Teams Securlet Changes
search cancel

Teams Securlet Changes

book

Article ID: 389450

calendar_today

Updated On:

Products

CASB Advanced Threat Protection CASB Audit CASB Gateway CASB Gateway Advanced CASB Security Advanced CASB Security Advanced IAAS CASB Security Premium CASB Security Premium IAAS CASB Security Standard CASB Securlet IAAS CASB Securlet SAAS CASB Securlet SAAS With DLP-CDS

Issue/Introduction

Changes are coming to CASB's M365 securlet (API) support for Teams.

Currently, Teams is supported through the M365 securlet. In order to align with Microsoft’s licensing requirements and to avoid API throttling Symantec CloudSOC CASB will support MS Teams using a custom OAuth application that will be owned by the customer going forward. This app will be installed in the Azure environment owned by the customer. 

Resolution

The Microsoft Teams Content Inspection techdoc will guide you through the creation of the Azure application for CloudSOC as well as the configuration of the Client ID, Private Key and the Thumbprint in CloudSOC. You are not required to reactivate the M365 securlet post OAuth application configuration.

Existing M365 securlet implementation with the Teams integration will need to perform these steps in order to maintain protection.

Additional Information

Symantec CloudSOC CASB can inspect sensitive content and malware in Microsoft M365 (previously known as O365) apps like OneDrive, Sharepoint, Mail, and Teams. For Microsoft Teams, this is possible through Microsoft’s Teams API described here

For applications performing a security or compliance function on Microsoft Teams using Microsoft's API, Microsoft recommends using model A outlined here 
To be able to use the API, Microsoft requires one of the following licenses:

Microsoft 365 E5/A5/G5
Microsoft 365 E5/A5/F5/G5 Compliance [add-on]
Microsoft 365 E5/A5/F5/G5 Information Protection and Governance [add-on]
Microsoft 365 F5 Security & Compliance [add-on]