ORIGINAL REDDIT POST

Block entire top level domain from teams calls

We have been getting an influx of spam calls from specific top level domains (.top, .sk, etc.) , from various accounts and domains. Can we block these teams calls/chats without disabling all external access? From what i see wildcards are not supported. For…

Original postr/sysadmin

We have been getting an influx of spam calls from specific top level domains (.top, .sk, etc.) , from various accounts and domains. Can we block these teams calls/chats without disabling all external access? From what i see wildcards are not supported. For email a rule has already been setup.

Collected discussion

13 comments

u/XB_Demon1337

You should be using a whitelist anyways. What is the point in a black list for Teams? Like it allows anyone in the world to message you. You should only allow certain companies to message you. Vendors, partner companies, etc.

u/Valdaraak

Disable external access, whitelist approved external domains.

u/sitesurfer253

White list is the way to go. We set this up relatively simply, just pull a report of the domains your users have interacted with using powershell, convert to a csv, switch teams to whitelist instead of blacklist and at the same time upload the csv of domains. Unless your users are contacting new domains daily, they will just submit a ticket saying they can't talk to X@Y.com and if they look legit, add to the whitelist.

u/cantstandmyownfeed

Oh good, another reason for the sales people to blame IT for their missed quotas.

u/Defconx19

Sales and Marketing team has entered the channel.

u/lordmycal

And then look at blocking these stupid TLDs at the DNS and/or firewall level. I'm never going to receive a legitimate, work related request to go to website.blue or website.singles or website.guru. It seems like 99% of those newer gTLDs are only used for phishing and malware.

u/True-Price5403OP

Does this cover only direct calling or meetings with other domains as well?

u/Demented_CEO

Tenant Allow/Block List is your friend, if you want to go down that route, but you need to identify the domains. Not just TLDs. I'd also go with whitelisted domains instead.

u/[deleted]

This comment was deleted.

u/Sasataf12

If you go with an allowlist make sure you have a quick and reliable way to update that allowlist. Otherwise you're just replacing one problem with another (potentially larger) one.

u/rambleinspam

Domains will just change, we are having the same issue.

u/[deleted]

This comment was deleted.