VYPR
advisoryPublished Oct 10, 2026· 1 source

Microsoft Teams Enhances Security with Post-Delivery QR Code Link Scanning

Microsoft Defender for Office 365 now scans QR codes within Teams messages for malicious links after delivery, warning or blocking users upon detection.

Microsoft is bolstering its Teams security posture by introducing a new feature within Microsoft Defender for Office 365 that scans QR codes embedded in messages for malicious links, even after they have been delivered to users. This enhancement aims to combat sophisticated "quishing" attacks, where threat actors hide harmful URLs within QR codes to trick recipients into visiting fraudulent websites, often for credential harvesting.

The new protection, detailed in Message Center notice MC1490905, began its worldwide rollout in early October 2026 and is expected to conclude by early November. It requires no additional setup for end-users and operates automatically for organizations utilizing Microsoft Teams with Defender for Office 365. The system extracts URLs from QR codes within Teams messages and analyzes them for malicious content. If a threat is identified, Teams will display a warning on the message or, in some cases, block it entirely, providing users with a clearer indication of potential danger.

Microsoft's provided examples illustrate two possible outcomes: a visible warning on a message or a complete block of the content. For organizations with Defender for Office 365 Plan 1 or Plan 2 and Zero-hour Auto Purge (ZAP) for Teams enabled, malicious internal messages may also be automatically blocked post-delivery. This leverages existing ZAP capabilities to act on harmful content after it has reached the recipient's inbox.

This new capability is distinct from previous Teams QR code protections, such as those that obscure QR images for external senders until explicitly revealed by the user. The Defender for Office 365 enhancement focuses on evaluating the extracted URLs post-delivery and responding to detected malicious content, addressing a different stage of potential exposure. Security teams will benefit from enhanced visibility through Advanced Hunting in Microsoft Defender XDR, where extracted QR code URLs will be logged in the MessageUrlInfo table, identifiable by the QRCode value in the UrlLocation column.

Administrators are advised to review their existing Teams protection settings and ZAP configurations. They should also inform their security operations staff about the new hunting data and update investigation processes to incorporate these QR code detections. While the feature is enabled as part of existing Teams URL protection, Microsoft emphasizes that this is a post-delivery protection mechanism and not a guarantee that all harmful QR codes will be blocked before users encounter them.

Given the nature of post-delivery detection, Microsoft continues to stress the importance of user vigilance. Employees are encouraged to verify unexpected scanning requests, particularly those prompting account verification or issue resolution, through trusted communication channels. This layered approach, combining automated scanning with user education, is crucial for mitigating the evolving threat landscape of QR code-based phishing attacks.

Synthesized by Vypr AI