Message Center

MC1470410Microsoft Teams: QR code protection for messages from external users

Summary

Microsoft Teams will blur QR code images from external users by default starting October 2026 to reduce phishing risks. Users can choose to reveal these images if trusted. No admin action is needed, but user education on QR code safety is recommended. This applies across all Teams platforms.

More information

What and why

Microsoft Teams is introducing additional protection for QR codes shared by external users in Teams messages. To help reduce the risk of phishing and fraud, images containing QR codes from external senders will be obscured by default. Users can choose to reveal the image before viewing or scanning the QR code.

This security enhancement promotes safer interactions with content received from external users while maintaining flexibility for trusted communications.

Rollout schedule

  • Targeted Release: Beginning in early October 2026 and expected to complete in early October 2026
  • General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete in mid-October 2026

Impact on your organization

Who is affected

  • Organizations that allow communication with external users in Microsoft Teams.
  • Users who receive Teams messages from external senders.
  • Teams administrators and support teams that manage external collaboration policies.

Platforms and services

  • Microsoft Teams
  • Teams desktop
  • Teams web
  • Teams mobile

What will happen

  • Images containing QR codes sent by external users will be blurred by default in Teams messages.
  • Users can reveal the image if they trust the sender and want to view or scan the QR code.
  • The blurred image does not indicate that Microsoft Teams has determined the QR code to be malicious.
  • The protection is applied automatically to QR code images received from external senders.
  • No administrator configuration or policy changes are required.
  • The feature will be enabled by default as part of the rollout.

Action required and recommendations

No admin action is required before rollout.

We recommend that administrators:

  • Inform users that QR code images from external senders may appear blurred by default.
  • Remind users to verify the sender before revealing or scanning QR codes.
  • Review existing user education materials related to phishing awareness, QR code safety, and external collaboration.
  • Update internal help desk documentation to reflect the new user experience.

Compliance considerations

No compliance considerations identified, review as appropriate for your organization.