Our institution needs to shared PII with Georgia Student Finance Comission. This is their practice, not mine. I would choose another means to share the PII. Their position is many other Georgia colleges do this (Share PII via Microsoft Teams Posts). Posts encrypted in transit and at rest, but are not E2EE. Microsoft could decrypt the Posts. Therefore it seems reasonable that hackers could also decrypt the Posts.
My ultimate question is, are Teams Posts GLBA compliant? If not, is there a way to make Teams Posts compliant with GLBA?