Augmentt Update: Teams Policy Management Goes Live, and Purview DLP Coverage Expands

Table of Contents

A client calls because a guest joined a Teams meeting and started sharing their screen when they shouldn’t have been able to. You go looking for the setting, and it’s buried in the Teams admin center for that one tenant. You fix it there, then remember the other nineteen tenants are probably configured the same way, because nobody ever went back and standardized it. So you start clicking through each one by hand.

That’s the kind of work this release is aimed at. Here’s what shipped.

Standardize Microsoft Teams Across Every Tenant, From One Screen

Teams policies and settings are live in Secure Autopilot. You can now see and manage the Teams configuration that actually drives risk, guest access, external federation, meeting permissions, messaging permissions, without opening the Teams admin center for each client separately.

Augmentt Teams Settings screen showing guest access, external federation, and guest meeting and messaging permissions for a client tenant

Alongside settings, you get Teams policies: Meeting, Messaging, Channels, and External access. Build a policy once as a template or baseline, then push it to every client the same way you already do with Conditional Access and Intune. No more recreating the same meeting policy from scratch for the fifteenth time.

Augmentt Teams Policies list showing counts for Meeting, Messaging, Channels, and External access policies across a tenant

And when a client needs something adjusted on the spot, you don’t have to redeploy an entire policy. Inline edit lets you open a policy and change the specific setting live, right from the Augmentt portal.

Augmentt inline edit view of a Teams meeting policy, showing toggles for meeting scheduling, join and lobby settings

Purview Gets Broader DLP Coverage, Plus Retention and Sensitivity Labels

Two weeks ago we shipped Data Loss Prevention policy support. This release extends it. Augmentt now covers additional DLP policy locations, including Copilot, Foundry, Power BI, Managed Cloud Apps, and Inline Web Traffic, so the policy you build accounts for where data actually moves through a client’s tenant now, not just where it moved a year ago.

Retention Policies are here too. Apply retention across Exchange, SharePoint, OneDrive, Teams, and Groups, so a client’s data lifecycle rules are consistent everywhere instead of configured piecemeal per workload.

Sensitivity Labels round it out. Classify and protect data so you control what users, devices, and AI tools can actually access, and how that data can be used once they have it. As Copilot and other AI tools get pointed at client tenants, that label is doing real work.

Augmentt Purview Data Loss Prevention policy list, showing policy name, priority, mode, and sync status for a client tenant

Two New Checks Round Out Email Posture Coverage

Two new security checks joined the posture library this release: inbound anti-spam policies that don’t contain allowed domains, and outbound anti-spam message limits that aren’t in place. Both are common gaps and both show up in the same posture view you’re already using.

Defender EOP: Fix the Check, Right From the Recommendation

Augmentt has supported templating, deployment, and standardization of Defender EOP policies for a while now. This release adds per-security-check configuration on top of it.

Instead of jumping into Microsoft’s admin center to figure out which setting a failing check actually wants, you can now edit the existing policy directly from the check itself, with the recommended settings already populated, through a short wizard flow. That covers all 34 Defender EOP checks Augmentt tracks against Secure Score.

Augmentt Configure tab for a Defender EOP posture check, showing a recommended fix and a choice between editing an existing policy or creating a new one

Where to Find It

Teams settings and policies are under Secure > Teams. The expanded Purview coverage, DLP, Retention, and Sensitivity Labels, is under Secure > Purview. The two new anti-spam checks and the Defender EOP Configure tab show up right where you already review posture, under Secure > Security Posture, on the check itself.

FAQ

What’s the difference between Teams settings and Teams policies in Augmentt?

Settings cover the tenant-wide controls, guest access, external federation, and guest meeting and messaging permissions. Policies are the Meeting, Messaging, Channels, and External access policies you build as templates or baselines and deploy to specific groups of users, then edit inline when something needs a quick change.

Does the new Purview DLP coverage include Copilot?

Yes. This release adds DLP policy coverage for Copilot and Foundry, along with Power BI, Managed Cloud Apps, and Inline Web Traffic locations, on top of the DLP support Augmentt shipped two weeks prior.

How many Defender EOP checks can I now fix through the Configure tab?

34. Each one supports per-security-check configuration, so you can apply the recommended fix to an existing policy or create a new one without leaving the check.

Do I need to rebuild my Defender EOP policies to use the new configuration option?

No. The Configure tab edits your existing policies with the recommended settings needed to satisfy the Secure Score recommendation behind the check. You’re not starting over.

Where do the two new anti-spam checks show up?

Alongside your existing checks in Security Posture: one flags inbound anti-spam policies missing allowed domains, the other flags outbound anti-spam policies without message limits in place.

Photo by Roman Kraft on Unsplash

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.