Managing Microsoft Teams across an NHS organisation is not the same as managing it in a corporate office. Your users include clinicians who need real-time collaboration, porters who work on wards with patchy network coverage, and administrative staff handling sensitive patient data. The Teams Admin Centre is your command post, but most NHS admins only use about 40% of its features, leaving security gaps and operational friction.
This guide covers the five Teams Admin Centre settings that matter most in NHS environments, how to lock them down without breaking workflow, and how to stay compliant with NHS Digital's data governance requirements.
The first thing most NHS Teams admins do wrong is apply the same permissions to everyone. A surgeon doesn't need the same channel creation rights as a secretary, and a junior doctor doesn't need access to workforce planning teams.
In the Teams Admin Centre, go to Teams > Teams policies. Create separate policies for different user groups:
Assign these via Azure AD group membership, not individual users. Use dynamic groups based on job role codes in your HR system. This means when someone moves from being a registrar to a consultant, their permissions update automatically without manual intervention.
Practical tip: In the Teams Admin Centre, go to Messaging policies > Edit. Turn on "Read receipts" for clinical teams (surgeons want to know their urgent message was seen), but turn it off for administrative channels handling HR or payroll data.
This is where most NHS Teams implementations fail compliance audits. Teams chat and files are not permanent unless you tell Teams to keep them.
Go to Data lifecycle management > Retention policies in the Microsoft 365 Compliance Centre (linked from Teams Admin Centre). Create a policy that:
Link this to your patient data lifecycle. If a patient leaves your care, chat relating to that patient should be archived within your retention window, not deleted immediately. This isn't just compliance: it's professional defence.
Enable eDiscovery in the Compliance Centre. Your legal and audit teams need to be able to search Teams messages if there's ever a complaint or formal investigation. Make sure they have read-only access to the eDiscovery tool, not delete rights.
Common mistake: Setting retention too short. NHS Trusts that delete Teams history after 30 days often face complaints from clinicians who need to reference old discussions during patient reviews, and from auditors checking decision trails. Seven years is safer.
Patients' names, test results, and appointment slots should not end up in a guest's personal OneDrive.
In Teams Admin Centre > Teams > Teams settings > Guest access, turn off:
Then go to Org-wide settings > File sharing and turn on "Restrict file sharing" to "Only people in your organisation". Allow Teams channel file sharing, but not external link sharing unless the user explicitly changes permissions per file.
For shared channels (new in Teams 2024/2025), use these only for verified partner organisations like council social services teams or external radiology services. Require approval in Azure AD before external user access is granted.
Real example: A busy A&E department once shared a Teams channel with a logistics supplier to coordinate PPE delivery. The channel included room layouts and staffing rotas. These files were accessible to anyone with the public link. After an audit flagged this, it took two weeks to remove all external access. You can prevent this by disallowing public link creation in the first place.
Most NHS admins use Teams Admin Centre only when something breaks. Analytics should be your early warning system.
Go to Analytics & reports > Teams usage. Run this report monthly:
Export this data to Excel and share with your governance team. Low adoption on clinical teams might mean clinicians don't trust it yet (training or change management issue). High adoption with low chat might mean they're using Teams for file storage only, which wastes storage and compliance resources.
Set up alerts in the Security & Compliance Centre for suspicious patterns: someone downloading 500+ files in one session, or a user in India accessing a radiology team (legitimate if you have that staff, but worth checking).
This one setting stops 99% of account takeovers in NHS environments.
Go to Azure AD > Security > Conditional Access. Create a policy:
Set this to "Report-only" for one week to see who's affected. Then switch to "Enable". A small number of users will complain about MFA fatigue. Respond with this: "We've had three NHS Trusts breached in the last two years. Both started with a stolen password. MFA adds 10 seconds per login and stops that."
Most users accept it within a week. Authentication apps (Microsoft Authenticator) are faster than SMS codes and work offline.
If you're new to Teams administration or managing it across an NHS network for the first time, the learning curve is real. The Microsoft 365 Administrator Programme at SmoothOps 365 includes two full modules on Teams configuration, security policies, and compliance in healthcare settings. You'll work through live scenarios like the ones above with a trainer who has actually implemented Teams in a hospital environment. The course is three months, weekends only, and includes hands-on labs that match real NHS infrastructure. Check the programme details and join the waitlist.
A Teams policy controls what users can do right now (e.g. create channels, add guests, record meetings). A retention policy controls what happens to old content automatically (e.g. delete chat after 90 days, keep files for 7 years). Both are essential in NHS Teams, but they solve different problems.
Yes. NHS Digital expects you to be able to retrieve and search Teams content if an audit or complaint investigation asks for it. Setting it up before you need it takes one afternoon. Setting it up during an investigation is impossible and looks like cover-up. Have it ready.
Not directly. Teams is a chat and collaboration tool, not a medical imaging repository. Patient images should live in your PACS system or secure cloud storage with full audit trails. You can link to images from Teams, but don't store the originals there. If you do, you'll lose imaging audit compliance and create retention nightmares.
At least quarterly, and after any security incident in healthcare news. After the Change Healthcare breach in 2024, many NHS Trusts tightened their Teams guest access policies within weeks. Create a calendar reminder and check adoption metrics, audit findings, and Microsoft security updates each cycle.
Teams chats and channel messages are kept indefinitely by default. This sounds good until an audit asks for chat history from 2019 and you have to hand over thousands of conversations, many irrelevant. It's also expensive: every message counts toward your tenant's storage. Set a retention policy and let Microsoft delete old content automatically.
SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.