MDO Encrypted email attachment protection
Microsoft Defender for Office 365 will introduce an opt-in Safe Attachments policy to quarantine emails with password-protected attachments that cannot be scanned. Administrators can control release, users can self-release with passwords, and the feature supports various file types. Rollout begins August 2026 worldwide. What and Why: Organizations commonly use encrypted or password-protected attachments to securely share sensitive information through email. However, when Microsoft Defender for Office 365 cannot obtain the attachment password during scanning or detonation, the content cannot be fully analyzed for threats. To help organizations reduce risk from unscanned content, Microsoft is introducing a new opt-in setting in Safe Attachments policies. This setting allows administrators to automatically quarantine email messages that contain password-protected attachments when Microsoft Defender for Office 365 cannot complete scanning or detonation. This enhancement provides administrators with greater control over potentially risky content while preserving business workflows through controlled release options. Rollout Schedule: Worldwide: Early August 2026 through Late August 2026 GCC: Late August 2026 through Late September 2026 GCC High: Late August 2026 through Late October 2026 DoD: Late August 2026 through Late October 2026 Impact on Your Organization: Who is affected: Administrators managing Safe Attachments policies. Security operations teams responsible for quarantine management. Users who receive password-protected email attachments. Platforms/Services: Microsoft Defender for Office 365 Safe Attachments Quarantine Advanced Hunting Exchange Online What will happen: This feature is off by default and requires administrator opt-in. Administrators can configure Safe Attachments policies to quarantine messages when password-protected content cannot be scanned or detonated. Organizations can pilot the feature using a separate scoped Safe Attachments policy. Users can self-release eligible messages by providing the attachment password. A just-in-time detonation is performed before release. Security administrators can release quarantined messages without requiring the attachment password. Supported file categories include ZIP, GZIP, 7z, RAR, PDF, and Microsoft Office file formats. Selected file categories can be excluded from protection. Important: Users should only enter the attachment password. Users should never enter account credentials, banking passwords, or unrelated passwords. Users should only release expected messages from validated senders. Unexpected protected email messages should be escalated to SecOps. View image […]
The post MDO Encrypted email attachment protection appeared first on M365 Admin.
Published on:
Learn moreWe can help you with MDO Encrypted email attachment protection
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Excel: Excel canvas
Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...
Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads
We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...
Microsoft Outlook: Right-click to customize the classic ribbon
Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...
Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs
Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...
Microsoft Entra App Gallery: Self-service onboarding for new applications
Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...
Upgraded call history in Teams Calls app
Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...
Power Automate – Enable Process Intelligence Studio in object-centric process mining
We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...
Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities
We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...
Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center
The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...
Microsoft Teams: Start side conversations during meetings
Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...