Blocking external Teams from all onmicrosoft.com domains

Jeff Rynders 0 Reputation points
2026-09-17T16:07:47.2133333+00:00

We have external collaboration set up in Teams, but we've been getting hit by these fly-by-night phishers coming from onmicrosoft.com domains. If we block the onmicrosoft.com domain in the Teams admin center for external collaboration, is that going to affect us as a tenant? We have custom domains set up for our tenant.

Microsoft Teams | Microsoft Teams for business | Meetings and calls | Audio and video

2 answers

Sort by: Most helpful
  1. Jeff Rynders 0 Reputation points
    2026-09-23T13:49:13.9433333+00:00

    I understand not wanting to block the entire onmicrosoft.com domain. We usually do not see any legitimate clients who do not have their own domain in their tenant. We do, however, see numerous phishing attempts to users from malicious actors who have set up temporary tenants under a .onmicrosoft.com tenant and I think the "microsoft.com" part of that address makes it appear more legitimate to users. I just wanted to make sure that in blocking the onmicrosoft.com domain would not cause any internal issues because our .onmicrosoft.com domain in our tenant still exists underneath everything.

    Was this answer helpful?


  2. Chris-D 1,695 Reputation points Independent Advisor
    2026-09-17T16:30:22.8366667+00:00

    Hi Jeff,

    Thank you for sharing the details of your concern. 

    The domain restrictions configured under External access in the Microsoft Teams admin center are intended to control communication with users from external organizations. Therefore, blocking an external domain should not disable your tenant’s own default tenantname.onmicrosoft.com domain, affect your custom domains, or interfere with communication between users within your organization. 

    However, blocking the entire onmicrosoft.com domain may be broader than intended. Many legitimate Microsoft 365 organizations use tenant-specific domains in the format organizationname.onmicrosoft.com. Depending on whether the configuration also applies to subdomains, this could prevent your users from communicating through Teams with legitimate external organizations that use those domains. 

    For this reason, I recommend blocking the specific tenant domains associated with the suspicious activity, such as suspicioustenant.onmicrosoft.com, or blocking the individual sender addresses, rather than blocking the entire onmicrosoft.com domain. You may also review the Teams external domain anomalies report to help identify the external domains responsible for the unwanted communication before adding them to the block list.   

    • If your organization communicates only with a defined group of external partners, you could also consider configuring External access to allow only specific trusted domains.  

    Kindly note that External access controls external chats and meetings and is separate from guest access to teams, channels, and other organizational resources. 

    For reference, you may find these Microsoft articles helpful: 

    I hope this helps clarify the expected impact and the safer options available. Should you have any further questions or need additional assistance, please feel free to share them in the comment below. I'm very happy to help.  


    If the answer is helpful, please click 'Yes' and kindly upvote it.

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.