Microsoft Teams Will Let Admins Customize Blocked File Types to Improve Malware Protection
Microsoft Teams is adding new administrative controls that will allow organizations to customize the file extensions blocked by the platform’s malware and security protection features.
The update expands Weaponizable File Protection, a built-in Teams messaging security feature that scans conversations and blocks chats and channel messages containing dangerous or high-risk file attachments.
According to a Microsoft 365 roadmap entry, the feature is currently in development and is expected to begin rolling out in November 2026.
“Microsoft Teams is expanding administrative controls for Weaponizable File Protection. Administrators will now be able to customize the file types they block in Teams to suit their organization’s security requirements, or continue using the default list recommended by Microsoft,” Microsoft said.
“This added flexibility allows organizations to adjust their file protection policies while maintaining a secure collaboration environment.”
Once generally available, the customizable file-blocking controls will be supported on Android, desktop, iOS, macOS, and the web in standard multitenant cloud environments worldwide.
Currently, according to the Microsoft support website, administrators cannot modify the list of blocked file types.
More Microsoft Teams security improvements are coming
Starting in December, administrators will also be able to block external users through the Microsoft Defender portal. The control is designed to help stop cybercrime organizations, including ransomware groups, from exploiting Teams in social engineering attacks targeting employees.
Earlier this month, Microsoft announced additional Teams security features designed to protect users from phishing and fraud, including the ability to blur QR codes sent by external senders.
Microsoft also announced that, starting in November, users will be able to report suspicious guest invitations. The feature will help security teams identify and block phishing attempts and other attacks delivered through guest invitations directly from Teams.
Recently, Microsoft began rolling out new Teams meeting protection policies that allow administrators to automatically block all identified external bots from joining meetings.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



