The behaviours Teams users can exercise in chats and channels are governed by messaging policies: sending GIFs, editing or removing their own messages, using stickers, issuing urgent notifications, and so on. Messaging policies carry less complexity than meeting policies — yet they still deserve deliberate configuration, particularly in regulated industries where editing and deleting messages raises compliance questions.
The Scope of Messaging Policies
Settings within a messaging policy group into several broad categories:
Editing and removing messages. The Owners can delete sent messages toggle determines whether owners may remove messages that other people posted in channels. Users can delete sent messages determines whether the original sender can take their own messages down. Users can edit sent messages determines whether someone can return to and change what they already sent. On the compliance side, if regulations impose message immutability on you — some financial services rules do — both editing and deletion must be switched off for end users. Keep in mind that compliance retention policies in the compliance portal keep the original version of every message no matter what edits or deletions occur; turning these settings off simply makes the position easier to present to regulators.
Read receipts. With this enabled, private chats show read receipts to users. It is a user-experience knob far more than a governance lever. Certain users want it badly; others feel it adds social pressure they don't need. By default, each user decides their own read-receipt visibility. Where consistency matters more, policy can take that choice away.
Chat. A master on/off switch for chat itself. Switching it off suits kiosk setups or frontline workers for whom chat plays no part in the workflow. Bear in mind that turning chat off also strips the ability to post in channel conversations, so apply it with care.
Giphy, stickers and memes. The lighthearted part of the policy. Governance teams rarely spend long here, although heavily regulated sectors such as financial services and healthcare switch these off for everybody as part of a wider effort to minimise informal communication that ends up captured in compliance archives. Where that is not a concern, the defaults are fine.
URL previews. Determines whether links posted in messages expand into rich previews showing a title, image and description. As much as anything else, this is a bandwidth setting: switching previews off cuts data consumption in low-bandwidth environments. It occasionally matters for security too, since previews let users see what an external URL holds without clicking through to it.
Translate messages. Lets users translate incoming messages inline into their preferred language. Purely a user-experience capability — leave it enabled unless there is a specific reason not to.
Immersive reader. An accessibility feature for reading messages. There is no good reason to turn it off.
Priority notifications. Urgent messages that repeat audio alerts until the recipient acknowledges them. Valuable in critical scenarios and disruptive when overused. Enabling them for managers and supervisors, while leaving them off for frontline workers without a specific use case, is a sensible split.
Audio messages. Sets whether users may record and send voice messages in chat. Most enterprise configurations leave this off. Some organisations switch it on for particular cases such as field workers or accessibility; others prefer keeping all chat communication text-based for archiving reasons.
Where Edit and Delete Settings Meet Compliance
This is the point at which messaging policies overlap most directly with compliance requirements.
When a user edits a Teams message, the original version survives in the compliance copy — the version held in the mail service mailboxes for compliance purposes, separate from the one displayed to users. Deleting a message leaves the compliance copy intact as well. Your compliance records therefore remain complete even when users hold edit and delete permissions.
Even so, disabling edit and delete at the policy level brings two practical advantages. First, compliance audits become simpler — nobody has to ask whether a user altered a message after the fact. Second, the position is easier to convey to auditors and regulators: "Users cannot edit or delete messages" is a clean statement, whereas "Users can edit messages but we preserve compliance copies in Exchange" demands more explanation.
For most organisations the workable approach is this: turn edit and delete off for users in regulated roles (insurance adjusters, healthcare professionals, financial advisors), and keep them enabled for standard employees, where the compliance case is weaker.
External Chat: The Toggle People Overlook
Messaging policies also carry a setting for external chat — whether users may chat with people outside your organisation through Teams (Teams Connect, or federated chat). This setting operates alongside the external access settings found under Org-wide settings.
The org-wide external access setting decides whether external chat is technically possible at all, while the messaging policy setting decides whether a particular user can start or receive external chats. External chat works only when both allow it. A frequent misconfiguration: external chat enabled in the messaging policies while external access is left disabled in Org-wide settings, or the other way round.
