$ techbeacon▋
Threats

Microsoft Teams Adds Admin Control Over Risky File Types

Microsoft Teams Adds Admin Control Over Risky File Types

Microsoft announced that its collaboration platform Teams will soon allow organization administrators to define and block custom file extensions, expanding the tool's built‑in security controls to better match corporate policies.

File extensions such as .exe, .js or .vbs have long been associated with malware delivery, phishing and other cyber threats. Teams currently blocks a standard set of these high‑risk types by default, but the new capability lets IT teams tailor the list to include additional extensions that may be considered dangerous within their specific environment.

Administrators will access the feature through the Teams admin center, where they can add or remove extensions from a configurable blocklist. The interface is expected to mirror existing settings for content filtering, making it straightforward for administrators already familiar with Teams' security suite. The change does not affect the ability to share files that are already permitted, and users attempting to upload a blocked type will receive a clear warning.

Enterprise security teams view the move as a response to the growing sophistication of file‑based attacks that often bypass traditional email filters by exploiting collaboration tools. By granting granular control over file types, Microsoft aims to reduce the attack surface for organizations that rely heavily on Teams for daily communication, document sharing, and project coordination.

Industry analysts note that similar customization options are already available in competing platforms, and the addition puts Teams on a more even footing with rivals that have long offered extensive file‑type policies. For companies subject to strict compliance regimes—such as finance, healthcare or government—the ability to align Teams' file handling with internal standards could simplify audit processes and lower the risk of inadvertent data leakage.

Microsoft has not disclosed a specific rollout date, but the feature is slated for inclusion in an upcoming Teams update later this year. The company indicated that it will continue to refine the security roadmap, potentially adding automated threat intelligence feeds to suggest new extensions for blocking. Organizations interested in the functionality can monitor the Teams admin portal for the option to enable it, and may need to update internal guidelines to reflect the expanded controls.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related