Skip to content

Security1 publisher2 min readPublished

Microsoft opens the Teams weaponizable-file blocklist to admin edits in November 2026

Weaponizable File Protection has blocked high-risk attachments in Teams chats off a list only Microsoft could edit. From November 2026 administrators can write their own.

The Watch · Security desk

What happened

  • A Microsoft 365 roadmap entry puts an admin control for Teams Weaponizable File Protection into rollout in November 2026, letting tenants set which file types the feature blocks in chats and channels.
  • At general availability the control covers Android, desktop, iOS, macOS and web, in standard multi-tenant cloud environments worldwide.
  • A separate December change lets admins block external users from the Defender portal; Microsoft cites cybercrime gangs, ransomware groups included, abusing Teams for social engineering against employees.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Audit and incident work gain a per-tenant setting: after the rollout, the blocked-extension set has to be pulled from policy before anyone can say a delivered file should have been stopped.
  • exposure If customization permits deletions, a tenant can run more permissive than Microsoft's default with no signal to the users sending or receiving files in it.
  • capability Security teams get to block file types their own policy names, instead of filing a request and waiting for the recommended list to change.

Weaponizable File Protection works off a list of file extensions [1]. The list matches on what a file is called [1]. Microsoft describes the feature as scanning conversations and blocking chat or channel messages that carry dangerous, high-risk attachments [2].

Today a tenant cannot touch that list. Microsoft's support documentation says administrators can't change the blocked file types [7], so every Teams tenant enforces the same set. The roadmap entry ends that for tenants that want it ended, starting November 2026 [3].

Microsoft's wording is specific about the choice and vague about the direction. "Administrators will be able to customize which file types are blocked in Teams to align with their organization's security requirements or continue using the Microsoft-recommended default list," the roadmap entry says [4]. The entry is silent on whether customizing includes taking an extension off the list. Adding extensions helps defenders: a security team can block a type its own policy names without waiting for Microsoft [4]. Removing them is what an attacker cares about, because a tenant could then sit more permissive than the default while the people sending and receiving files see nothing different.

Before the rollout, a responder can assess a Teams-delivered file against one known set [7]. After it, the tenant policy is evidence you have to pull before you can say whether the file should have been stopped.

Microsoft also said the change "helps organizations tailor file protection policies while maintaining a secure collaboration environment" [5]. At general availability the control covers Android, desktop, iOS, macOS and web, in standard multi-tenant cloud environments worldwide [6].

Set it against the rest of the queue. Four of the five Teams protections Microsoft has described concern someone outside the tenant [12]: external users blockable from the Defender portal in December [8], QR codes from external senders blurred [9], suspicious guest invitations reportable from within Teams starting in November [10], and identified external bots kept out of meetings by policy [11]. The file blocklist is the one that applies to internal chat as well [2]. For the December control, Microsoft's stated reason is cybercrime gangs, ransomware groups among them, abusing Teams in social engineering attacks against employees [8].

So the November 2026 change does not hand an attacker anything on its own. It moves the blocklist from Microsoft's control to the tenant's, and a tenant setting can be set wrong. The roadmap lists the feature as in development [3].

What to watch

  • Whether the shipped control lets an admin delete entries from Microsoft's recommended list or only append to it.
  • Whether the November 2026 date holds; the roadmap entry still lists the feature as in development.
  • Whether Microsoft publishes the default extension set, so a defender can diff a customized tenant against it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories