Microsoft Teams Is About to Hide QR Codes From External Senders — Here's Why That Matters
Quick Answer: Microsoft Teams will soon obscure QR codes sent by external users by default, requiring a manual "reveal" before viewing or scanning — a direct response to rising quishing attacks. Rollout begins October 2026.
Last verified: September 7, 2026
A vendor you've never met sends a "new invoice portal" QR code in a Teams chat. It looks routine — vendors do this constantly. Someone on the finance team scans it on their phone, half-thinking about the three other messages waiting in their inbox. Thirty seconds later, they've handed a Microsoft 365 session token to an attacker who never had to touch the corporate network, bypass EDR, or write a single line of malware. They just asked, politely, to be scanned.
This is exactly the scenario Microsoft is now trying to interrupt. According to a Microsoft 365 Roadmap entry spotted this week, Teams is building a feature that automatically blurs QR code images from external senders until the recipient chooses to reveal them. It's a small UI change with a fairly large security rationale behind it, and it's worth understanding both the mechanics and the gap it doesn't close.
Table of Contents
- What's Actually Changing in Teams
- Why QR Codes Became a Favorite Social-Engineering Tool
- A Realistic Attack Scenario
- Roadmap Details and Rollout Indicators
- Detection and Prevention Beyond the Blur
- Expert Tips for Security Teams
- Related Articles
- FAQ
- Conclusion
What's Actually Changing in Teams
Per Microsoft 365 Roadmap ID 570439, Teams will "provide additional protection for QR codes shared by external users in messages." Images containing QR codes sent from outside the recipient's tenant will be obscured by default. The user has to take a deliberate action — revealing the image — before they can view or scan the code underneath.
The feature is currently listed as In Development, with both Targeted Release and General Availability phases planned. Rollout is scheduled to begin in October 2026, covering Teams on desktop, Mac, Android, and iOS, for organizations in the Worldwide Standard Multi-Tenant cloud environment.
Critically, this only applies to external senders — guest users, partner organizations, vendors, contractors, or anyone outside the recipient's own tenant. QR codes shared internally between colleagues on the same tenant won't be affected. That scoping decision reflects where Microsoft's threat data says the real risk sits: the trust boundary between "someone in my company" and "someone I've never verified."
Why QR Codes Became a Favorite Social-Engineering Tool
QR codes are attractive to attackers for a simple reason: the destination URL is invisible until the code is scanned. A malicious link pasted directly into a chat can be inspected — hovered over, copied, checked against a blocklist. A QR code embedded in an image skips all of that. Most secure email gateways and chat-based URL scanners were built to inspect text-based links, not pixels inside an image, which creates a detection blind spot attackers have been exploiting more aggressively.
That blind spot shows up in the broader phishing telemetry too. Quishing has been one of the fastest-growing attack vectors industry-wide going into 2026, and Microsoft's own threat intelligence has flagged phishing email volume climbing sharply this year, with QR-based delivery methods — particularly through PDF and document attachments — seeing outsized growth quarter over quarter. Teams becoming a delivery channel for the same tactic isn't a surprise; it's the logical next step once email defenses started catching up.
A Realistic Attack Scenario
Picture a mid-size enterprise that regularly onboards external contractors into Teams for project collaboration — a common setup for consulting, IT services, and marketing agencies. An attacker compromises one contractor's Microsoft 365 account, or simply creates a lookalike guest account with a similar display name.
From there, the attacker messages several employees directly, referencing an ongoing project by name for credibility, then attaches an image containing a QR code — framed as a "secure document link" or "updated payment details." Because the QR code renders as an ordinary image in the chat thread, it doesn't trigger the same instinctive caution a suspicious hyperlink might. The employee scans it on their phone, lands on a credential-harvesting page cloned to look like a Microsoft sign-in screen, and enters their credentials — handing over session access without ever leaving what felt like a normal work conversation.
This is the specific gap the new Teams control is designed to close: not by blocking the QR code outright, but by forcing a conscious "do I actually want to see this?" decision point before the image renders.
Roadmap Details and Rollout Indicators
| Detail | Value |
|---|---|
| Roadmap ID | 570439 |
| Status | In Development |
| Rollout start | October 2026 |
| Platforms | Teams Desktop, Mac, Android, iOS |
| Cloud instance | Worldwide (Standard Multi-Tenant) |
| Release phases | Targeted Release, General Availability |
| Scope | QR codes in images from external senders only |
The entry was published to the Microsoft 365 Roadmap on September 3, 2026, and hasn't been substantially revised since. As with most roadmap items still in development, exact rollout dates and tenant-level default behavior (opt-in vs. opt-out control for admins) may shift before General Availability — worth monitoring in the Microsoft 365 admin center's Message Center rather than treating the roadmap listing as final.
