Loading...

Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

Microsoft Defender for Office 365 extends Teams URL protection to detect malicious URLs in QR codes post-delivery, warning users and enabling security teams to investigate via Advanced Hunting. Rolling out worldwide from October to November 2026, no user action is required, but admins should review related settings and processes. We’re extending Microsoft Teams URL protection in Microsoft Defender for Office 365 to detect and respond to malicious URLs embedded in QR codes. As attackers increasingly use QR codes to conceal malicious destinations, this update helps protect users by analyzing URLs extracted from QR codes after message delivery and applying post-delivery protections when malicious content is identified. For organizations using Microsoft Defender for Office 365, this enhancement builds on existing Teams URL protection capabilities and improves visibility for security operations teams investigating QR-code-based threats. Security teams will also be able to identify QR code URL detections in Advanced Hunting through the MessageUrlInfo table. Rollout schedule General Availability (Worldwide): Beginning in early October 2026 and expected to complete by early November 2026 Impact on your organization Who is affected Organizations using Microsoft Teams with Microsoft Defender for Office 365 Organizations using Microsoft Teams Organizations licensed for Microsoft Defender for Office 365 Security operations teams that use Microsoft Defender XDR Advanced Hunting Organizations that have Zero-hour Auto Purge (ZAP) for Teams enabled can receive additional protection for eligible internal messages Platforms and services Microsoft Teams Microsoft Defender for Office 365 Microsoft Defender XDR Advanced Hunting What will happen Teams messages containing QR codes will be analyzed after message delivery. URLs extracted from QR codes will be evaluated for malicious content. When a malicious URL is identified in an external conversation, users will see a warning on the affected Teams message. When a malicious URL is identified in an internal conversation, users will see a warning on the affected Teams message. Organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2 and Teams ZAP enabled may have eligible malicious internal messages blocked through existing post-delivery protection mechanisms. Security teams will gain visibility into QR code URL detections through Advanced Hunting. URLs extracted […]

The post Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Defender for Office 365: Post-delivery protection for malicious QR codes in Microsoft Teams

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Dynamics 365 Field Service: Automate optimizations with Scheduling Operations Agent

This release expands the optimization capabilities of the Scheduling Operations Agent to include the ability to create recurring optimizations...

1 hour ago

Microsoft Teams: Call quality feedback surveys for Teams Rooms on Android

Microsoft Teams will introduce call quality feedback surveys for Teams Rooms on Android starting November 2026. Users can rate audio, video, a...

2 hours ago

Microsoft Edge: Retiring legacy sign-in implementation on Windows

Microsoft Edge on Windows will retire its legacy direct-WAM sign-in in version 157, fully adopting the OneAuth library to standardize authenti...

2 hours ago

Microsoft Defender Vulnerability Management: Private preview for selected developer package vulnerability coverage

Microsoft Defender Vulnerability Management is privately previewing expanded vulnerability coverage for selected Node.js, Python, and Java pac...

2 hours ago

Microsoft Teams: Analytics for desk utilization in Teams Pro Management portal

Microsoft Teams Pro Management portal will add desk utilization analytics, showing usage, reservations, occupancy, and peak patterns. Requires...

3 hours ago

‘Record A Skill’ Capability in PowerPoint Copilot

PowerPoint Copilot will introduce a “Record a Skill” feature in October 2026, allowing users to record and reuse workflows for com...

3 hours ago

Microsoft 365: Targeted Release retirement

Microsoft 365 Targeted Release will retire in January 2027, replaced by Frontier, Standard, and Deferred release options. Administrators must ...

3 hours ago

Interim guidance for Manitoba time zone changes

A time zone change affects Windows devices in Manitoba, with Windows releasing a fix in October 2026. Manitoba is permanently moving to UTC-5 ...

3 hours ago

Microsoft Purview DLP: Improved setup and Intune multi-admin approval support for unmanaged apps in Edge for Business

Starting November 2026, Microsoft Purview DLP will improve setup and support Intune multi-admin approval for unmanaged apps in Edge for Busine...

3 hours ago

Microsoft Viva Insights: New Power BI report publishing capabilities for leaders

Microsoft Viva Insights is expanding Power BI report publishing to leaders, allowing them to publish and distribute reports directly. The R...

3 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.