Microsoft Teams Adding Defense Against QR Code Scams in External Chats

Microsoft Teams is rolling out a new safeguard to counter phishing and fraud by blurring QR code images sent by people outside an organization. The feature, now marked “In Development” on Microsoft’s roadmap, is meant to stop malicious links disguised within QR codes from being forwarded unchecked in chat messages. Organizations should anticipate its arrival beginning in October 2026.

How QR Code Protection Will Work

This new protection automatically hides any image containing a QR code sent from an external user to a Teams recipient. Rather than having the code immediately visible, users will need to deliberately choose to reveal and scan it. This design aims to inject a moment of caution, particularly in cases where bad actors attempt to misuse seemingly innocent QR codes to direct people toward phishing or credential-stealing sites.

The safeguard is slated to be available on all major Teams platforms—desktop, Mac, Android, and iOS—for organizations using the Worldwide Standard Multi-Tenant cloud environment. Both the early Targeted Release and General Availability phases of deployment are scheduled under Microsoft’s Roadmap ID 570439.

Why This Matters

Despite their convenience, QR codes have become a common vector for cyberattacks. External users—be they contractors, vendors, or new contacts—may exploit trust to share malicious codes that appear harmless but redirect recipients off secure platforms. Teams’ blur-on-external-sender policy gives users a chance to judge whether an unexpected QR code is safe before interacting with it.

Security and IT teams should start planning now: reviewing norms around guest and external communications in Teams environments will help ensure this feature is effective. Users also need reminders that simply exposing a QR code doesn’t verify its legitimacy—best practice is to double-check unexpected codes through separate, trusted channels, especially for matters involving account access, payments, or sensitive documents.

This QR code protection measure was added to Microsoft’s 365 roadmap on September 3, 2026, with the rollout expected to begin in October. The policy was last updated that same day.

What it means: This change reflects a broader shift toward more visual security defences in collaboration tools. With remote work and cloud-based chat platforms now essential, organizations must harden every touchpoint—including seemingly benign images. Expect more such additions that force friction where attackers often find easy inroads.