ASD's Blueprint for Secure Cloud

Microsoft Teams

This section describes the configuration of Microsoft Teams associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 4 minutes

Automated Configuration Deployment and Assessment

Overview

Some of the Teams configurations can be automatically deployed using Microsoft 365 Desired State Configuration (DSC).

Some of the Teams configurations cannot be assessed using a DSC blueprint. Please refer to those configuration pages to conduct a manual assessment.

ConfigurationBlueprint automation provided
Teams & Channels
- TeamsYes (DSC)1
- Teams update managementYes (DSC)
- Migrating to TeamsYes (DSC)
External collaboration
- Guest accessYes (DSC)
- B2B member accessNo
AppsYes (DSC)
Meetings & Events
- Audio conferencingYes (DSC)
- MeetingsYes (DSC)2
- Themes & customizationNo
- Live eventsYes (DSC)
- EventsYes (DSC)3
MessagingYes (DSC)
Voice
- CallingYes (DSC)
- Call parkYes (DSC)
- Caller IDNo
- MobilityYes (DSC)
- VoicemailYes (DSC)
- Voice applicationsNo
EmergencyYes (DSC)
Enhanced encryptionYes (DSC)
UsersYes (DSC)
Teams appsNo

1: The Notifications and feeds, Tagging, Email integration, Search by name, Safety and communication and Shared channels configurations must be set manually.

2: The Include attendees in the report, Real-time-text (RTT), Allow streaming media input and Anonymous users can interact with apps in meetings configurations must be set manually.

3: The Recording & transcription configurations must be set manually.

Desired State Configuration

Before using the below DSC file, please refer to the setup and automated deployment pages for instructions.

Do not proceed with the automated deployment instructions until you’ve familiarised yourself with the addition configuration required below.

Desired State Configuration file
Download the Teams DSC file and rename the linked .txt file to .ps1.

Configuration data file
Download the configuration data file and rename the linked .txt file to .psd1.

Service principal permissions

For organisations importing the DSC as per the instructions on the automated deployment page, the following permissions will need to be added to the M365DSC app:

"TeamsAppPermissionPolicy", "TeamsAudioConferencingPolicy", "TeamsCallHoldPolicy", "TeamsCallingPolicy", "TeamsChannelsPolicy", "TeamsClientConfiguration", "TeamsComplianceRecordingPolicy", "TeamsDialInConferencingTenantSettings", "TeamsEventsPolicy", "TeamsFederationConfiguration", "TeamsFeedbackPolicy", "TeamsGroupPolicyAssignment", "TeamsGuestCallingConfiguration", "TeamsGuestMeetingConfiguration", "TeamsGuestMessagingConfiguration", "TeamsMeetingBroadcastConfiguration", "TeamsMeetingBroadcastPolicy", "TeamsMeetingConfiguration", "TeamsMeetingPolicy", "TeamsMessagingPolicy", "TeamsOrgWideAppSettings", "TeamsPstnUsage", "TeamsShiftsPolicy", "TeamsTemplatesPolicy", "TeamsTenantDialPlan", "TeamsTenantNetworkRegion", "TeamsTenantNetworkSite", "TeamsTranslationRule", "TeamsUpdateManagementPolicy", "TeamsUpgradeConfiguration"
Additional configuration

The following instructions must be completed before step 6 Deploy the configuration, on the automated deployment page:

  • Assign the Entra, Teams Administrator role to the M365DSC service principal.

Settings & policies

This section describes the configuration of the settings and policies within Microsoft Teams associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Users

This section describes the configuration of users within Microsoft Teams associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Teams apps

This section describes the configuration of apps within Microsoft Teams associated with systems built according to guidance in ASD's Blueprint for Secure Cloud.

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra