Launches

Microsoft to Enforce Three New Security Defaults in Teams Starting January 2026

Microsoft is moving Teams toward mandatory security protections, automatically enabling three critical messaging safeguards for organizations using standard configurations beginning January 12, 2026.

·3 min read
Microsoft Makes Teams ‘Secure by Default’ Starting January 2026
Microsoft Makes Teams ‘Secure by Default’ Starting January 2026

The software maker is reshaping how workplace collaboration handles security, moving away from a model where protections remain optional toward one where defenses activate by default. On Jan. 12, 2026, Microsoft will enable three essential messaging protections automatically for any organization that hasn't customized its security settings. This shift aims to protect companies lacking dedicated security resources from the growing threat of AI-powered phishing campaigns and malware distribution.

The initiative represents a key component of Microsoft's effort to reduce vulnerabilities in its suite of tools. In communications to system administrators, Microsoft outlined the reasoning behind this mandatory security enforcement.

We're improving messaging security in Microsoft Teams by enabling key safety protections by default. This update helps safeguard users from malicious content and provides options to report incorrect detections.

Microsoft

Going forward, Teams will no longer depend on administrators to manually activate threat-blocking mechanisms. Instead, security standards will be elevated universally, ensuring that organizations without specialized security personnel still benefit from robust protection.

Three walls of defense

The rollout will transition three capabilities from optional to enabled for standard users:

  • Weaponizable file-type protection: Messages containing dangerous file types—including executables and certain scripts commonly deployed by attackers to introduce malware—will be blocked automatically by Teams.
  • Malicious URL detection: Every hyperlink posted in conversations or channels will undergo real-time analysis. Links directing to known phishing destinations or suspicious domains will display a warning before users can access them.
  • False positive reporting: A feedback mechanism will be incorporated to prevent excessive blocking. Users can flag files or links that were incorrectly blocked, enabling Microsoft's systems to refine their detection logic.

What this means for your daily workflow

Organizations subject to this change may notice alterations to their Teams experience starting Jan. 12. Attempting to share a file flagged as high-risk will prevent the message from being sent. Similarly, when someone shares a potentially dangerous link, recipients will encounter a visible warning before proceeding.

Though this may introduce friction into certain workflows, the objective is to block the ransomware infections and account compromise attacks that frequently originate from a single seemingly legitimate message within a collaboration platform.

Administrators retain some agency in this transition. Microsoft has established a deadline allowing organizations to evaluate these modifications before implementation becomes mandatory.

Organizations preferring to maintain their existing, less stringent security configuration must manually modify their settings and save them through the Teams Admin Center prior to the January deadline. The required path is Messaging > Messaging settings > Messaging safety.

All other organizations will receive the update without any action needed. Security professionals recommend that support teams receive training now so they can properly assess whether a blocked message represents a genuine security incident or a configuration issue when the new protections activate in 2026.