VendorScore · Team chat & meetings · Data-access posture
A plain-language answer from Microsoft Learn (Teams, Purview), Trust Center and licensing pages. Teams E2EE protects call and meeting media only, never chat, files or recordings.
Get the full 5-dimension PDF — join the waitlistEvidence dated 2026-10-07, public docs only, not legal advice.
Short answer
Yes, unless you enable E2EE: Microsoft's service can decrypt Teams chats, files, recordings and transcripts; E2EE covers only audio, video and screen sharing in one-to-one calls and E2EE meetings.
Scored configuration: Teams in a Microsoft 365 enterprise tenant with Purview Customer Key (multi-workload DEP), Customer Lockbox, and E2EE enabled for one-to-one VoIP calls and (Teams Premium) meetings that require it.
Default setup scores lower: Microsoft-managed keys, no Customer Lockbox, and call E2EE off. Scored separately; the Microsoft 365 score isn't reused.
Report confidence: Medium-high.
Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.
E2EE covers audio, video and screen sharing in one-to-one VoIP calls and Premium meetings set to require it; not chat, group calls, channel meetings, files, recordings or transcripts.
Evidence: Encryption in Teams, Teams end-to-end encryptionCustomer Key encrypts Teams chat, media messages and recordings in Teams storage with your Azure Key Vault root keys (Microsoft keeps an availability key).
Evidence: Customer Key overviewCustomer Lockbox covers Teams chats, files, meeting recordings and transcripts.
Evidence: Customer LockboxOur report flags these gaps in Microsoft Teams's public documentation:
Get the full 5-dimension PDF — join the waitlist
PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.
Yes, unless you enable E2EE: Microsoft's service can decrypt Teams chats, files, recordings and transcripts; E2EE covers only audio, video and screen sharing in one-to-one calls and E2EE meetings. VendorScore rates Microsoft Teams 70/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Teams in a Microsoft 365 enterprise tenant with Purview Customer Key (multi-workload DEP), Customer Lockbox, and E2EE enabled for one-to-one VoIP calls and (Teams Premium) meetings that require it.
Only for call and meeting media, and only when turned on. Teams E2EE covers audio, video and video-based screen sharing in one-to-one VoIP calls and in scheduled meetings set to require E2EE (the organizer needs Teams Premium). It never covers chat messages (including meeting chat in an E2EE meeting), group calls, channel meetings, shared files, recordings, transcripts or recap, and PSTN calls are excluded. Call E2EE is off by default; admins must allow it and both participants must turn it on. Everything else uses TLS 1.2+ in transit and BitLocker plus per-file encryption at rest, which Microsoft's service can decrypt. Customer Key can encrypt Teams chat, media messages and recordings in Teams storage with your Azure Key Vault root keys, while Microsoft keeps an availability key.
Not by default. Microsoft says engineers have no default access to cloud customer data and access is granted under oversight when needed. Customer Lockbox lets you approve such requests and covers Teams 1:1, group, channel and meeting chats, files posted to chats, meeting recordings and transcripts. Microsoft's own services still read stored content for search, transcription, DLP, retention, eDiscovery and Copilot.
Not foundation models. Microsoft's Copilot documentation says: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs, including those used by Microsoft Copilot." Teams chats and meetings are Graph content. Optional feedback may be used to improve Copilot but not to train foundation LLMs. Copilot, transcription and intelligent recap are unavailable in E2EE meetings.
VendorScore doesn't certify compliance; Microsoft publishes a DPA at https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA. Microsoft 365, including Teams, is an EU Data Boundary service (see the residency question below).
Microsoft publishes its Online Services Subprocessor List through the Service Trust Portal at https://servicetrust.microsoft.com/, a JavaScript app, so we couldn't read the list content. Microsoft says it publishes new subprocessors "at least six months in advance". Copilot features in Teams add AI subprocessors: OpenAI-operated models have been on by default since 2026-07-24, and Anthropic is off by default in the EU/EFTA/UK.
Yes. Teams stores data in your tenant's geography, including France, Germany, Italy, Norway, Poland, Sweden, Switzerland and the EMEA region (some in-country options are for new tenants only), and Microsoft 365 is an EU Data Boundary service. Microsoft's Teams data-location page was last updated 2024-02-29.
Every URL cited on this page. Score, key findings and FAQ: VendorScore report (microsoft-teams.md), evidence dated 2026-10-07.