Jump to content

Recommended Posts

Posted

We've had a couple of lessons this week disrupted by unknown (and unwanted!) external people joining them.

 

We can't see how this is possible. The teacher will "meet now" inside a team - and we believe this meeting is only available for those in that team?

 

We have allowed external access - but we understood this only worked for a meeting where the link was shared - not that anyone could access any meeting.

 

We can turn off guest access to our entire tenant - but this feature is useful for meetings where we actually do want to see external people.

 

Anyone had anything similar? Or knows how they've avoided it?

Posted
We don't use Teams but we have had a similar issues with strangers joining lessons This activity may or may not be linked to the TikTok fad which encourages users to share their log in details for online learning so that others can crash into lessons.
  • Thanks 1
Posted

Used to be able to just set the Team Meeting option so only those signed in your organisation can bypass your lobby. For some reason, Microsoft have changed this recently to 'Those in your organisation AND GUESTS!!!!!' WTF? The key here is to use the Lobby feature. Teachers will have to allow people in from the Lobby into the Meeting and ignore those that are not recognised - let them fester in the lobby! Also, make sure they have those that can present set to 'Only Me' or chaos reigns as students can kick others out and generally disrupt. They also need to control who can unmute.

 

PEte

Posted
Used to be able to just set the Team Meeting option so only those signed in your organisation can bypass your lobby. For some reason, Microsoft have changed this recently to 'Those in your organisation AND GUESTS!!!!!' WTF? The key here is to use the Lobby feature. Teachers will have to allow people in from the Lobby into the Meeting and ignore those that are not recognised - let them fester in the lobby! Also, make sure they have those that can present set to 'Only Me' or chaos reigns as students can kick others out and generally disrupt. They also need to control who can unmute.

 

PEte

We do that but are finding impostors will create names identical to the students display names. It must be shared by the students but it's making it extremely difficult to identify the real student in the meeting lobby for the teacher if not impossible [emoji21]
Posted
We do that but are finding impostors will create names identical to the students display names. It must be shared by the students but it's making it extremely difficult to identify the real student in the meeting lobby for the teacher if not impossible [emoji21]

Our solution to not knowing if it's an official account, or a guest, turned out to be a bit of an accident.

We set all our users profile picture previously as the School logo, and as we prevent users from changing that profile picture (including in teams) if a guest account joins it has the default Office 365 avatar of a couple of letters, where as all our users clearly show the logo in the lobby.

 

Now if staff pay attention to that or just click "admit" as the messages pop up we can't control, since the few incidents we've had this month is mainly students sharing the invite message that gets sent out with friends elsewhere as a laugh.

  • Thanks 2
Posted
Our solution to not knowing if it's an official account, or a guest, turned out to be a bit of an accident.

We set all our users profile picture previously as the School logo, and as we prevent users from changing that profile picture (including in teams) if a guest account joins it has the default Office 365 avatar of a couple of letters, where as all our users clearly show the logo in the lobby.

 

Now if staff pay attention to that or just click "admit" as the messages pop up we can't control, since the few incidents we've had this month is mainly students sharing the invite message that gets sent out with friends elsewhere as a laugh.

I'm glad someone else is doing this, as I've just done this for our school, for the same reason... Validation is always good..!
Posted
Our solution to not knowing if it's an official account, or a guest, turned out to be a bit of an accident.

We set all our users profile picture previously as the School logo, and as we prevent users from changing that profile picture (including in teams) if a guest account joins it has the default Office 365 avatar of a couple of letters, where as all our users clearly show the logo in the lobby.

 

Now if staff pay attention to that or just click "admit" as the messages pop up we can't control, since the few incidents we've had this month is mainly students sharing the invite message that gets sent out with friends elsewhere as a laugh.

How do you disable them changing their profile picture?
Posted (edited)

So i`ve disabled our Guest access and enabled external access - My understanding of the two is that now we can still create meetings with external users but not Teams?

 

I`m yet to test access to a meeting from a shared link.

 

Tried with a guest account and I can access the meeting?? Must be missing something?!

Edited by maxrebo
Posted

Seems like even a "meet now" meeting has a link the students can see - so they could share with someone outside our organisation.

"Guests" seems to be an admin feature of known email addresses we've permitted access to?

So for a lesson - we want to stop anyone using the link who is outside our organisation (actually I'd be happy with the meeting link not working for students at all, they have no need even to invite students who ought to be in the class). But for other meetings - we do want to be able to have external people able to follow a link.

I'm not sure lobby is a good solution - I think we'll drive staff up the wall making them start every lesson needing to check the lobby, and then we'll find too many students who are 10-15 minutes later but can't get in.

This seems harder than we'd hoped for!

Posted
Seems like even a "meet now" meeting has a link the students can see - so they could share with someone outside our organisation.

"Guests" seems to be an admin feature of known email addresses we've permitted access to?

So for a lesson - we want to stop anyone using the link who is outside our organisation (actually I'd be happy with the meeting link not working for students at all, they have no need even to invite students who ought to be in the class). But for other meetings - we do want to be able to have external people able to follow a link.

