Reference
Team
All teams in your tenant
Part of the Teams inventory.
Scan settings
| Default scanning interval | Allowed scanning intervals | Data removal during incremental scan |
|---|---|---|
| Daily | Daily, Weekly, Bi-Weekly, Monthly, Never, Initial | Yes |
Properties
| Property | Type | Description | Automation placeholder |
|---|---|---|---|
| Classification | String | An optional label. Typically describes the data or business sensitivity of the team | {{Team.Classification}} |
| Initially Scanned | DateTime | Shows when this object was initially found in a scan. | {{Team.CreatedTime}} |
| Description | String | An optional description for the team | {{Team.Description}} |
| Icon | String | Default scanning interval: Monthly. | {{Team.DisplayIcon}} |
| Display Name | String | {{Team.DisplayName}} | |
| Group | Group | Team connected to the Group | {{Team.GroupId}} |
| Group Name | String | {{Team.GroupIdName}} | |
| Is Archived | Boolean | Whether this team is in read-only mode | {{Team.IsArchived}} |
| Last Message Posted | DateTime | Date of last message or reply posted in channels Default scanning interval: Weekly. | {{Team.LastMessagePosted}} |
| Last scan update | DateTime | Shows when this object was last updated in a scan. If an object is found during a scan but no property has been changed this date will not change. | {{Team.LastModifiedTime}} |
| Risk Score | Int32 | Stores risk score | {{Team.RiskScore}} |
| Risk Score Update | DateTime | Stores risk score update | {{Team.RiskScoreLastUpdate}} |
| Risk Score Value | String | Stores risk score value like Low_Low | {{Team.RiskScoreValue}} |
| Created Date | DateTime | Timestamp at which the team was created | {{Team.TeamCreatedTime}} |
| Team Id | String | The team's unique identifier. | {{Team.TeamId}} |
| Team InternalId | String | A unique ID for the team that has been used in a few places such as the audit log/Office 365 Management Activity API. | {{Team.TeamInternalId}} |
| Visibility | String | The visibility of the group and team Allowed values: Private, Public. | {{Team.Visibility}} |
| Site | Site | Default scanning interval: Initial. | {{Team.Web}} |
| Site Display Name | String | {{Team.WebName}} | |
| Web Url | String | A hyperlink that will go to the team in the Microsoft Teams client. This is the URL that you get when you right-click a team in the Microsoft Teams client and select Get link to team. | {{Team.WebUrl}} |
Relations
| Relation | Service | Description |
|---|---|---|
| Agent Conversation | Copilot Studio | Conversations of users with agent |
| Group | Microsoft 365 | All Entra ID groups in your Tenant (Security groups, Microsoft 365 groups) |
| Sensitivity Label | Microsoft 365 | Sensitivity label of the Team |
| User | Microsoft 365 | Members of the Team |
| User | Microsoft 365 | Owners of the Team |
| Site Collection | SharePoint | SharePoint site collection of the Team |
| Site Collection | SharePoint | Site Collections connected to private channels of this Team |
| Site | SharePoint | All root site and subsites of a SharePoint site collection |
| Channel | Teams | All Channels of the Team |
| Channel | Teams | Channel shared with the team |
| App | Teams | Apps used in the Team |
| Tab | Teams | All tabs of your teams in your tenant |
| Usage | Teams | Usage report of the Team |
Segments
| Segment | Description |
|---|---|
| Archived Teams | All Teams that have been archived |
| New Teams | All Teams scanned the first time in the last 14 days |
| Private Teams | All Teams that are marked as private |
| Public Teams | All teams that are visible to everyone in the organization |
| Teams with Agents | Identifies Teams which had a Copilot agent conversation in the last 90 days |
Actions
- Archive Team
- Delete Team
- Change Title
- Add user to a Team
- Remove user from a Team
- Unarchive Team
Policies that check this object
| Policy | Severity | Description |
|---|---|---|
| Teams with a disabled owner account | Medium | Shows Teams that have at least one disabled owner account |
| Teams with private channels | Information | Shows Teams with private channels |
| Teams with many channels | Information | Shows Teams that have more than a certain number of channels (default 50) |
| Teams that use forbidden/misleading words in display name | Low | Shows Teams that use forbidden/misleading words in the team display name |
| Teams with only disabled owner accounts | Medium | Shows Teams where all owners have disabled accounts |
| Teams that reach the 200 channel limit | Medium | Shows Teams that have more than 180 channels |
| Teams with very few owners | High | Shows Teams which have 1 or no owner |
| Teams with very few users | Medium | Shows Teams which has 1 or 2 users |
| Teams with many users | High | Shows Teams with a number of users that exceeds a threshold (default 50 users) |
| Teams that reach the 100 owner limit | Medium | Shows Teams that have more than 80 owners |
| Inactive teams | Medium | Shows teams with no message posted in last 6 month and no SharePoint content modified in last 6 month |
| Teams with inactive external users | Information | Shows teams with external members that have not logged in for more than 6 month |
| New Teams | Information | Teams created in the last 14 days, eg. to send onboarding information |
| Public Teams | Information | Shows public teams |
| Team contains Copilot agent and external members | High | Detects Team where a Copilot agent is installed and external users are present, posing security concerns. |
| Teams with external users | Low | Shows all Teams that have external users/guests |
| Teams with less than 2 owners | Medium | Shows Teams teams with less than 2 owners |
| Teams with many owners | Low | Shows Teams that have more than a certain number of owners (default 10) |
| Teams without owners | Medium | Shows Teams teams without any owners |
| Teams that use prohibited words in the name or description | High | Shows teams that use a list of prohibited words in the name or description |