Skip to content
Independent IT security review - Canada Français
Secure M365 Scope a review
Contents

Independent IT security review

Teams Phone runs on the identity backbone you already review.

A calling identity is a Microsoft 365 account like any other. This review extends the same evidence-based method to calling policy, emergency-location records, and who administers the phone system.

Recognize Teams Phone as an identity-backed system, not a separate phone line.

Whether calling runs through Calling Plan, Direct Routing, or Operator Connect, every calling identity is still a Microsoft 365 account. The Conditional Access and MFA policy already governing email and chat governs calls too-if it is actually applied there.

Calling-path identity dependency

Confirm how the chosen calling path-Calling Plan, Direct Routing, or Operator Connect-ties back to the same Entra ID accounts used everywhere else.

Conditional Access applied to calling

Check whether sign-in policies actually reach the Teams Phone experience, or whether a gap lets calling behave differently from chat and mail.

Guest and external calling access

Review what calling capability, if any, external or guest accounts have, since calling features are not always covered by the same guest-access assumptions as file sharing.

Confirm emergency-location records are accurate, not just configured.

Dynamic emergency calling depends on network-site and location records staying current as people move, work remotely, or change offices. A stale record is a life-safety gap, not a paperwork detail.

Network site and location mapping

Confirm that network locations are actually mapped to civic addresses, and that the mapping was updated after the last office change.

Remote and hybrid coverage

Check whether remote workers have a way to provide or confirm their emergency location, rather than defaulting to a head-office address that is wrong for them.

Emergency-call notification routing

Confirm who is actually notified when an emergency call is placed, and that the notification path has been tested rather than assumed to work.

Check who administers calling policy and phone numbers.

Calling-policy roles, number assignment, and voicemail or call-recording access are privileged actions. They deserve the same ownership scrutiny as any other administrative role on the tenant.

Calling-policy admin roles

Confirm who can assign or change calling policy, and whether that role is separated from everyday Teams administration.

Number and assignment change control

Review how phone numbers are assigned, reassigned, and retired, since an unmanaged number can end up reaching the wrong person.

Voicemail and recording access

Confirm who can access voicemail transcripts and call recordings where enabled, and how long that data is retained.

Separate a security review from a telephony deployment project.

This review checks the access and security posture of a Teams Phone estate that is already deployed. It does not design a dial plan, port phone numbers, or select a PSTN carrier.

What is in scope

Identity-backed access, Conditional Access coverage, emergency-location accuracy, and administrative ownership of the calling system.

What is out of scope

Carrier selection, number porting, call quality or network performance-these belong to a telephony implementation project, not this review.

Where an implementer’s work begins

Hand findings about policy, ownership, and emergency records to whoever operates the phone system, separately from any deployment or carrier decision.

Next step

Define the review before sharing evidence.

Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.