Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security·
Hyperautomation·
Zero Trust · SASE·
NextGen MSSP for Cloud Security·
Cloud Platforms·
Managed Services·
Data & AI Security·
Identity Protection·
Security Automation·
Threat Intelligence·
Cloud Security 2 min read6 January 2026

Microsoft Teams Secure by Default: Jan 12, 2026

From January 12, 2026 Microsoft Teams enables Secure by Default security layers, filtering risky file types and malicious URLs. Here's what to check before it goes live.

T

Tal

YouCC Technologies

Microsoft Teams Secure by Default: What Changes on January 12, 2026

Starting January 12, 2026, Microsoft is turning on new Teams security layers by default as part of its Secure by Default approach. This is a significant change, because Teams is a daily work channel and attackers actively abuse it for social engineering using files and links that look legitimate inside a seemingly "internal" conversation.

What's changing

The new defaults harden how messages and shared content are handled in Microsoft Teams. Key protections include:

  • Blocking or filtering high-risk, weaponizable file types shared in chats and channels.
  • Protection against malicious URLs delivered through messages.
  • A feedback mechanism for false positives, so teams can report incorrect detections and reduce noise over time.

Why it matters

The organizational impact is not only security but also governance and operations. Teams must balance protection against business continuity, define controlled exceptions where there is a genuine business need, and ensure visibility into block events and alerts. That visibility is what lets you tell the difference between a real attack attempt and legitimate activity that requires a policy adjustment.

What to do

  • Run a short review in the Teams Admin Center under Messaging safety before the change goes live.
  • Confirm that the default policy matches your organizational security standard.
  • Define controlled exceptions for legitimate workflows that rely on file types now being filtered.
  • Make sure block and alert events are surfaced to your security team so you can investigate suspicious activity quickly.

Acting ahead of January 12 means the new Secure by Default protections strengthen your environment without disrupting day-to-day collaboration.


Shared from the CSC - Cloud Security Community community, by Tal.

Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community