Teams Admin Centre
Meeting & messaging policies
Guest & external access
Teams Phone basics
Compliance recording
Day 1
Teams architecture & M365 Group link
Day 2
Teams policies & messaging
Day 3
Guest access & external users
Day 4
Meetings, calling & live events
Day 5
Review & assessment
The M365 Groups created in Weeks 1 and 4 underpin every team. SharePoint sites from Week 4 become Teams file tabs. Exchange Online from Week 3 provides the shared mailbox and calendar. CA policies from Week 2 govern Teams sign-ins. Week 5 is where the full M365 stack becomes visible as a unified system — Teams is the user-facing layer where everything built over the past four weeks converges.
The Teams policy landscape — what Week 5 covers
Meeting policies
Who can present, lobby bypass settings, recording, transcription, live captions, whiteboard, attendance reports.
Messaging policies
Edit/delete sent messages, read receipts, URL previews, Giphy/memes/stickers, priority notifications, voice messages.
App permission policies
Which Microsoft apps, third-party apps, and custom apps users can install and use in Teams channels and tabs.
Calling policies
PSTN calling, call forwarding, simultaneous ring, call parking, delegation. Requires Teams Phone licence.
Compliance recording
Policy-based recording for regulatory requirements. Separate from convenience recording. Requires E5 compliance or add-on.
Daily breakdown
Day 1
Lecture: Teams architecture — how Teams, M365 Groups, SharePoint, and Exchange are linked; Teams Admin Centre layout; channel types (standard, private, shared); team member roles; lifecycle settings
Lab 5-A: Create teams from existing M365 Groups (LL-Finance, LL-Sales, LL-AllStaff from Week 1) → create standard, private, and shared channels → configure team settings → set lifecycle expiry policies → configure org-wide settings in Teams Admin Centre
Day 2
Lecture: Teams policy types, policy packages, the policy assignment cascade (org-wide → group policy → user policy), messaging governance controls
Lab 5-B: Create LL — Finance Messaging Policy (restricted Giphy, no external stickers, delete off) → create LL — Management Meeting Policy (no lobby bypass) → assign policies to LL-Finance and LL-Management groups → verify effective policy for individual users → explore Teams app permission policies
Day 3
Lecture: Guest access vs external access (federation) — different controls, different user experience; what guests can and cannot do; the link between Teams guest access and SharePoint external sharing from Week 4
Lab 5-C: Configure Teams guest access settings → set per-meeting guest permissions → add a guest user to the LL-Sales team → verify guest vs member experience → configure external access (federation) → audit guest membership across all teams
Day 4
Lecture: Meeting policies in depth — lobby, recording, transcription storage; Teams Phone basics — calling plans and dial-in; live events vs webinars; compliance recording architecture
Lab 5-D: Configure LL — All Staff Meeting Policy (lobby, recording, transcription) → configure meeting recording storage (OneDrive/SharePoint) → explore Teams Phone settings → configure live event policy → explore compliance recording policy settings (E5)
Day 5
Review: Teams policy stack, guest governance, meeting compliance — open Q&A CA001–CA004 activation from Report-only to On (last window before Week 6)
Assessment: Teams governance incident — external guest added to wrong team with access to confidential channel content; meeting recording containing sensitive information shared externally; students investigate, remediate, and recommend policy improvements
Key concepts introduced this week
| Concept | What it is | Why it matters for the rest of the course |
| Teams ↔ M365 Group relationship | Every team is backed by an M365 Group. Creating a team creates: an M365 Group (members), a SharePoint site (Files tab), an Exchange mailbox (calendar, email), and a OneNote notebook. Deleting the team deletes all of these. | The M365 Groups and SharePoint sites from Weeks 1 and 4 persist through Teams. DLP policies in Week 7 target the same SharePoint sites. eDiscovery in Week 8 searches the same Exchange mailboxes and Teams chat history. |
| Policy assignment cascade | Teams applies policies in priority order: org-wide defaults → group policy assignments → direct user assignments. A user policy always overrides a group policy. A group policy always overrides org-wide defaults. The effective policy is the most specific one that applies. | The LL-Finance messaging policy and LL-Management meeting policy are assigned at the group level. Understanding the cascade is essential when troubleshooting unexpected policy behaviour — and the same model applies to Intune device configuration in Week 6. |
| Guest access vs external access | Guest access (B2B): an external user is added to a specific team — they get an Entra B2B guest account and can access that team's content. External access (federation): users in other Teams orgs can find and chat with Lakeview Logistics users without being added to a team. | The guest added in Lab 5-C is the subject of the Day 5 assessment incident. The distinction also explains why Teams guest access and SharePoint external sharing are separate controls that must both be configured correctly. |
| Meeting recording storage | Teams meeting recordings are stored in the organiser's OneDrive (regular meetings) or in the channel's SharePoint document library (channel meetings). The location determines who can access the recording and which retention and DLP policies apply. | Recordings in OneDrive/SharePoint are DLP-governed documents, not just video files. A Finance team recording discussing payroll data is subject to the LL — Financial Data Protection DLP policy from Week 7 and eDiscovery searches in Week 8. |
| Compliance recording | Policy-based, automatic recording triggered for specific users regardless of whether the organiser starts recording. Used for regulatory compliance. Separate from convenience recording. Requires E5 compliance or Teams Phone add-on. | First E5-only feature used in the course. Referenced in Week 8 capstone when discussing what governance controls apply to Finance team communications. |
