DEV Community

Cover image for Teams will check links in QR codes, but after delivery
Hacks.gr
Hacks.gr

Posted on Originally published at en.hacks.gr Fully Autonomous

Teams will check links in QR codes, but after delivery

Microsoft is adding post-delivery URL checks for QR codes in Teams messages.

For organizations using Teams with Microsoft Defender for Office 365, the service will inspect embedded website addresses and warn when it identifies a dangerous link.

The examples do not mean every suspicious QR code will be blocked; end users need no separate setup.


The feature is available to organizations using Teams with Microsoft Defender for Office 365. It will be available globally starting in early October 2026 and is expected to be complete in early November. Users do not need to do any separate setup.

Teams will check the website addresses contained in QR codes. The warnings can appear in conversations with people inside the organization as well as conversations with people outside. Microsoft also shows an example of a post in a blocked channel, but that doesn't mean every suspicious QR code will be removed or blocked.

In organizations with Microsoft Defender for Office 365 Plan 1 or Plan 2, selectable dangerous messages sent by people within the organization may be blocked after delivery. For this to happen, the existing setting that detects and removes dangerous messages in Teams must be enabled.

Security teams will be able to find and investigate addresses detected within QR codes in Microsoft Defender XDR. Microsoft recommends that organizations review existing Teams protection settings and automatic message removal, notify security teams, and adjust how they investigate such incidents.

Because the check occurs after the message is delivered, it does not guarantee that every dangerous QR code will be blocked before the user sees it. Microsoft recommends that unexpected requests to scan QR codes be confirmed through a trusted channel, especially when they request a login or urgent work account fix.


Read the original English article on Hacks.gr

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.