Illustration of workplace chat and IT support risk

A growing social-engineering pattern: someone messages you on Microsoft Teams (or another chat tool) claiming to be IT support, then pushes a remote tool, a “security update,” or a login page.

For how Microsoft thinks about Teams security and compliance controls, start with Microsoft Learn: Teams security and compliance overview. Your company process still matters more than any single product setting.

Why chat scams work

  • Teams feels “internal,” so people drop their email skepticism
  • Urgency (“your account will be locked in 10 minutes”)
  • Callers or chatters use help-desk language and ticket numbers
  • Employees want to be helpful and resolve issues quickly

How to spot fake IT support

Red flags

  • Unsolicited chat from someone you do not normally work with
  • Pressure to install remote-control software immediately
  • Requests for your password, MFA codes, or “screen share so I can enter credentials”
  • Links to odd domains for “password reset” or “compliance training”
  • Slightly off display names (extra letters, look-alike characters)

What to do instead

  • Hang up / end the chat and contact IT through a known channel (help desk portal, published phone number, or your MSP)
  • Never read MFA codes aloud to anyone
  • Do not install remote tools from chat links unless your IT process already started a ticket with you
  • Report the chat to security so other staff can be warned

Policy tip for owners

Publish a one-page rule: IT will never ask for your password or MFA code in chat. Train reception and finance first—they are high-value targets.

Related official resources


If your team needs clearer remote support processes, SabatAge can help. Remote support · Contact us · (845) 475-8468.

Subscribe

SabatAge blog—IT news, tips, and stories for Hudson Valley businesses