ZeroHour
BleepingComputerpublished ()ingested Sergiu Gatlan

Microsoft Teams will let admins block custom file extensions

infoToolsimportance 22
AI summary · glm-5.3-flash

Microsoft Teams will let admins customize blocked file extensions in Weaponizable File Protection, rolling out globally from November 2026 across all platforms.

Microsoft is expanding admin controls for the Weaponizable File Protection feature in Teams, letting administrators customize the list of blocked high-risk file extensions instead of relying only on Microsoft's recommended default list. The capability is in development per the Microsoft 365 roadmap, with rollout beginning November 2026 across Android, desktop, iOS, macOS, and web for standard multi-tenant cloud environments. Microsoft also announced complementary Teams defenses: blocking external users via the Defender portal starting December, blurring QR codes from external senders, reporting suspicious guest invitations from November, and automatically blocking external bots from meetings.

  • Admins can customize blocked file types in Teams or keep Microsoft's recommended default list
  • Feature is in development with rollout starting November 2026 on all Teams platforms
  • December update will let admins block external users via the Defender portal
  • Other additions: external QR code blurring, guest invitation reporting, and external bot blocking
Full article351 words · extracted from bleepingcomputer.com · click to collapse

Microsoft Teams

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with malware and security threats to meet their company's security requirements.

This will come as an update to Weaponizable File Protection, a built-in Teams messaging safety feature that scans conversations and blocks chat or channel messages with dangerous, high-risk file attachments.

As detailed in a new Microsoft 365 roadmap entry, the feature is currently in development and will start rolling out in November 2026.

"Microsoft Teams is expanding admin controls for Weaponizable File Protection. Administrators will be able to customize which file types are blocked in Teams to align with their organization's security requirements or continue using the Microsoft-recommended default list," Microsoft says.

"This added flexibility helps organizations tailor file protection policies while maintaining a secure collaboration environment." 

When it reaches general availability, it will be available across Android, desktop, iOS, macOS, and web platforms for standard multi-tenant cloud environments worldwide.

Right now, according to Microsoft's support website, admins can't change the list of blocked file types.

More Teams security improvements

Starting in December, admins can also block external users via the Defender portal to thwart cybercrime gangs(including ransomware groups) attempting to abuse Teams in social engineering attacks targeting victims' employees.

Earlier this month, it said that Teams will get a new security feature designed to provide additional protection against phishing and fraud attempts by blurring QR codes sent by external senders.

This week, Microsoft also announced that, starting in November, it will let users report suspicious guest invitations directly from Teams to help their organization's security teams identify and block phishing attempts and other attacks through guest invitations.

More recently, Microsoft has begun rolling out a new Teams meeting protection policy that lets admins automatically block all identified external bots from joining meetings.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/microsoft-teams-will-let-admins-block-custom-file-extensions/