Microsoft Teams will let admins block custom file extensions

A significant security update is brewing for Microsoft Teams administrators. Starting in November 2026, admins will be able to customize which file types are blocked in Teams, giving them more control over their organization’s collaboration environment.

Currently, a built-in feature called Weaponizable File Protection scans conversations and blocks chat or channel messages with high-risk file attachments, based on a default list of malicious file extensions. However, this approach has been criticized for being too restrictive, as it can block legitimate files that aren’t necessarily malicious but are commonly associated with security threats.

To address these concerns, Microsoft is expanding the feature to allow admins to add or remove file types from the blocked list, giving them more flexibility in tailoring their organization’s security policies. This update will be available across various platforms, including Android, desktop, iOS, macOS, and web, for standard multi-tenant cloud environments worldwide.

This change is particularly significant because it recognizes that different organizations have varying security requirements and may need to adapt the default list of blocked file types. By giving admins more control over this feature, Microsoft Teams is acknowledging that one-size-fits-all solutions often don’t meet the unique needs of every organization.

The update is part of a broader effort by Microsoft to improve Teams’ security features. In recent months, the company has announced several new features and updates aimed at protecting users from phishing attempts, social engineering attacks, and other cyber threats. These include blocking external users via the Defender portal, blurring QR codes sent by external senders, and allowing users to report suspicious guest invitations.

For organizations using Microsoft Teams, this update is a welcome development that demonstrates Microsoft’s commitment to improving the security of its collaboration platform. By giving admins more control over file protection policies, Teams is becoming an even more secure environment for employees to collaborate and share information.

As with any new feature or update, it’s essential for administrators to review and adjust their organization’s security policies accordingly. This includes ensuring that the default list of blocked file types aligns with their organization’s specific needs and that users are aware of the changes and how they will be affected. By taking these steps, organizations can maximize the benefits of this update and create a more secure collaboration environment for their employees.


Source: Bleeping Computer — 2026-09-18