Microsoft Teams adds customizable file-extension blocking and new external-access defenses; sponsored report flags M365 sharing governance gaps
Microsoft is developing admin controls letting Teams administrators customize blocked high-risk file extensions in Weaponizable File Protection, rolling out from November 2026, alongside external-user blocking, QR-code blurring, and bot blocking; separately,…
Two BleepingComputer reports published 2026-09-18 cover Microsoft 365 security governance from different angles. The first reports that Microsoft is expanding admin controls for Weaponizable File Protection in Teams, letting administrators customize the list of blocked high-risk file extensions rather than relying only on Microsoft's recommended default list. Per the Microsoft 365 roadmap, the feature is in development with rollout beginning November 2026 across Android, desktop, iOS, macOS, and web in standard multi-tenant cloud environments. Microsoft also announced complementary Teams defenses: blocking external users via the Defender portal starting December, blurring QR codes from external senders, reporting suspicious guest invitations from November, and automatically blocking external bots from meetings. The second report, a sponsored article by tenfold, argues that shared access in Microsoft 365 frequently outlives its purpose, citing a Wire survey in which 61% of security leads said access to shared files often remains active longer than intended. It criticizes native SharePoint Advanced Management sharing reports as too coarse and site-level exports as too manual, and promotes tenfold's identity governance platform for centralized visibility into shared Teams, OneDrive, and SharePoint content plus owner-driven access reviews with confirm-or-revoke actions. The two reports do not conflict; they address adjacent aspects of M365 security administration, with the second being vendor-sponsored content.
- Microsoft Teams Weaponizable File Protection will let admins customize the list of blocked high-risk file extensions instead of using only Microsoft's recommended default list
- Feature is in development per the Microsoft 365 roadmap; rollout begins November 2026 across Android, desktop, iOS, macOS, and web for standard multi-tenant cloud environments
- December update will let admins block external users via the Defender portal
- Additional Teams defenses announced: blurring QR codes from external senders, reporting suspicious guest invitations starting November, and automatically blocking external bots from meetings
- Wire survey cited in tenfold-sponsored article: 61% of security leads said access to shared files often remains active longer than intended
- Sponsored article calls native SharePoint Advanced Management sharing reports too coarse and site-level exports too manual
- tenfold's identity governance platform offers centralized visibility into shared Teams, OneDrive, and SharePoint content plus owner-driven access reviews with confirm or revoke actions
Coverage timelineoldest first · each row is one article
- · 8d agoMicrosoft Teams will let admins block custom file extensions
BleepingComputer· 22
Microsoft Teams will let admins customize blocked file extensions in Weaponizable File Protection, rolling out globally from November 2026 across all platforms.
- · 8d agoSecure enterprise sharing with access reviews for Microsoft 365
BleepingComputer· 12
tenfold-sponsored article warns Microsoft 365 file sharing often outlives its purpose and pitches its identity governance platform for access reviews.