Security1 distinct publisher2 min readPublished
Microsoft 365 Roadmap entry 570439 obscures images containing QR codes from outside the tenant until the recipient reveals them. That puts the last check on the person in the chat window.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A reveal gate is an interface control: it moves the decision to the recipient without telling the product anything new about the image. The roadmap wording quoted by Help Net Security covers obscuring the image and requiring a reveal, and nothing in it says Teams will decode the code, resolve the destination, or block it [1][12]. Microsoft's own stated rationale is behavioural, encouraging more deliberate interaction with QR code content [4].
That is what a defender should take from this. The problem the report names is that a user cannot see where a code leads before scanning it, and that scammers hide malicious links and malware behind a code that looks ordinary [5]. The control shipping against that problem is a human pause [1]. A scanner reading the destination inside the chat pipeline would produce a verdict; this produces a blur.
The consumer statistics in the report are the weakest part of the case for anyone sizing Teams exposure. NordVPN's figure of 73% of Americans scanning without verifying the destination leaves 27% who do check [6][10], and the more than 26 million users it counts as redirected to malicious sites are not identified as Teams users [7]. The Federal Trade Commission's 2025 advisory concerned QR codes on unexpected packages [8]. None of those measure how much quishing arrives in a federated chat, and the material carries no such figure [13].
Dates are firmer than the framing. The report is dated September 4, 2026 [9]. Rollout is expected to begin in October 2026 across Android, desktop, iOS and Mac, roughly a month later [2][14], and about a year after the FTC's 2025 warning to consumers [11]. The entry also says the feature is in development, which is a target and not a shipped control [2].
So the practical delta is narrow and worth having anyway. Every external image that carries a machine-readable destination arrives flagged as something requiring a decision, on all four clients listed [1][2]. Defenders gain a training hook and an audit trail for the reveal; they gain no detection of what the code contains. Tenants that already treat external federation as a phishing channel get no new inspection out of it; tenants that do not will get a prompt their users can click through.
Read against the broader pattern, the interesting part is placement. Scammers hide the destination in the image rather than in a link a recipient could read [5], and the answer Microsoft has put on the roadmap for the collaboration surface is a default of distrust for one class of rendered content [1][4].
Ranked by verification strength, evidence, and original report placement.
Microsoft Teams will obscure by default images containing QR codes shared by external users in messages, requiring users to reveal them before viewing or scanning.
The feature is currently in development, with rollout expected to begin in October 2026 for Android, desktop, iOS and Mac.
The change is described in Microsoft 365 Roadmap entry 570439.
Microsoft says the change helps reduce the risk of phishing and fraud by encouraging more deliberate interaction with QR code content.
The main problem with QR codes is that users cannot see where they lead before scanning, and scammers use this to hide bad links or malware behind a normal-looking code.
In 2025 the U.S. Federal Trade Commission warned consumers that QR codes on unexpected packages should be treated as suspicious.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Microsoft documents helpdesk impostors riding a granted Teams session to domain controllers1 distinct publisher
product
Scam victims in China are logging into Teams accounts their scammers control1 distinct publisher
leadership
Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem1 distinct publisher
product
Agent-to-agent email is already here. The disclosure rule is not.1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Roadmap quote solid, surrounding numbers borrowed
The centre of this story is Microsoft's own roadmap wording, quoted directly — about as reliable as a pre-release fact gets, and about as narrow. Everything wrapped around it is thinner: the 73% and the 26 million come from NordVPN by way of Help Net Security, with no sample, period or link, and no second outlet has independently touched the story.
A dated plan, not a deployment
October 2026 is the target; the reporting is dated September 2026. Nothing has shipped, no tenant has it, and no preview ring, admin toggle or early-access build is described anywhere in this coverage. The only thing in the world today is a roadmap row.
Headline promises more than the roadmap does
'Much harder' is carrying a lot of weight for a change that blurs a picture until someone taps it. Microsoft's own text never claims to decode the code or check where it points, so the final judgement still sits with the person in the chat window — and not one figure in the story says how often that person is being targeted in Teams to begin with.
Every number has a seller behind it
Microsoft is publicising a control it has not yet shipped; the prevalence figures come from NordVPN, which sells consumer security subscriptions. Neither is disqualifying, but no disinterested measurement appears in this story — the 2025 FTC advisory is the only cited party with nothing to sell.
Confident about the plan, little else
What Microsoft has published, and when it says the change starts, we can state plainly. Whether it arrives on that date, whether admins get a switch, and how much QR abuse Teams actually carries all stay open, because a single outlet paraphrasing a roadmap entry is the whole basis for this assessment.