Microsoft Teams - Ownership & Access

Overview

Microsoft Teams provides a shared workspace for conversations, meetings, files and collaboration. Each Team should have clear ownership, current membership and appropriate access controls so the Team remains available, manageable and secure throughout its lifecycle.

This page provides guidance for managing Team owners, members, guests and access in Microsoft Teams.

 

Teams Roles & Responsibilities

Every Team should have clear ownership and current membership. Microsoft Teams uses three common roles:

RoleTypical Use
OwnerManages Team settings, adds and removes members, adds guests, changes Team settings, and handles administrative tasks.
MemberCollaborates in conversations and files and can upload and edit files.
GuestCollaborates in a Team when invited from outside CU Boulder. As external users, guests have fewer capabilities than Team members or owners.

Assign the role that matches the person's responsibilities, and use the lowest level of access necessary for the collaboration.

 

Team Owners

Management Responsibilities

Team owners are responsible for the overall administration and stewardship of a Team. Owners can manage Team settings, add and remove members, add guests, change Team settings, and handle administrative tasks.

Responsibilities include:

  • Maintaining at least two unique Team owners.
  • Managing Team membership and permissions.
  • Keeping Team ownership current as personnel change.
  • Reviewing membership to ensure only appropriate individuals have permissions.
  • Responding to inactive site certification requests.
  • Removing access for former employees, students, affiliates, guests or collaborators who no longer require it.
  • Keeping Team channels and files organized.
  • Following university policies for storing and sharing institutional information.
  • Archiving or deleting the Team if it is no longer needed.

Keeping Ownership Current

Every Microsoft Team should have at least two unique Team owners. Having multiple owners helps ensure the Team can continue to be managed if an owner changes roles, leaves the university, is unavailable, or transfers responsibility to another person.

Team ownership should be reviewed whenever:

  • A Team owner leaves the university.
  • A Team owner changes departments or job responsibilities.
  • Responsibility for the Team transfers to another individual.
  • A department reorganizes.
  • A project concludes or changes leadership.

Responding to Ownership Notifications

If a Team's associated SharePoint site has fewer than two owners, the Team owner may receive an automated SharePoint ownership notification prompting them to assign a second owner.

To do so:

  1. Open Microsoft Teams.
  2. Select the Team.
  3. Select More options (⋯) next to the Team name, then select Manage team.
  4. Open the Members tab.
  5. Under the Role column, change the user's role from Member to Owner.
  6. Verify that the Team now has at least two owners.

Adding a Team owner automatically grants that person owner permissions in the associated SharePoint site.

Do not add owners directly to the SharePoint site. For Teams-connected SharePoint sites, ownership should be managed through Microsoft Teams to keep permissions synchronized.

 

Team Members

Team owners should review membership regularly to ensure access remains appropriate, especially whenever:

  • Employees leave the university.
  • Students, affiliates, vendors or collaborators no longer need access.
  • Staff change roles or departments.
  • External collaborations conclude.
  • Projects are completed.
  • Sensitive or regulated information is added to the Team.
  • A Team changes purpose or ownership.

Remove members or guests who no longer require access.

 

Guests

Teams can be used to collaborate with people outside CU Boulder when there is a legitimate business, academic, research or operational need.

Unlike an OIT-provided SharePoint site, Teams is enabled for external sharing and guest collaboration by default. Team owners can add guests to a Team when guest access is available and appropriate, as for:

  • Research collaborations
  • Vendor or consultant collaboration
  • Joint projects with other universities
  • Grant-funded partnerships
  • Committees or working groups that include non-CU Boulder participants.

To learn more about guest access, see Microsoft Teams - Guest & External Users.