Microsoft Defender Tenant Allow/Block List can now block external Teams users and domains

Microsoft has enhanced the integration between Teams and Defender for Office 365, allowing security admins to manage blocked external users and domains in Teams directly through the Tenant Allow/Block List (TABL) in the Microsoft Defender portal. Previously, only domain blocking was supported.

This update should centralize external access controls across Microsoft 365 services, improving consistency for security and compliance teams.

Timeline

The rollout should be completed in February 2026.

How does this affect your organization?

Microsoft has supported domain blocking in Teams via the Defender Tenant Allow/Block List since September 2025. That initial implementation was limited to domains.

Tenant Allow/Block list from September 2025
Tenant Allow/Block list from September 2025
Read:  Teams now supports domain blocking via Microsoft Defender Tenant Allow/Block List

The list now supports both external domains and email addresses.
Incoming communications, including chats, channel messages, meetings, and calls, from blocked users are prevented. Any existing communications from blocked users are automatically deleted.

  • Up to 4,000 blocked domains and 200 email addresses are supported.
  • A Defender for Office 365 Plan 1 or Plan 2 subscription is required.
Tenant Allow/Block list now supports domains and email addresses
Tenant Allow/Block list now supports domains and email addresses

Adding an email address may currently return an error, even though domain entries work as expected.

To block email addresses on Teams, contact your Teams administrator about enabling “Block specific users from communicating with people in my organization.”

You cannot add an email address to the Tenant Allow/Block list
You cannot add an email address to the Tenant Allow/Block list

To resolve this, enable “Block specific users from communicating with people in my organization” with Teams PowerShell or via Teams Admin Center. A setting introduced in February 2025 as part of the Teams External Access configuration.

You need to enable BlockExternalUserAccess to support email addresses in the TABL
You need to enable BlockExternalUserAccess to support email addresses in the TABL
Read:  Block an external user in Microsoft Teams

Reminder, DomainBlockingForMDOAdminsInTeams must be enabled; without it, security admins cannot manage blocked domains and email addresses through the Microsoft Defender TABL.

You need to enable DomainBlockingForMDOAdminsInTeams
You need to enable DomainBlockingForMDOAdminsInTeams

These settings can also be configured by a Teams administrator via Teams Admin Center > External Access.

External access settings in the Teams Admin Center
External access settings in the Teams Admin Center

Blocked senders receive a delivery error and are unable to communicate further with your organization.

Blocked sender through the TABL
Blocked sender through the TABL
Share
Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Reply

Your email address will not be published. Required fields are marked *