Overview
- Microsoft began rolling out the new Teams admin policy Manage external bots and their access to meetings in late June, which auto-detects suspected bots and sends them to the meeting lobby for review.
- Teams now uses a mix of behavioral and infrastructure signals to identify non‑human participants with higher accuracy instead of relying on the older CAPTCHA challenge.
- Detected bots are visually labeled and grouped in the lobby as either waiting or suspected threats, and organizers must confirm admission because one‑click Admit has been removed for identified bots.
- Microsoft is previewing a Teams Bot Identification Program that will let ISVs register and self‑identify known bots to be pre‑cleared, and it has started retiring the legacy CAPTCHA flow.
- Administrators can assign the new policy to users or groups and are advised to pair it with stricter lobby admission settings now while Microsoft develops extra controls such as allow lists, org‑wide blocking and audit logs.