Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365 protections, giving users clearer warnings and security teams more data to investigate suspicious messages.
According to Message Center notice MC1490905, published on October 7, worldwide rollout begins in early October 2026 and is expected to finish by early November. The feature applies to organizations using Microsoft Teams with Defender for Office 365 and requires no separate setup by end users.
The new protection checks Teams messages containing QR codes after delivery. Defender extracts the web addresses stored inside those codes and checks whether they point to malicious content. If a dangerous URL is found, Teams displays a warning on the affected message in both internal and external conversations.
How Teams QR Code Protection Works
Microsoft’s example screenshots show warnings stating that a message contains a link that might be harmful. Another example shows a channel post marked as blocked because of potentially harmful content. These examples show two possible outcomes, a visible warning or a blocked message, rather than a promise that every suspicious code will be removed.
Organizations with Defender for Office 365 Plan 1 or Plan 2 and Zero-hour Auto Purge for Teams enabled may also have eligible malicious internal messages blocked. Known as ZAP, this existing feature acts on harmful messages after delivery. Microsoft’s Teams protection documentation explains how administrators can review its settings and exclusions.
QR code phishing, often called quishing, embeds a malicious web address in an image instead of a standard text link. Attackers use requests to verify accounts, review documents, or resolve technical problems to encourage scanning. Victims may then reach fake sign-in pages that steal their passwords.
Cybersecurity News previously covered a Microsoft 365 QR code phishing campaign in which fake Microsoft or IT messages pushed users to scan codes with their phones. The links redirected to copied login pages. Checking the address inside the image helps defenders assess the destination rather than relying on the surrounding message.
This update is different from the previously reported Teams QR code protection for external senders, which obscures QR images until users choose to reveal them. The new Defender capability evaluates extracted URLs after delivery and responds when malicious content is identified. The two controls address different stages of exposure.
Security teams will also gain visibility through Advanced Hunting in Microsoft Defender XDR. Addresses extracted from QR codes will appear in the MessageUrlInfo table, with QRCode recorded in the UrlLocation column. Analysts can use that value to identify URLs found inside QR images during investigations.
Microsoft recommends reviewing existing Teams protection settings and ZAP configuration, informing security operations staff about the new hunting data, and updating investigation processes to include QR detections. No action is required to enable the enhancement as part of existing Teams URL protection.
The timing remains important. Microsoft describes this as post-delivery protection, not a guarantee that every harmful QR code will be blocked before users see it. Employees should keep verifying unexpected scanning requests through trusted channels, especially when messages ask them to sign in or fix an urgent work account issue.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