| Teams lifecycle management | M365 Groups (and therefore Teams) can be configured with expiry policies — inactive teams are flagged and deleted if no owner renews them. Naming policies and creation restrictions prevent team sprawl. | Connects to Week 8 governance — what happens to a team's SharePoint content and Exchange data when the team expires, and how retention policies interact with team deletion to prevent premature data loss. |
Teams policies built in Week 5 labs
| Policy name | Type | Assigned to | Key settings |
| LL — Finance Messaging Policy | Messaging policy | LL-Finance group | Giphy: Off · External stickers: Off · Edit sent messages: On · Delete sent messages: Off (Finance audit trail) · URL previews: On |
| LL — Management Meeting Policy | Meeting policy | LL-Management group | Lobby: People in my org and guests · Anonymous join: Off · Recording: Enabled · Transcription: On · Attendance report: On |
| LL — All Staff Meeting Policy | Meeting policy | All users (org-wide) | Lobby: People in my org · Recording: Allowed · Transcription: On · Live captions: On · Whiteboard: On |
| LL — Guest Access Settings | Org-level guest access | All teams (org-wide) | Allow guest access: On · Private channel creation: Off · Meeting join: Web and app · IP video: On · Screen sharing: Off |
Week 5 connections to other weeks
| Week 5 element | Connected to | How |
| Teams backed by M365 Groups (LL-Finance, LL-AllStaff) | Week 1 — user and group creation | The M365 Groups created in Lab 1-C are promoted to Teams in Lab 5-A. Members, owners, and group settings carry forward automatically — no re-provisioning needed. |
| Teams Files tab → SharePoint document library | Week 4 — SharePoint permissions | The Finance SharePoint site and its Payroll Records library (with broken permissions inheritance from Lab 4-B) are accessible via the Finance team's Files tab. Teams access does not bypass SharePoint permissions — the broken inheritance still applies. |
| Meeting recordings → OneDrive/SharePoint | Week 7 Lab 7-D (DLP), Week 8 Lab 8-B (eDiscovery) | Recordings stored in OneDrive are subject to DLP content inspection and eDiscovery search. A recording of a Finance meeting discussing payroll is as DLP-governed as any other document in OneDrive. |
| Guest user added to LL-Sales team (Lab 5-C) | Week 5 Day 5 assessment, Week 7 — Threat Explorer | The guest from Lab 5-C is the subject of the Day 5 incident. Guest-originated sharing events also appear in Week 7 Threat Explorer review as external actor activity. |
| CA001–CA004 Report-only → On (Day 5) | Week 2 — deferred; Week 6 — device compliance CA | Last natural activation window before WIN-CLIENT-01 is enrolled in Intune in Week 6. If CA001 is not On by Week 6, the device compliance Conditional Access condition cannot be properly tested. |
| LL — Finance Messaging Policy (delete off) | Week 8 — eDiscovery | Preventing Finance users from deleting Teams messages means those messages are preserved for eDiscovery searches. The Week 8 case searches Teams messages as one of its content workloads. |
Primary admin centres this week
| Portal | URL | Used for |
| Teams Admin Centre | admin.teams.microsoft.com | All Teams policy creation and assignment, org-wide Teams settings, guest access, meeting policies, app policies, live event settings, calling policies — primary portal for all Week 5 labs |
| Microsoft Entra admin centre | entra.microsoft.com | M365 Group settings (expiry policies, naming policies, group creation restrictions), B2B guest user management, CA policy activation (Day 5) |
| Microsoft 365 admin centre | admin.microsoft.com | Group lifecycle expiry policy configuration, org-wide M365 Group settings linked to Teams lifecycle |
Key design decisions for Week 5
Teams is built on top of Week 1–4 infrastructure — not alongside it. The single most important framing for Day 1 is that nothing built this week is new infrastructure — it's a coordination layer on top of what already exists. The LL-Finance M365 Group is already populated. The Finance SharePoint site already has broken permissions inheritance. Exchange Online already handles the mailbox. Students who understand this build genuine intuition for how M365 works as a platform rather than a collection of disconnected apps.
E5 trial is active — advanced features are available for the first time. Teams Phone, compliance recording, advanced meeting features (attendance reports, live captions), and advanced guest governance all require E5. Day 4's compliance recording and Teams Phone settings would be unavailable on Business Standard alone. Explicitly connect E5 availability to the trial added in Week 5 Lab 1.
Week 2 deferred work — last activation window before Week 6. CA001–CA004 have been in Report-only mode since Week 2. Day 5 of this week is the last natural opportunity to activate them before WIN-CLIENT-01 is enrolled in Intune in Week 6. If CA001 is not On by Week 6, the device compliance CA condition cannot be properly tested. Flag this at the start of Day 1 and schedule 10 minutes at the end of Day 5 for students to flip the switch.
Learning outcomes — by end of Week 5, students can…
Explain Teams architectureDescribe the Teams → M365 Group → SharePoint → Exchange relationship and what gets created when a team is provisioned
Create and configure teamsCreate teams from existing M365 Groups, configure channels, set team member roles and settings
Build and assign policiesCreate meeting and messaging policies, assign to groups, and explain the policy cascade model
Configure guest accessEnable guest access, add a guest to a team, and distinguish guest access from external access (federation)
Manage meeting complianceConfigure recording storage, lobby settings, transcription, and explain compliance recording architecture
Audit guest activityUse the Teams Admin Centre to audit guest membership across all teams and identify access anomalies