Microsoft Teams Adds Admin Control to Block Custom File Extensions
What Happened — Microsoft announced that, starting November 2026, Teams administrators will be able to customize the list of file extensions blocked by the Weaponizable File Protection feature. The change lets orgs add or remove extensions beyond the Microsoft‑recommended defaults across all Teams clients.
Why It Matters for Trust & Control Assurance
- Provides a concrete control for the “file‑type filtering” objective that continuous‑control programs monitor and evidence.
- Enables organizations to align Teams’ file‑blocking policy with their own data‑loss‑prevention (DLP) and malware‑prevention standards, creating a defensible audit trail.
- Supports the Verisq Control Mapping capability, which captures configuration changes as verifiable evidence across frameworks.
Who Is Affected
- Enterprises and government agencies that rely on Microsoft Teams for collaboration.
- SaaS providers and MSPs that manage Teams environments for multiple tenants.
Recommended Actions
- Review the upcoming Teams “custom file‑extension block” setting in the Microsoft 365 roadmap.
- Define the extensions that match your organization’s DLP and malware‑prevention policies.
- Once the feature is GA, enable the custom block list and document the configuration in your control‑assurance repository.
- Map this configuration to the relevant control objective (e.g., NIST CSF PR.DS‑1 “Data-at‑rest is protected”) and capture evidence for audit readiness.
Technical Notes – The feature extends the existing Weaponizable File Protection engine, which scans messages for high‑risk attachments. It will be available on Android, iOS, macOS, Windows, and web clients. No CVEs or vulnerabilities are disclosed. Source: BleepingComputer