MC1423114: Microsoft Teams Adds PowerShell Controls to Enforce External Access and Mutual Federation in Group Chats

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
50
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Teams AdminsMicrosoft 365 AdminsIT ManagersService OwnersSecurity Teams
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
Microsoft extended the rollout timeline, with general availability for the first feature now mid-August and the second by end of September. Two new optional PowerShell controls in Teams introduce stricter external access and federation enforcement for federated chats. Admin impact is significant if enabled, as it requires policy reviews, configuration updates, and communication with stakeholders; user impact is conditional and indirect, affecting federated chat behaviour. Urgency remains moderate since the features are off by default, but organisations planning to adopt these controls should prepare ahead of upcoming availability.
60
🛡️ Admin Impact
35
👥 User Impact
45
Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Two new PowerShell settings give admins tighter control over who can join federated group chats, helping align participation with your external access policies.
👥

END USERS

Users may be removed from federated chats if new controls are enabled and requirements aren’t met.
🛡️

IT ADMINS

If you enable these controls, review external access policies, allowed domains, and update guidance for helpdesk staff.
📅

ROLLOUT TIMELINE

Upcoming:
Aug–Sep 2026

📢 Official Microsoft Message Center Announcement


(Updated) Microsoft Teams: Stricter external access controls for federated chats
Message ID: MC1423114 (Updated)

Updated August 4, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why]

We’re introducing two new Microsoft Teams PowerShell controls that help organizations enforce external access and federation policies more consistently in federated group chats:

  • External Access Restrictions for Chat Participants (EnableExternalAccessRestrictionsForChatParticipants)
  • Mutual Federation for Chat Participants (EnableMutualFederationForChatParticipants)

These controls are independent from each other and help ensure federated chat participation strictly aligns with configured external access policies. They help reduce indirect exposure to unapproved external organizations and provide admins with greater control over cross-tenant communications. 

[Rollout Schedule]

  • General Availability (Worldwide): Beginning late July 2026 and expected to complete late September 2026
    • External Access Restrictions for Chat Participants available: August 14, 2026 (previously July 31)
    • Mutual Federation for Chat Participants available: September 30, 2026

[Impact on Your Organization]

Who is affected

  • Microsoft Teams administrators managing external access and federation settings
  • Organizations using federated group chats with external tenants
  • Users assigned External Access Policies that restrict federation access

Platforms/Services

  • Microsoft Teams
  • Teams PowerShell

What will happen

  • The new controls are disabled by default.
  • The change only affects organizations that choose to enable the controls.
  • The controls are configured through the existing Set-CsTenantFederationConfiguration PowerShell cmdlet.

When EnableExternalAccessRestrictionsForChatParticipants is enabled:

  • Users whose External Access Policy has EnableFederationAccess set to False cannot be added to federated group chats with external users.
  • Those users are automatically removed from existing active federated group chats that include external participants.
  • This setting does not change behavior controlled through the CommunicationWithExternalOrgs setting in External Access Policies.

When EnableExternalAccessRestrictionsForChatParticipants is disabled:

  • Users whose External Access Policy has EnableFederationAccess set to False can still participate in federated group chats if the chat was created by a user in their organization who is allowed to use federation.

When EnableMutualFederationForChatParticipants is enabled:

  • All federated group chat participants from tenants that have this setting enabled must be allowed to federate with the domains of the other tenants in the chat. 
  • Users who do not meet mutual federation requirements with all other participants cannot be added to or join the chat (not even facilitated through a third-party tenant that they are allowed to federate with)

Participants can be automatically removed from active chats when federation requirements are no longer met.

When EnableMutualFederationForChatParticipants is disabled (default):

  • Only the user being added (or joining) and the chat initiator must have a valid federation relationship. Other existing chat participants might not meet the user’s effective external access requirements.

  • Supported scenarios include:
    • Creating external federated group chats.
    • Adding users to external federated group chats.
    • Enforcing updated federation requirements after external access or federation policies change.

Additional details:

  • Automatic participant removal applies only to active group chats (a chat that has had a message sent within the previous two hours). Users in inactive group chats are evaluated when new activity occurs.
  • The user who initiated the chat is never automatically removed.
  • These two new controls do not affect:
    • Meetings with external users and meeting chats
    • Shared Channels

[Action Required/Recommendations]

No immediate action is required.

If you plan to enable these controls:

  • Review your organization’s external access requirements and federation strategy.
  • Verify that your Allowed Domains configuration is complete and current.
  • Review External Access Policies to identify users or groups with EnableFederationAccess set to False.
  • Assess business processes that rely on federated group chats involving multiple external organizations.
  • Communicate potential impacts to helpdesk staff and affected stakeholders.
  • Review the Microsoft Teams PowerShell documentation for Set-CsTenantFederationConfiguration.

Organizations may observe users being removed from existing federated group chats after either they or a partner organization enable these controls and federation requirements are no longer satisfied.

Learn more: Set-CsTenantFederationConfiguration | Microsoft Teams | Microsoft Learn

[Compliance considerations]

QuestionAnswer
Does the change provide a new way of communicating between users, tenants, or subscriptions?Yes. The change modifies how existing federated group chat communications are governed by enforcing participant eligibility and mutual federation requirements across tenants.
Does the change include an admin control and can it be controlled through Entra ID group membership?Yes. Two new administrator controls are introduced through Teams PowerShell: EnableExternalAccessRestrictionsForChatParticipants and EnableMutualFederationForChatParticipants. User impact depends on External Access Policy assignments, which can be administered through existing policy assignment mechanisms.

Source: Microsoft Message Center • Analysed by MWPro

<<< [MC1423114] Archive
Tooltip: View earlier revisions of this post

Share This Update