Skip to main content
CybersecurityNetwork Security

Microsoft Enhances Teams Security with Custom File Extension Blocking

Microsoft Teams interface on laptop screen with file upload window and office background.

"Microsoft Teams is expanding admin controls for Weaponizable File Protection. Administrators will be able to customize which file types are blocked in Teams to align with their organization's security requirements or continue using the Microsoft-recommended default list," Microsoft says.

Weaponizable File Protection: what will change

Microsoft is updating Weaponizable File Protection, the built‑in Teams messaging safety feature that scans conversations and blocks chat or channel messages carrying dangerous, high‑risk file attachments. Under the planned change, administrators will be able to customize which file extensions are blocked by Teams, rather than relying solely on the product's default list of file types associated with malware and security threats. Microsoft described the move as providing "added flexibility" to tailor file protection policies while maintaining a secure collaboration environment.

Development status and rollout schedule

The capability is listed in a Microsoft 365 roadmap entry and is described as "currently in development." Microsoft says the change will begin rolling out in November 2026. When it reaches general availability, the customizable block list will be supported across Android, desktop, iOS, macOS, and web platforms for standard multi‑tenant cloud environments worldwide.

What administrators can and cannot do today

As of the current support documentation, administrators cannot modify the list of blocked file types in Teams. The forthcoming update will add the ability to deviate from the Microsoft‑recommended default list and set organization‑specific policies for which file types are blocked in chats and channels.

Other Teams security controls Microsoft has announced

Microsoft has been rolling out multiple Teams security features alongside the Weaponizable File Protection change. Starting in December, administrators will be able to block external users via the Defender portal — a measure Microsoft framed as intended to thwart cybercrime gangs, including ransomware groups, that attempt to abuse Teams in social engineering attacks targeting employees.

Earlier this month Microsoft said Teams would gain a feature to blur QR codes sent by external senders to provide additional protection against phishing and fraud attempts. Separately, Microsoft announced that, starting in November, users will be able to report suspicious guest invitations directly from Teams to help their organization's security teams identify and block phishing attempts and other attacks delivered through guest invitations. More recently, Microsoft has begun rolling out a Teams meeting protection policy that lets administrators automatically block all identified external bots from joining meetings.

What this means for technologists, enterprises, and end users

  • Technologists and security teams: The customizable block list will let administrators align Teams' file‑type protections with internal policy and risk tolerance rather than relying only on Microsoft’s default. Teams administrators should plan for the November rollout and test policies across the Android, desktop, iOS, macOS, and web clients in multi‑tenant cloud environments.
  • Enterprises and procurement leaders: Organizations evaluating collaboration controls will have an additional configurable lever to mitigate delivery of potentially weaponizable file types through corporate Teams channels, while retaining compatibility with Microsoft’s recommended defaults if preferred.
  • End users: Users will continue to have messages scanned by Weaponizable File Protection; the update affects administrative control over which file types are blocked, rather than removing the scanning or blocking behavior itself.

Microsoft’s changes bundle into a broader effort to surface more granular controls for Teams administrators: customizable file‑extension blocking in November 2026, user reporting of suspicious guest invites starting in November, external‑user blocks via the Defender portal beginning in December, and other protections such as QR code blurring and meeting bot blocking already entering rollouts. The sequence leaves administrators with concrete configuration choices to consider as the features become broadly available.

Read the original report: https://www.bleepingcomputer.com/news/security/microsoft-teams-will-let-admins-block-custom-file-extensions/