Microsoft 365 Message Center item MC1470410

MC1470410 - Microsoft Teams: QR code protection for messages from external users

Microsoft Teams will blur QR code images from external users by default starting October 2026 to reduce phishing risks. Users can choose to reveal these images if trusted. No admin action is needed, but user education on QR code safety is recommended. This applies across all Teams platforms.

Message Center ID
MC1470410
Category
stay Informed
Severity
normal
Services
Microsoft Teams
Tags
Feature update, User impact, Admin impact
Roadmap ID
570439
Platforms
Android, Desktop, iOS, Mac, Web
Published
2026-09-10
Last updated
2026-09-10
Expires
2026-11-12

[What and why]Microsoft Teams is introducing additional protection for QR codes shared by external users in Teams messages. To help reduce the risk of phishing and fraud, images containing QR codes from external senders will be obscured by default. Users can choose to reveal the image before viewing or scanning the QR code.This security enhancement promotes safer interactions with content received from external users while maintaining flexibility for trusted communications.[Rollout schedule]Targeted Release: Beginning in early October 2026 and expected to complete in early October 2026General Availability (Worldwide): Beginning in mid-October 2026 and expected to complete in mid-October 2026[Impact on your organization]Who is affectedOrganizations that allow communication with external users in Microsoft Teams.Users who receive Teams messages from external senders.Teams administrators and support teams that manage external collaboration policies.Platforms and servicesMicrosoft TeamsTeams desktopTeams webTeams mobileWhat will happenImages containing QR codes sent by external users will be blurred by default in Teams messages.Users can reveal the image if they trust the sender and want to view or scan the QR code.The blurred image does not indicate that Microsoft Teams has determined the QR code to be malicious.The protection is applied automatically to QR code images received from external senders.No administrator configuration or policy changes are required.The feature will be enabled by default as part of the rollout.[Action required and recommendations]No admin action is required before rollout.We recommend that administrators:Inform users that QR code images from external senders may appear blurred by default.Remind users to verify the sender before revealing or scanning QR codes.Review existing user education materials related to phishing awareness, QR code safety, and external collaboration.Update internal help desk documentation to reflect the new user experience.[Compliance considerations]No compliance considerations identified, review as appropriate for your organization.