Cyber Security

Microsoft Teams to Add QR Code Protection in Teams Messaging

Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users.

The feature, currently listed as “In Development” on the Microsoft 365 roadmap, will automatically obscure images containing QR codes when they are sent in Teams messages by people outside an organization.

Microsoft Teams QR Code Protection

The upcoming Microsoft Teams QR code protection feature is scheduled to begin rolling out in October 2026. It will be available across Teams desktop, Mac, Android, and iOS clients, covering organizations in the Worldwide Standard Multi-Tenant cloud environment. Microsoft has classified the update for both Targeted Release and General Availability phases under Roadmap ID 570439.

QR codes have become a common way to share links quickly, but attackers can also use them to move victims away from monitored messaging environments and onto malicious websites. A QR code embedded in an image may appear harmless in a chat conversation, particularly when it is delivered by an external contact, compromised account, or unfamiliar sender.

By requiring users to take an additional action before viewing such content, Microsoft Teams aims to make people pause before scanning a potentially risky code.

Under the planned protection, QR code images shared by external senders will be obscured by default. A Teams user who receives one of these images will need to actively reveal it before they can view or scan the QR code.

The change is intended to encourage more deliberate interaction with QR code content rather than allowing a code to be scanned immediately from within a message thread.

The feature is particularly relevant for organizations that use Teams for collaboration with customers, suppliers, contractors, partners, and other external contacts.

External messaging can be essential for business operations, but it also creates an opportunity for social-engineering attempts that rely on trusted-looking conversations. A fraudster may attempt to imitate a vendor, project stakeholder, or support representative and send a QR code that directs recipients to a credential-harvesting page or other fraudulent destination.

Microsoft’s approach does not remove a user’s ability to access legitimate QR codes. Instead, it adds a visible friction point before an external QR code becomes available for viewing.

This allows recipients to consider the sender, the context of the conversation, and whether the request is expected before proceeding.

Security teams should review how external access and guest communications are used within their Teams environments ahead of the rollout.

Organizations may also want to remind employees that revealing a QR code is not the same as confirming that it is safe. Users should verify unexpected QR codes through a trusted communication channel, especially when the code is connected to login requests, document sharing, payment instructions, or urgent account-related messages.

The Microsoft Teams QR code protection update was added to the Microsoft 365 roadmap on September 3, 2026, and was last modified on the same date.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago