MC1440701: Microsoft Defender for Office 365 Adds Safe Attachments Setting to Quarantine Unscannable Password-Protected Files

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
54
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This is an optional security enhancement that introduces new controls in Safe Attachments policies for handling password-protected attachments. Admins who choose to enable it will need to review and adjust policies, pilot configurations, update documentation, and educate users on release behaviour. Users see minimal direct impact unless quarantined messages occur, but support processes and security operations will need updates and training. Urgency is moderate due to the opt-in nature and the security implications for unscanned files.
65
🛡️ Admin Impact
30
👥 User Impact
55
Urgency
50
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

A new Safe Attachments setting lets you quarantine emails when password-protected files can’t be scanned. It helps reduce risk from unscanned attachments.
👥

END USERS

Users may see password-protected emails held in quarantine and can release them by entering the password.
🛡️

IT ADMINS

Review Safe Attachments policies, consider piloting the feature, update documentation, and inform users and support teams.
📅

ROLLOUT TIMELINE

Upcoming:
August 2026

📢 Official Microsoft Message Center Announcement


MDO Encrypted email attachment protection
Message ID: MC1440701

What and Why:

Organizations commonly use encrypted or password-protected attachments to securely share sensitive information through email. However, when Microsoft Defender for Office 365 cannot obtain the attachment password during scanning or detonation, the content cannot be fully analyzed for threats.

To help organizations reduce risk from unscanned content, Microsoft is introducing a new opt-in setting in Safe Attachments policies. This setting allows administrators to automatically quarantine email messages that contain password-protected attachments when Microsoft Defender for Office 365 cannot complete scanning or detonation. This enhancement provides administrators with greater control over potentially risky content while preserving business workflows through controlled release options.

Rollout Schedule:

  • Worldwide: Early August 2026 through Late August 2026
  • GCC: Late August 2026 through Late September 2026
  • GCC High: Late August 2026 through Late October 2026
  • DoD: Late August 2026 through Late October 2026

Impact on Your Organization:

Who is affected:

  • Administrators managing Safe Attachments policies.
  • Security operations teams responsible for quarantine management.
  • Users who receive password-protected email attachments.

Platforms/Services:

  • Microsoft Defender for Office 365
  • Safe Attachments
  • Quarantine
  • Advanced Hunting
  • Exchange Online

What will happen:

  • This feature is off by default and requires administrator opt-in.
  • Administrators can configure Safe Attachments policies to quarantine messages when password-protected content cannot be scanned or detonated.
  • Organizations can pilot the feature using a separate scoped Safe Attachments policy.
  • Users can self-release eligible messages by providing the attachment password. A just-in-time detonation is performed before release.
  • Security administrators can release quarantined messages without requiring the attachment password.
  • Supported file categories include ZIP, GZIP, 7z, RAR, PDF, and Microsoft Office file formats.
  • Selected file categories can be excluded from protection.

Important:

  • Users should only enter the attachment password.
  • Users should never enter account credentials, banking passwords, or unrelated passwords.
  • Users should only release expected messages from validated senders.
  • Unexpected protected email messages should be escalated to SecOps.

21287 1

21287 2

21287 3

21287 4

21287 5

21287 6

21287 7

21287 8

SecOps teams:

EmailAttachmentInfo | where AdditionalFields contains "IsPasswordProtectedItem"

Action Required/Recommendations:

No action is required unless you want to use this capability.

Compliance considerations:

The change modifies how password-protected email attachments may be processed and accessed when organizations enable the feature. Administrators gain new controls through Safe Attachments policies and can identify affected content using Advanced Hunting. No other compliance considerations were identified.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update