eMerge 365 Alert: Management of External Bots Joining Your Teams Meetings
Aug 12 2026
During Teams meetings, if an external third-party bot attempts to join a meeting, organizers will be able to see a clear representation of the bot while it waits in the lobby. Organizers will be required to explicitly and separately admit the bot into the meeting, where desired. This approach will ensure that no one inadvertently accepts external bots into a meeting, promoting full organizer control over the presence of these bots.
Additionally, Microsoft is extending the admin controls provided for managing external AI bots and regulating their access to meetings by adding the option to automatically block all identified bots.
What’s Changing and When
These are new features and the retirement of an existing feature.
Microsoft 365 Roadmap ID: 558107
Preview: NA
Expected GA: Rolling out June 2026
Microsoft 365 Roadmap ID: 566201
Preview: NA
Expected GA: August 2026
Please also note the following feature retirement: Retirement of CAPTCHA for meeting join
Microsoft Message Center ID: MC1262588
Expected retirement: Late August 2026
Why This Matters
The use of meeting bots to transcribe discussions, capture notes, and identify action items is rapidly increasing. However, allowing third-party (non-Microsoft) bots to join meetings without proper awareness or controls can create significant confidentiality, privilege protection, data security, and privacy risks.
New capabilities help protect meeting content by automatically detecting bots and enabling the meeting organizer to decide how to handle them. In addition, administrators will have clear, centralized controls to define how bots are managed across meetings, ensuring that their use aligns with organizational security and compliance requirements.
Teams will soon use behavioral and infrastructure signals to identify bots more accurately, and an upcoming registration program will allow third-party software vendors to formally identify their bots via a self-identification marker. When bots are detected, they can be held in the meeting lobby and visually separated from human participants, with lobby members grouped into two categories — “Waiting” (verified participants and registered bots) and “Suspected Threats” (unregistered or system-flagged bots) — giving organizers a clearer, at-a-glance view of who (or what) is trying to join. To prevent accidental admission, Teams will be adding friction to the bot-admission process, including confirmation prompts, warnings when using “Admit All,” and the removal of the one-click admit option for identified bots.
As a result of these changes, Microsoft will retire the CAPTCHA for meeting join feature set. Microsoft provided the following timeline for this retirement but notes that the features will be retired once the other bot detection features are released:
- Early May 2026: CAPTCHA policy can no longer be enabled.
- Late July 2026: CAPTCHA policy removed from PowerShell.
- Late August 2026: CAPTCHA policy removed from the Teams Admin Center.
No administrative action is required to manage the retirement, but organizations should consider adopting the newer bot detection features as a replacement.
Key Risks Organizations Should Consider
Allowing third-party bots into meetings introduces meaningful confidentiality, privilege protection, security, privacy, and compliance risks. These features enable organizations to more effectively identify and reduce those risks.
Data Privacy
Third-party bots may receive full access to meeting content, including audio/video, live chat and reactions, shared screens or documents, and participant names, emails, and metadata.
eDiscovery and Records Management
Third-party bots often store transcripts, summaries, or recordings outside Microsoft 365, placing this data beyond established Microsoft Purview legal hold and retention controls. As a result, information may fall outside corporate recordkeeping and preservation requirements, deletion timelines may be inconsistent and undermine defensible disposition, and retention is frequently governed by non-configurable, manual, or vendor-controlled processes that are not aligned with enterprise retention schedules.
Privilege Protection
A key component of attorney-client privilege is that the communication in question was conducted in a confidential manner, and the presence of a third party (human or bot) in an otherwise privileged meeting could undermine that element, risking privilege waiver.
Security and Identity
Bots operate as nonhuman identities with persistent access, often relying on broad, long-lived OAuth permissions that may bypass conditional access, MFA, or DLP controls. If compromised, these bots can become powerful attack vectors. Restricting bot access at the front end reduces the need for reactive security controls that would otherwise be required after an unauthorized bot has already joined a meeting.
How eMerge Can Help
eMerge can help clients develop clear policies governing the use of third-party bots and AI note-taking/meeting applications, including who may host them, which tools are permitted, where meeting data is transmitted, and how long it is retained. Using this visibility, eMerge can identify specific risk patterns (such as frequent use of unapproved bots, external participation in sensitive meetings, or inconsistent retention) and convert those findings into concrete, practical policy requirements.
eMerge can then work with clients to design and implement processes to operationalize and enforce these policies by standardizing approved bots and applications, aligning Teams meeting settings with information governance rules, and restricting certain capabilities for high‑risk meetings.
Bottom Line
Effective management of enterprise risk begins with awareness. These features give meeting organizers and enterprise administrators clear visibility into the presence of third-party bots attempting to join their meetings and enable broad or conditional blocking of such bots.
Want to learn more about whether and how this new capability should be enabled in your environment? Contact eMerge Information Governance for guidance.