account, then also accessing Company B account in same App, can any users in company B see company A files, email, or data? And vice-versa?
Example 2) Using desktop App installed from Company A account, then being added as a "guest" onto a channel for Company C. Can any other user or administrator in Company A see into Company C channel?

Working on a few projects where information security may be an issue, and don't want to be opening up pathways between groups who should not have access to each other. Have had to sign a few NDA's regarding keeping data separate, even from other departments within my employers organization.

I realize Teams probably isn't the #1 most secure option for sharing information, but the choice of platform is not up to me. Thoughts?

killramos
09-08-2022, 10:15 AM
A second laptop is cheap insurance.

Church and state.

mr2mike
09-08-2022, 10:23 AM
Isn't there a FB video chat platform?

bjstare
09-08-2022, 10:23 AM
Some questions regarding MS teams and security of files and information when accessing multiple accounts from one desktop app.
Example 1: Using desktop app installed from Company A account, then also accessing Company B account in same App, can any users in company B see company A files, email, or data? And vice-versa?
Example 2) Using desktop App installed from Company A account, then being added as a "guest" onto a channel for Company C. Can any other user or administrator in Company A see into Company C channel?

Working on a few projects where information security may be an issue, and don't want to be opening up pathways between groups who should not have access to each other. Have had to sign a few NDA's regarding keeping data separate, even from other departments within my employers organization.

I realize Teams probably isn't the #1 most secure option for sharing information, but the choice of platform is not up to me. Thoughts?

Those are both safe options. I've used Teams in both of those ways, with highly sensitive information, with large scale clients and engagements ($50-100MM deals). Teams can set permissions based on specific accounts/email IDs, Teams channels, both.

Typically, I will set whatever email I'm most active with (e.g., my own company email) as the default on the desktop app, and log in with my secondary email (e.g., the email my client provides me with from their enterprise) on the webapp.

ExtraSlow
09-08-2022, 10:43 AM
A second laptop is cheap insurance.

Church and state.

I may be going this way for a different reason. Maybe this is one more nudge in that direction. Realized that the hard drive may store temporary files which are them subject to inspection by the IT department owning that machine. Don't like that.

- - - Updated - - -


Those are both safe options. I've used Teams in both of those ways, with highly sensitive information, with large scale clients and engagements ($50-100MM deals). Teams can set permissions based on specific accounts/email IDs, Teams channels, both.

Typically, I will set whatever email I'm most active with (e.g., my own company email) as the default on the desktop app, and log in with my secondary email (e.g., the email my client provides me with from their enterprise) on the webapp.

Yeah, knowing the little that I do, about your work, I can see that you would have some experience with this.

Xtrema
09-08-2022, 02:11 PM
I may be going this way for a different reason. Maybe this is one more nudge in that direction. Realized that the hard drive may store temporary files which are them subject to inspection by the IT department owning that machine. Don't like that.


Or if machine is beefy enough run Company B acct in a Virtual Machine.

If Company B want to inspect it, just send them the .VHDX or pull the .VHDX off your laptop before sending hardware in for Company A inspection.


Example 2) Using desktop App installed from Company A account, then being added as a "guest" onto a channel for Company C. Can any other user or administrator in Company A see into Company C channel?


Only if Company A got your creds by resetting your password.