Meeting policies in Teams are more complicated than they first appear. At a glance they look simple โ a set of switches that govern what users can do in meetings. In reality, settings interact in subtle ways, there's a not-always-obvious divide between organiser-level and attendee-level settings, and a handful of settings carry downstream consequences that don't become clear until the support tickets start piling up.
This walkthrough covers the settings that matter most for governance, spells out the interactions you need to grasp, and gives concrete recommendations drawn from what generally works well and what tends to cause grief.
How Meeting Policies Operate: Organiser vs Participant
Before we get into individual settings, there's a structural distinction worth understanding: meeting policies behave differently depending on whether a setting governs what an organiser can do or what an attendee can do.
When a meeting is created, the meeting policy belonging to the organiser sets certain aspects of the meeting environment โ including who can skip the lobby, whether recording is turned on, and whether transcription is available. The meeting policy of individual attendees governs what those attendees are able to do inside the meeting, no matter what the organiser has set.
In practice that means: to stop every user from recording meetings, you have to disable recording in the policy applied to attendees (specifically, the recording setting dictates whether the user can start a recording). To shape the lobby experience across an entire meeting, that's handled on the organiser side.
General Meeting Settings
Allow scheduling private meetings. Governs whether users can schedule one-on-one or private meetings. In most organisations this ought to be on. Restricting it only makes sense for particular groups such as frontline workers or kiosk users who have no need to schedule meetings on their own.
Allow Meet Now in channels and chats. Governs whether users can kick off an ad-hoc meeting straight from a channel or chat. Handy for collaboration; it's generally best left enabled for standard users.
Allow channel meeting scheduling. Governs whether users can schedule meetings inside channels. This differs from scheduling private meetings; channel meetings show up on the channel calendar and are visible to every channel member.
Audio and Video Settings
Allow IP video. This is as much a bandwidth setting as a governance one. Turning off IP video disables the camera for every meeting the user joins or organises. It's handy for easing bandwidth on constrained network segments โ some organisations switch off video for frontline workers on cellular or shaky Wi-Fi.
Mode for IP audio. Sets whether users can use VoIP audio in meetings, and if so, whether it can be incoming, outgoing, or both. The default (Two-way audio enabled) suits most users.
Allow NDI streaming. Network Device Interface streaming lets a Teams meeting feed be broadcast to third-party streaming software. It's off by default and should stay off unless you have a specific broadcasting need.
Recording and Transcription
This is the section that prompts the most governance questions.
Cloud recording. This setting governs whether a user can start a recording in a meeting they're attending or organising. Disable it for a user and they can't begin a recording in any meeting they take part in, whether or not the organiser has recording turned on.
The governance question is who ought to be allowed to record. For most enterprise rollouts, the answer is "meeting organisers and co-presenters, not just any attendee." You get there with a mix of policy and meeting options. The meeting policy setting switches on the capability; the meeting organiser can then tighten it per-meeting through meeting options.
Transcription. Governs whether a user can start live transcription in a meeting. Transcription produces a real-time text record of spoken audio. It's a compliance-sensitive feature: in certain regulated industries, transcription carries legal implications for data retention. Understand your requirements before you enable it widely.
Store recordings outside of your country or region. Teams recordings are kept in the personal file store or the file service belonging to the meeting organiser. This setting governs whether that storage may sit in a datacentre outside the organiser's home country. For organisations bound by data residency requirements, leave it off.
Auto-recording. When switched on, meetings begin recording automatically as they start. This fits certain compliance scenarios โ some financial services firms, for example, are obliged to record every client call. For general enterprise use, auto-recording is intrusive and isn't recommended.
Recording governance tip
For most enterprises: switch on cloud recording for organisers and co-presenters, turn it off for anonymous attendees, and weigh up whether any user group genuinely needs auto-recording. Keep recordings in the organiser's the personal file store with a retention policy applied through the compliance portal.
Lobby Settings
The lobby is the waiting room for Teams meetings. When someone joins a meeting and lands in the lobby, they stay there until an organiser or presenter lets them in. Lobby settings are among the most consequential for meeting security.
Automatically admit people. This organiser-side setting decides who skips the lobby by default for meetings the organiser schedules. The choices are: Everyone, People in my organisation, People in my organisation and guests, and People in my organisation, trusted organisations, and guests.
The main governance point here: set this to "Everyone" and anyone holding the meeting link โ including external users who were forwarded the invite without the organiser realising โ bypasses the lobby automatically. For most enterprise meetings, "People in my organisation and guests" is the sensible default. Organisers can override it per meeting when needed.
Dial-in bypass lobby. Governs whether users joining by phone (PSTN dial-in) skip the lobby. Leave it off unless you have a specific reason to admit phone users automatically.
Content Sharing
Screen sharing mode. Governs whether users can share their whole screen, a single application window, or nothing at all. "Entire screen" is the most permissive; "Single application" cuts the chance of accidentally exposing something sensitive. For high-security or regulated-industry users, single application sharing lowers the risk of data leakage.
Allow participant to give or request control. While a user is sharing their screen, this setting decides whether they can hand keyboard/mouse control to another attendee. Switch it off for users in sensitive roles โ passing control of a screen to an external attendee is a serious security risk.
Allow external participants to give or request control. This is the external-user counterpart of the above. It defaults to on in the Global policy. For most enterprises it should be off.
PowerPoint Live. Lets presenters share PowerPoint files directly through Teams, with navigation controls shown to attendees. This is a functionality setting rather than a security concern as a rule.
Whiteboard. Governs whether users can use the whiteboard app feature in meetings. Whiteboard data lives in the file service and is subject to the usual the file service retention and compliance policies.
Participant and Guest Management
Let anonymous people start a meeting. When off, a meeting can't begin until an authenticated user (someone from your tenant) joins. This stops anonymous attendees from holding a private meeting in a room set up with your tenant's conferencing bridge while none of your tenant users are present. Keep it off.
Allow meeting chat. Governs whether chat is available during meetings. The options are: on, off, and in-meeting only (chat works during the meeting but not before or after). For compliance scenarios where meeting chat leaves a persistent record, "in-meeting only" keeps the chat thread from being reachable afterward.
Allow reactions. Emoji reactions in meetings. Usually a non-issue for governance, but handy to know it can be configured.
Recommended Baseline Configurations
For a standard enterprise rollout, a baseline Global policy might look something like this:
- Cloud recording: Enabled (for organisers)
- Transcription: Enabled (review compliance requirements first)
- Automatically admit people: People in my organisation and guests
- Anonymous bypass lobby: Off
- External participant control: Off
- Let anonymous people start a meeting: Off
- Screen sharing mode: Entire screen (adjust for high-security users)
Layer on a restricted policy for frontline workers or regulated users that switches off recording, transcription, and external control features. Add an elevated policy for executives or broadcast organisers that unlocks advanced features such as live events or NDI streaming.
The precise configuration hinges on your industry, your compliance obligations, and the way your users genuinely work. But the framework โ a sensible Global policy, a tighter tier, and an elevated tier โ handles most scenarios without spawning an unmanageable sprawl of policy variants.