How to Structure Your Messaging Policies
Two or three messaging policies will be sufficient for most organisations:
- Global (standard): Edit and delete on; URL previews on; Giphy and stickers on. Fits the majority of employees.
- Restricted (compliance): Edit and delete disabled; audio messages disabled; Giphy and stickers disabled. Intended for regulated roles.
- Frontline: Chat switched off or capabilities kept minimal. Suits kiosk and shift-worker scenarios.
- Supervisors: Audio messages and priority notifications enabled, with Giphy left off. Intended for on-call leads who need an interrupt path without exposing stickers to the entire tenant.
- Contractors: The same chat surface as employees, but with external chat and URL previews switched off, so a six-month contractor cannot mint link cards or start federated threads.
Assignment works the same as for every policy type: use group policy assignment against the identity service groups that mirror your HR job categories. A financial advisor's messaging policy should match that of every other financial advisor in the organisation — consistency is what keeps audits manageable.
A Word on Compliance and Message Retention
What messaging policies control is what users can do with messages inside the Teams interface. They say nothing about how long messages are retained, or about who can search for them in eDiscovery — the compliance portal's retention policies and eDiscovery handle those separately. The two layers of control are complementary rather than overlapping, so don't confuse them.
What Occurs When a User Falls Under Two Messaging Policies
Group assignment never blends settings. Teams applies a single messaging policy per user, selected by the rank of the group policy assignment, in the same way calling and meeting policies resolve. A claims handler who also sits in an "all staff" group gets no mixture of the restricted and global profiles — the higher-ranked assignment wins every toggle in the policy, including the ones the administrator assumed were inherited from Global.
This all-or-nothing behaviour is easy to miss in a tenant of roughly 1,800 people, a common size for a regional insurer. The compliance group ranks 1 and holds every licensed adjuster. A later project adds those same accounts to a collaboration group ranked 3 so they can take part in a cross-team channel. Chat behaviour stays the same, because rank 1 still applies. The surprise comes when a role change leads someone to remove the adjuster from the compliance group and the collaboration group is forgotten. The user drops to rank 3 — or to Global, if that group carries no messaging assignment at all — and edit/delete flips back on overnight.
Verify the effective policy on the user record in the Teams admin center, both before and after any group membership change touching a regulated role. In PowerShell that is Get-CsEffectivePolicy, or the per-user policy readout from Get-CsOnlineUser. Either reveals the messaging policy actually in force — the only name worth comparing against the written standard.
Policy packages muddy the picture only when a package is assigned directly to the user on top of a group assignment, because direct assignment outranks group assignment. A package applied during onboarding "to save time" will silently beat the compliance group until that direct assignment is cleared. Use packages as a starting template for a cohort, then move the cohort to group assignment and remove the direct policy so the rank stays predictable.
Propagation is not immediate. A rank change can take several hours to reach a mobile client that has been backgrounded, and the desktop client may keep showing the old toggle set until the next sign-in. Where a control is being tightened after an audit finding, don't close the finding on the strength of the admin-center screenshot alone — spot-check a live user session the following morning.
Joining a quarterly export of effective messaging policies to the HR cost-centre code catches the adjuster who changed desks and lost the restricted profile. Keep the restricted policy's display name stable — renaming it mid-audit forces every evidence screenshot to be recaptured. URL preview acts as a data-egress control as much as a bandwidth one: the preview fetch reaches the destination host from the vendor's service, which some security teams read as an implicit outbound request. Audio messages land in the same compliance store as text, yet reviewers often skip them, because the export shows a media attachment rather than a sentence. Where a role is barred from editing text, decide explicitly whether voice notes are in or out. Frontline chat-off is fragile if the same account is also used at a shared desk with a full client — confirm the licence and the policy together, not the policy alone. Record the rank order beside the policy matrix; a matrix without ranks is not operable by the next administrator.