Attackers can bypass MDO protections in Teams for guest users using an unprotected tenant. The protections used in Teams messages are determined by the host tenant; therefore, if a guest account is invited to a Teams chat in an unprotected tenant, then an attacker can send them malicious URLs and attachments that are not scanned by MDO.