Is It Safe to Share Passwords in Microsoft Teams?

Short answer: a password sent in a Teams chat is protected in transit, but it is then kept — in the chat itself and in compliance copies your organisation's administrators can search. It is a poor place for a credential that should exist for minutes.

Where a Teams message actually goes

Microsoft documents that copies of Teams chat messages are stored in a hidden folder in the Exchange Online mailbox of every participant; channel messages are stored in the mailbox of the team's group. These copies exist so that Microsoft Purview can apply retention policies and run eDiscovery and content searches across them.

  • Retention. If your organisation has a retention policy for Teams — common in regulated industries — a message can be preserved for years, even after the sender deletes it from the chat.
  • eDiscovery and content search. Compliance administrators can search those copies across the organisation, including for words like "password".
  • Every participant's account. In a group chat, the password now lives in every member's mailbox and is exposed if any one of their accounts is compromised.
  • Guests and external chats. When you chat with someone outside your organisation, their organisation's systems and policies apply to their copy.

What this means in practice

The risk is not that Microsoft reads your chat. It is that a credential which should have a lifetime of minutes acquires a lifetime of years, in several places, governed by policies set by people you may never meet. When an account is phished, an attacker searching the mailbox and chat history finds it immediately.

A safer way to send a password in Teams

  1. Create a one-time link at oncepad.com: your browser encrypts the password before anything is uploaded.
  2. Post the link in the Teams chat. It contains no key, so the retained copies hold nothing readable, and Teams' link preview cannot reveal or destroy it.
  3. Give the seven-word passphrase on a different channel — say it on the Teams call, or send it by text.
  4. The recipient reveals it once; it is deleted from the server at that moment, or after 24 hours if unopened.

For administrators

Data-loss-prevention policies can flag credentials posted in chats, and it is worth searching existing Teams content for passwords to rotate. Giving people a sanctioned, simple way to hand over a secret does more than a policy forbidding it.

Source: Microsoft Learn, searching Teams content in eDiscovery and retention policies for Teams. Behaviour depends on your tenant's licences and policies.