I'm not sure lobby is a good solution - I think we'll drive staff up the wall making them start every lesson needing to check the lobby, and then we'll find too many students who are 10-15 minutes later but can't get in.

This seems harder than we'd hoped for!

 

We quickly scrapped the Lobby Idea as staff complained that they would have to let everyone in and it would take too long.

Posted
We use the lobby, and pupils are meant to be logged in. If they're logged in you'll get a "presence indicator" dot on their icons - red/green/yellow, if there isn't one that means they're a guest. Unfortunately guests don't all show with "(Guest)" after their name at the moment, e.g. if they joined as a guest from an Android device so the presence indicator is the way to tell who's actually logged in. We get the teachers to run through the list of people in the lobby when putting the lesson registration data into the MIS.
  • Thanks 3
  • 2 weeks later...
Posted

We ended up with the same problem. If turn off anonymous join as per this Microsoft document it will prevent it (https://docs.microsoft.com/en-us/microsoftteams/meeting-settings-in-teams). I did worry that this would prevent staff meeting with parents, but as long as the people you want joining the meeting are invited using the required attendees field they can still join.

 

I was sure (until I saw @Katy's) post that all guests showed up as guests when viewed from the lobby. We discovered that anonymous meeting joins from the Apple and Android app miss out the (Guest) from their name when showing up in the "xyz in the lobby" dialog.

 

I also started using call history and the debug logs to trace the culprits. In the Teams admin centre go to the users section and enter the name of the teacher in who's lesson the incident occurred then find the meeting they were in. There's likely to be a number of anonymous users showing up. Click on each one in turn, this will take you to the anonymous users call data. The Overview section helps to identify the device being used. If you then look in Debug and search for localsite you will find the IP address of the where they were connecting from. It's not perfect in that connections through the web browser show up as a Microsoft owned range, and anyone using mobile data is likely to end up with random addresses on repeat visits. However in several cases I took the IP address and then went to Azure AD and used it to filter the logins in the sign-in logs. This identified specific individuals. The students parents ended up with an conversation with one of our assistant heads. Since we did this the problem has not reoccurred.

Posted

strange, when you start a meeting within a channel, it should only allow channel members to join. if the team itself has the wrong permissions that allow pupils to invite external users this would be odd.

 

Also under external access you can limit the allowed domains, (this disables all other domains as a side effect) I've allowed ac.uk and sch.uk and other dorset domains. this should limit this. I've had 0 issues of the type you are describing.

Posted
when you start a meeting within a channel, it should only allow channel members to join.

 

Nope, I am afraid that is wrong. I mean it *should* but that is not what the documentation says, nor is it the actual behaviour of the system as built.

 

However, the other steps you suggest are great ideas, provided you have also disabled Anonymous access.

Posted
We ended up with the same problem. If turn off anonymous join as per this Microsoft document it will prevent it (https://docs.microsoft.com/en-us/microsoftteams/meeting-settings-in-teams). I did worry that this would prevent staff meeting with parents, but as long as the people you want joining the meeting are invited using the required attendees field they can still join.

 

I was sure (until I saw @Katy's) post that all guests showed up as guests when viewed from the lobby. We discovered that anonymous meeting joins from the Apple and Android app miss out the (Guest) from their name when showing up in the "xyz in the lobby" dialog.

 

I also started using call history and the debug logs to trace the culprits. In the Teams admin centre go to the users section and enter the name of the teacher in who's lesson the incident occurred then find the meeting they were in. There's likely to be a number of anonymous users showing up. Click on each one in turn, this will take you to the anonymous users call data. The Overview section helps to identify the device being used. If you then look in Debug and search for localsite you will find the IP address of the where they were connecting from. It's not perfect in that connections through the web browser show up as a Microsoft owned range, and anyone using mobile data is likely to end up with random addresses on repeat visits. However in several cases I took the IP address and then went to Azure AD and used it to filter the logins in the sign-in logs. This identified specific individuals. The students parents ended up with an conversation with one of our assistant heads. Since we did this the problem has not reoccurred.

Are you sure it won't prevent external users joining meetings even if they are added as an attendee within the meeting invitation?

 

From all the reading I've done it only allows users to join who can login with a Microsoft account or potentially a federated Google account.

 

The only Microsoft post I can find regarding it is https://techcommunity.microsoft.com/t5/microsoft-teams/what-does-disabling-anonymous-users-from-joining-teams-meetings/td-p/360843

 

Cheers

  • 2 weeks later...
Posted

I've had a support case open with Microsoft for guest being able to join from a mobile device without having '(Guest)' added to their name. Microsoft admitted the problem and have been working on it. Yesterday I was told this:

 

I hope this meets you well.

 

Please be informed that the issue has is fixed. However, it would take 2-3 weeks to propagate to the general ring.

 

Apologies for any inconvenience.

 

I've done a test today and it's not fixed for me yet, but this fix is hopefully on it's way out to clients.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...