Detection and Prevention Beyond the Blur
The obscure-by-default behavior is a useful friction point, but it isn't a control SOC teams should treat as sufficient on its own. A few things worth building around it:
- Don't treat "revealed" as "verified." Employees need to understand that choosing to reveal a QR code confirms curiosity, not safety. Train users to verify unexpected QR codes — especially ones tied to logins, payments, or urgent requests — through a separate, trusted communication channel before scanning.
- Tighten external access and guest policies. Review who can message your users from outside the tenant in the first place. Restricting external Teams communication to approved domains reduces the pool of accounts that can attempt this in the first place.
- Layer in conditional access and MFA resistant to phishing. QR-based credential harvesting is only catastrophic if the stolen credentials work unopposed. Phishing-resistant MFA (FIDO2 keys, certificate-based auth) blunts the payoff even if a user scans and enters credentials.
- Monitor for anomalous guest/external activity. Sudden messaging bursts from new external accounts, especially ones referencing project names or impersonating known vendors, are a detectable pattern worth alerting on in your SIEM.
- Extend awareness training to include chat-based quishing, not just email. Most phishing simulations still center on email. Teams-based QR lures are different enough in presentation that they deserve their own training module.
Expert Tips for Security Teams
- Ahead of the October rollout, confirm whether your organization will get admin-level control over this setting or whether it applies universally — that detail typically surfaces in Message Center updates closer to General Availability.
- Don't rely on this feature alone to reduce your quishing exposure metrics. Pair it with URL/QR content inspection at the email gateway level for a fuller picture, since attackers will likely just shift more QR delivery toward email and other channels this control doesn't touch.
- Add "Teams QR code from an external contact" as a named scenario in your next tabletop exercise or phishing simulation cycle — most current simulation platforms still don't cover this vector well.
Related Cybersecurity Topics You Should Explore
- Dahua Camera Backdoor Survives Password Resets and Factory Resets
- Is Your Driver's License for Sale? 153 Million Records Leaked, FBI Investigates
- QR Code Phishing Just Hit Record Levels: What SOCs Must Know Now
- Microsoft Teams Won't Load? Inside the TM1466820 Windows Bug
- Why Ad Networks Get Your Blogger Blog Locked (Fix It Fast)
- The touch Command Trick Attackers Use to Fake File Timestamps
- WordPress Now Uses AI to Catch Security Flaws Before Hackers Do
- Mini Shai-Hulud Worm Hits npm Package With 150K Weekly Downloads
- more vs less Linux Commands: The SOC Analyst's Log Review Guide
- JFrog Artifactory Hacked: Attackers Are Minting Admin Tokens
- tail -f Explained: The Linux Command That Beats Your SIEM's Delay
- Brave Browser Now Hides Your Real Email From Every Website
- D-Link Router Flaw Lets Hackers Steal Your Wi-Fi Password
- 'This Blog Has Been Locked' — How to Backup Blogger the Right Way
- cPanel Zero-Day Lets Hackers Seize Root Control of Your Server
FAQ
When does the Teams QR code protection feature roll out?
Rollout is scheduled to begin in October 2026, per Microsoft 365 Roadmap ID 570439, which is currently listed as In Development.
Does this block QR codes from internal colleagues too?
No. The protection specifically targets QR code images shared by external senders — guests, vendors, partners, or anyone outside your own tenant.
Can users still scan QR codes after they're obscured?
Yes. The image is hidden by default, but users can manually reveal it to view or scan the QR code. The feature adds friction, not a hard block.
Which Teams platforms will support this feature?
Desktop, Mac, Android, and iOS clients, for organizations in the Worldwide Standard Multi-Tenant cloud environment.
Does revealing a QR code mean it's safe?
No. Revealing only means the user chose to view it — it doesn't confirm the destination is legitimate. Unexpected QR codes, especially those tied to logins or payments, should still be verified through a separate trusted channel.
Why are QR codes a growing phishing vector?
Because the destination URL is hidden until scanned, QR codes bypass a lot of link-inspection tooling built for text-based URLs — making them attractive for credential-harvesting campaigns delivered through email attachments and, increasingly, chat platforms like Teams.
Does this replace the need for external access policies?
No. It's a complementary control. Guest access restrictions, phishing-resistant MFA, and user awareness training remain necessary alongside it.
Conclusion
Microsoft's QR code protection for Teams won't stop quishing on its own, but it closes a specific and fairly obvious gap: QR codes rendering as trusted-looking images inside a workplace chat, with zero friction between "received" and "scanned." For security teams, the real work between now and October is making sure external access policies, MFA posture, and user training actually cover this vector — because the moment this control ships, attackers adapt the lure, not the intent.
Is your organization reviewing its Teams external access settings ahead of this rollout? Share your approach in the comments, or subscribe for more breakdowns of upcoming Microsoft 365 security changes.
Analysis based on SOC monitoring and public threat intelligence review.





