The question that matters isn't whether you let the note-taking bot in. It's where what it heard ends up, how long it lives there, and who can delete it. None of that gets decided in the meeting lobby.
On 21 August Microsoft published message centre notice MC1459141: Teams admins will be able to automatically block identified external bots, instead of sending them to the lobby for the organiser to decide on the spot. General availability runs from late August to late September 2026.
It's good news and it was needed. It is also, read carefully, a switch that doesn't turn off the problem most people will go looking for it to solve. We deploy and govern Microsoft 365 for companies — MFA, conditional access, Secure Score — and this week we have to decide what to do with this policy across the tenants we run.
What exactly changes
The switch has a name: ExternalBotAccessMode, a parameter of Set-CsTeamsMeetingPolicy. Its official description says it "controls how external third-party meeting bots and meeting assistants are handled when they attempt to join meetings". And Microsoft's reference page, as of today, documents two possible values:
- 1
AllowAllBots: no detection. "Bots will appear the same as other participants" and, in the documentation's own words, "they may get mistakenly admitted to meetings". - 2
RequireApprovalWhenDetected: when detected, the bot is forced into the lobby "regardless of the lobby setting of the meeting" and needs approval. This is the default value.
The third value — the blocking one — shows up in the coverage of the announcement as BlockDetectedBots. As of 25 August 2026 it isn't on the cmdlet reference page, which was last updated on 24 August. That isn't anyone's fault: it's the normal rhythm of a ring-based rollout. But it's worth knowing before you open the admin centre expecting to find it today.
And there's a governance detail the headlines lose: the new mode doesn't switch itself on. It's a meeting policy assigned to users or groups. The day it reaches your tenant, nothing changes; it changes when somebody decides who gets it. Which is to say: this isn't news that protects you, it's work that just landed on you.
The word doing all the work is "detected"
This didn't start last week. In notice MC1251206, published on 13 March 2026 and rolled out between June and August, Teams already detects and labels external bots as they try to join, forces them into the lobby and makes the organiser admit them with a separate, deliberate click. That shipped enabled by default for every tenant, and Microsoft's advice to admins was, literally, to keep that setting.
With that in hand, the 21 August step is smaller than it looks: June drew the security boundary, and this is ergonomics. It takes the awkward live decision away from the organiser — saying no in front of everyone while the client waits. That's not nothing; that awkwardness is exactly why bots nobody wanted get admitted. But it's a process improvement, not a new door.
And blocking is only ever as good as the detection behind it. Teams identifies bots from infrastructure and behaviour signals read at the moment of joining. That leaves two possible errors, and both matter: an assistant that behaves like a person and walks in unflagged, and a real attendee flagged as a bot. Automatic blocking turns the second error into a support call at nine fifteen.
What this policy doesn't touch
Three things it leaves out:
- ×Microsoft 365 Copilot and Entra ID-registered applications are out of scope. The policy is about external third-party bots. What already lives inside your tenant is not its business.
- ×Someone else's meeting isn't yours. When your salesperson joins a meeting called by the client, the policy in force is the client's tenant policy. Their AI assistant records and transcribes what you said, and that copy stays on their side.
- ×The bot someone on your own side authorised once. A meeting assistant is usually an application with a consent grant. We already wrote about the token that never asks for MFA again: what comes in with permission doesn't get stopped by a lobby.
The problem isn't the door, it's the copy
What comes out of a meeting is no longer the meeting. It's a transcript, a summary and sometimes audio: an object with a location, an owner and a lifecycle. If a third party's assistant generates it, that location isn't your tenant and you don't write that lifecycle.
None of this is theoretical, and you don't need a bot to get into the mess. We already told the story of the recording sitting in the OneDrive of someone who left: the meeting belonged to the company, the file belonged to a person, and that difference only surfaces on the day it matters. And for what does live inside Microsoft 365, the other half of the conversation is what "having a backup" actually means, which is not the same thing as retention.
The useful questions, then, are about the object: where the transcript is stored, how long it lives, who can export it, whether it falls under the company's retention policy, and whether it would show up in the answer to a subject access request. We aren't lawyers and the legal assessment isn't ours to make; what is ours to say is that the record of processing activities belongs to the company, not to the tool somebody installed on a Tuesday.
When we would not switch it on (yet)
Switch it on tenant-wide on Monday and by Tuesday there's a meeting where the client's assistant is left outside and nobody understands why. Blocking isn't the lobby: there's no queue to wait in and nobody to ask. That's two emails and an awkward conversation with a client who had perfectly good reasons to record.
There are legitimate uses on the same side of the net: accessibility transcription, minutes for a governing body, the recording of a training session you paid for. Our approach, once the policy lands, will be this:
- ✓Look first, decide after. With June's detection already live, a few weeks are enough to see which bots actually show up and whose they are. Blocking without that data is switching off a light to see better.
- ✓By perimeter, not by tenant. Management, legal, HR and anything touching personnel data: block. Everything else: the usual lobby. The policy is assigned per group, so this is no more work than the blunt version.
- ✓Whoever calls the meetings needs to know. Anyone who organises meetings with outsiders should know the date from which their guest's assistant gets left outside, so they can say so themselves beforehand.
And a concession that doesn't do us any favours: in a lot of small companies, June's default is already fine. Detected, sent to the lobby, organiser decides. If nobody has ever run into a bot they weren't expecting, this policy is a task for next quarter, not for Friday.
In short
Blocking a bot is a door decision. Governing a transcript is a data decision. Microsoft has just improved the door, which was in worse shape than it should have been, and they were right to. The other one is still where it was: deciding what gets recorded in your company, where it's kept, how long it lasts and who can walk off with it. There's no checkbox for that.
Sources: the description of the ExternalBotAccessMode parameter, its two documented values and the RequireApprovalWhenDetected default — Set-CsTeamsMeetingPolicy reference on Microsoft Learn (page updated 24 Aug 2026); the publication date (21 Aug 2026), wording, rollout dates and default state of notice MC1459141 — public archive of the Microsoft 365 message centre, with the coverage of M365 Admin and BleepingComputer; notice MC1251206 (13 Mar 2026), bot labelling, the June-to-August 2026 rollout and the advice to keep the default — public archive of the Microsoft 365 message centre; the name of the third value BlockDetectedBots, the detection signals and the exclusion of Copilot and Entra ID-registered applications — UC Today.
Do you know which bots join your company's meetings?
At everyWAN we deploy and govern Microsoft 365: MFA, conditional access, Secure Score and the policies that decide who gets in and what stays. We review your Teams policies with you — and we also tell you when what you have is already fine. Take a look at our modern workplace and Microsoft 365 services.
Talk to everyWAN