A fixed Microsoft list is becoming an administrator decision

Microsoft 365 Roadmap item 571298 says Teams administrators will be able to customise which file types Weaponizable File Protection blocks or continue using Microsoft's recommended defaults. The feature is listed as in development, with November 2026 as the current target for worldwide standard multi-tenant environments.

Today, the protection checks file extensions in Teams chats and channels. If it detects a blocked type, Teams prevents delivery of the attachment and the accompanying message. In external conversations, the protection applies to everyone when any participating organisation has enabled it.

Plan against the current product, not the promised date

Microsoft's current documentation still says the blocked list is not configurable. Roadmap dates and implementation details can change, so prepare the policy now but verify the tenant controls and Microsoft documentation again when the feature reaches the environment.

An extension is a useful signal, not a verdict on the file

LayerWhat it can doWhat it does not prove
Teams extension policyStops messages carrying filenames with selected high-risk extensions.That every allowed file is benign or that renamed content is safe.
Safe Attachments and file-store protectionUses threat signals to identify and restrict malicious files in SharePoint, OneDrive, and Teams storage.That every file is scanned synchronously before every possible interaction.
Endpoint controlsRestricts execution and observes process, script, child-process, and network behaviour.That the original collaboration account or sender was trustworthy.
Identity and external-access policyLimits who can contact users and which partner relationships are permitted.That content from an approved identity is harmless after account compromise.

A renamed executable, a permitted archive, a malicious document, or a link to an external payload can bypass the narrow question of filename extension. The new option improves policy fit; it does not convert Teams into a complete content-analysis engine.

Build the policy before the setting appears

  1. 1

    Record the current baseline. Confirm whether Weaponizable File Protection is enabled, which clients and collaboration paths are in scope, and who owns the messaging-safety configuration.

  2. 2

    Measure legitimate file exchange. Review actual Teams workflows for IT support, engineering, security operations, software delivery, contractors, and partner organisations. Include blocked-message tickets and known workarounds.

  3. 3

    Start from the recommended list. Treat Microsoft's list as the baseline. Add formats that create specific risk in the organisation; remove a default only with a documented owner, reason, compensating controls, and review date.

  4. 4

    Provide a safe alternative. Give users an approved route for legitimate high-risk files, such as a managed repository with malware inspection, access control, retention, and audit logging.

  5. 5

    Test cross-tenant effects. Exercise internal chats, channels, guests, and federated conversations. Confirm what senders and recipients see when both the file and the surrounding message are blocked.

  6. 6

    Watch for displacement. Monitor whether a stricter list increases personal email, consumer storage, renamed files, password-protected archives, or unfamiliar transfer services.

How this analysis was prepared

This story was surfaced by The Cyber Security Hub newsletter. Threat Field Notes checked Microsoft's roadmap entry and current Teams and Defender documentation, then wrote this independent defender response. The newsletter was used as a lead, not as the article text.