logo

The Hidden Security Risk in Microsoft Teams: Detecting AI Note-Taking Bots with KQL

ID: 31e9dba9-de16-5853-a35f-c2a58f9ca29f

STIX ID: report--31e9dba9-de16-5853-a35f-c2a58f9ca29f

Feed Name: Detect FYI

Threat Score
35/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Bi Yue Xu

...
...

This report details a security/privacy gap where third‑party AI note‑taking bots can join Microsoft Teams meetings via calendar integrations and capture conversations outside the organization; it provides Microsoft Defender Advanced Hunting KQL queries to detect MeetingParticipantDetail events (participants admitted from the lobby), identify likely AI bots and the user who admitted them, and recommends mitigations such as blocking known bots, monitoring admissions, and user education while noting event ingestion delays.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.