Microsoft Teams is gradually strengthening security features its, adding more control to organization administrators. One of the most significant changes concerns the files that can be sent through chats and channels, as IT managers will soon be able to customize the list of extensions that are considered high-risk.

The new feature is an extension of Weaponizable File Protection, a security mechanism built into Teams designed to detect and block attachments that can be used by attackers as malware carriers.
Customize the list of blocked files
To date, administrators have not been able to modify the list of file types excluded from this protection. This is set to change as Microsoft develops a new layer of administrative control.
See also: Microsoft Teams: New shield against QR code phishing
According to a related entry in the roadmap , administrators will be able to choose which file extensions to block, depending on the needs and security policy of each organization. At the same time, those who do not wish to make changes will be able to continue to use the default list that Microsoft recommends.
The availability of this feature is expected to begin in November 2026, while the goal is to be offered in Teams for Android, iOS, Windows, macOS and web.
Why attachment control matters
Files have long been one of the primary means used by cybercriminals to bypass an organization's defenses. A document, an executable file, or even a compressed archive can be used as the initial stage of an attack, especially when accompanied by a convincing social engineering message.
The problem becomes even more complex on collaboration platforms like Teams, where employees exchange files and messages with colleagues, partners, and external users every day.
The ability to customize the list of blocked extensions allows businesses to implement policies that best suit their environment. An organization with increased security requirements can, for example, choose stricter restrictions, while a business with specific business needs can configure its policy differently.
New measures against external users
Microsoft is not restricting changes to attachments. Starting in December, administrators will be able to block external users, adding another layer of protection against social engineering attacks.
This development is particularly significant as corporate communication platforms are now a frequent target of attacks that seek to exploit employee trust. Malicious users can pose as colleagues or other trusted contacts and attempt to lead a victim to phishing pages, malicious files or other traps.
See also: TWINLOOT: SharePoint and Teams Abused to Steal Credentials

Protection for QR codes too
Teams is also getting additional defenses against phishing and scams that exploit QR codes. Microsoft has announced that QR codes sent by external senders will be displayed in a way that reduces the likelihood of direct user interaction.
The logic behind the measure is simple: a QR code can act as a link to a malicious website without the user easily seeing its true destination. This protection attempts to add an extra barrier before visiting a suspicious address.
Report suspicious invitations through Teams
Another measure expected to be available from November concerns guest invitations. Users will be able to report invitations they consider suspicious directly from Teams.
This way, security teams can gain insight into potential phishing campaigns and take action to block them. This approach moves part of the defense closer to the employee, who is often the first to notice that something doesn't look right.
Automatically block external bots in meetings
In the same context, a new protection policy for Teams meetings is also included. Administrators can configure the automatic blocking of identified external bots from meetings, thus limiting unwanted or potentially malicious automated presence in corporate meetings.
These successive changes show that security on collaboration platforms is no longer limited to protection against traditional malicious files. Protection extends to external users, phishing, QR codes, bots and social engineering, i.e. multiple points from which an attack can be launched.
See also: Microsoft Teams: Fake IT support calls lead to EtherRAT distribution

Teams is getting stricter
The new Weaponizable File Protection customization capability is another step towards a more flexible enterprise security model. Instead of all organizations following exactly the same policy, administrators gain more leeway to tailor defenses to their actual needs.
For businesses, however, technology alone is not enough. Effective protection requires a combination of proper settings, up-to-date security systems, and employee training so that suspicious files, invitations, and messages are treated with due care.
With the new features, Microsoft is attempting to transform Teams from a simple communication tool into an environment where security is an integral part of daily collaboration.
source: www.bleepingcomputer.com
