Jump to content
  • Microsoft shares details on a new Teams mandatory security requirement update


    Karlston

    • 553 views
    • 2 minutes
     Share


    • 553 views
    • 2 minutes

    Microsoft has announced that it will introduce updated authentication requirements for the Microsoft Teams PowerShell Module, with enforcement starting on September 15, 2025. The change affects organizations using application-based authentication, particularly those integrating Microsoft Entra applications for backend Teams management or automation. The company has cautioned that failure to deploy the necessary changes in time can lead to "service disruption."

     

    According to Microsoft, the update is part of its broader effort to “strengthen security across Microsoft 365 services” and will require Entra applications accessing the Teams PowerShell Module to be “properly scoped and secured.”

     

    This change aligns with the company's ongoing security hardening, like the ones announced earlier this year in June 2025 where it confirmed that it will be disabling outdated security protocols, which perhaps coincidentally happened just days after the Washington Post email hacks.

     

    For those not familiar, the Microsoft Teams PowerShell Module is widely used for administrative automation, enabling IT teams to configure policies, manage settings, and control Teams features at scale. It is essentially a set of cmdlets for managing Teams directly from the PowerShell command line and requires Windows PowerShell version 5.1 or PowerShell version 7.2 or later.

     

    The message was published on the Microsoft 365 admin center dashboard and it lays out the eligible application permissions that require the update:

     

    • RoleManagement.Read.Directory: Required for all Entra applications to verify association with an Administrative Unit.
    • GroupMember.Read.All: Required if your application uses the following cmdlets:
      • *-CsGroupPolicyAssignment
      • *-CsGroupPolicyPackageAssignment

     

    Aside from that, Microsoft has also outlined the steps on how to "ensure uninterrupted access" by reviewing and updating them. It writes:

    1. Review your Entra applications:
    • Go to Microsoft Entra ID > Roles and administrators.
    • Check the Global Administrator, Teams Administrator, and Skype for Business Administrator roles for any Entra applications or service principals used with Teams PowerShell.

    2. Update API permissions:

    • Navigate to Microsoft Entra ID > App registrations.
    • Locate the relevant application and add the following permissions:
      • GroupMember.Read.All
      • RoleManagement.Read.Directory

    For those who have access to the Microsoft 365 admin center website, they can view the message under ID MC1134747.

     

    Source


    Hope you enjoyed this news post. Feedback welcome.

    Posted Saturday 16 August 2025 at 4:58 am AEST (my time).

    News posts... 2023: 5,800+ | 2024: 5,700+ | 2025 (till end of July): 3,458

    RIP Matrix


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...