Qutzl LLC LogoQutzl Insights
3 min read

Teams lobby settings for external meetings

Who waits in the lobby, who walks straight in, and how to keep client calls from turning into open doors — a practical Teams policy pass for SMBs.

Teams meetings are the front door to your company for vendors, clients, and random calendar links forwarded around the office. The lobby is the bouncer. Leave it on default settings long enough and you will eventually admit someone who should have waited — or lock out a paying client while an internal standup runs long.

External meeting policy is a business decision dressed up as an admin toggle. Legal, sales, and ops should agree on the posture; IT implements it.

Default posture most SMBs should consider

For organizations that regularly meet with people outside the tenant:

  • People in my org bypass the lobby — staff should not wait on each other
  • External participants wait in the lobby — always, unless you have a narrow exception
  • Only organizers and co-organizers can admit from lobby — not “anyone in the meeting,” which invites well-meaning employees to let strangers in because the name looked familiar

“Everyone waits in lobby” sounds secure and feels terrible for internal culture. Split the policy: internals trusted, externals verified.

When to tighten further

Turn the dial stricter if:

  • Meetings discuss financial, health, or legal data under confidentiality expectations
  • You have had Zoom-bombing or uninvited guests in the past
  • Recordings are automatic and could capture sensitive conversation if the wrong person joins

Options include:

  • Only invited users bypass lobby (reduces link-forward sprawl)
  • Disable anonymous join unless a specific public webinar requires it
  • Restrict who can present — external presenters only when the organizer promotes them

When to loosen (carefully)

Some client-facing teams want frictionless join for recurring partners. That is fine if:

  • The meeting link is not posted publicly
  • Organizers know they are responsible for the guest list
  • You accept the tradeoff and document it

“Loosen for sales” without training is how a forwarded invite becomes a public URL on a proposal PDF.

Meeting policies vs org-wide defaults

Teams admin center lets you set meeting policies and assign them to users or groups. Common pattern:

  • Standard staff — external lobby, internal bypass
  • Executives / board — invited-only bypass, stricter presenter controls
  • Webinar organizers — separate policy if they run large external events (often with registration tools outside Teams)

One global policy for 200 different meeting styles creates either insecurity or help-desk tickets. Group policies beat heroic per-meeting settings nobody remembers.

User habits that matter more than sliders

Policy cannot fix:

  • Organizers clicking Admit all because they are late to their own meeting
  • Sharing “anyone with the link” invites when specific people would do
  • Leaving meet now links in permanent email footers

A five-minute onboarding note for client-facing roles beats twelve new admin policies. Tell people: check the lobby, verify unfamiliar names, do not admit “Guest” twice because you assume it is the same person.

Bottom line

For most SMBs, externals wait in the lobby, internals do not, and only organizers admit guests — with stricter policies for high-sensitivity teams. Match meeting policies to how sales, legal, and ops actually work, train organizers on admit discipline, and review settings after any uninvited join incident.