Microsoft is taking a major step toward strengthening the security of corporate communications, announcing that it will automatically enable basic messaging protection in Microsoft Teams features starting January 12 , 2026. The change applies to organizations using the default settings and is part of a broader “ secure-by-default ” strategy .

Risk reduction for organizations with basic setups
According to a related update, Microsoft aims to reduce the attack surface for companies that have not proceeded with manual security “hardening”. Many organizations rely on default settings due to limited resources or lack of expertise, which makes them more vulnerable to modern threats.
The changes are described in detail in notifications MC1148540, MC1148539, and MC1147984 and concern the "Message Security" section in the Teams Admin Center.
See also: Microsoft Teams: Administrators will block external users from Defender Portal
The three functions that are activated automatically
For tenants who have not adjusted their settings, Microsoft will enable three critical security controls.
The first is File Type Protection High-Risk, which blocks file extensions that are often used to spread malware, significantly reducing the chance of malicious code being executed through internal communication.
The second feature is protection against malicious URLs , with Teams checking links shared in messages in real time . Suspicious or known phishing sites are immediately flagged, warning users before they interact with dangerous content
See also: Vishing attack abuses Teams & QuickAssist to deploy .NET malware
The third is the ability to report false positive detections, allowing end users to notify Microsoft when legitimate content is being blocked in error. This feedback helps improve detection algorithms.

Who is affected and who is not?
The automatic rollout only applies to organizations that remain on the default settings. Those who have already customized and saved their message security policies will not see any changes, as their existing settings will override the new defaults.
This gives IT administrators the ability to maintain control, as long as they have invested in personalized policies.
What will change in users' everyday lives?
After enabling the new settings, end users may notice more frequent warnings on messages containing suspicious links. At the same time, certain file types may be rejected from being sent altogether.
See also: Guest access to Teams can remove Defender protection
While these measures may initially be seen as annoying, Microsoft claims that the false positive reporting feature ensures that legitimate business flows are not permanently hindered.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What managers need to do before 2026
Administrators are encouraged to review their settings early by navigating to: Teams admin center > Messaging > Messaging settings > Messaging safety. Those who wish to opt out of the new defaults will need to manually save their settings before January 12, 2026.
At the same time, it is recommended to update internal documentation, as well as prepare support teams to deal with relevant user requests.
Why Microsoft insists on tightening
Collaboration platforms have become an attractive target for cybercriminals, who use them for lateral movement and malware propagation. By universally enabling basic protections, Microsoft is attempting to stem this trend and put security at the heart of digital collaboration.
The move to “secure by default” is not just a technical upgrade; it is a clear message that security should not be optional.
