Microsoft Defender can quarantine emails with unscannable attachments

Microsoft is introducing a new opt-in setting within Safe Attachments policies that allows administrators to automatically quarantine email messages containing password-protected attachments when Defender for Office 365 is unable to obtain the password and therefore cannot complete scanning or detonation.
Password-protected and encrypted attachments are commonly used for legitimate business purposes, but they also prevent full threat analysis, leaving a coverage gap that this enhancement is designed to close.

Block unscanned attachments is off by default and must be explicitly enabled by administrators. A Defender for Office 365 Plan 1 or Plan 2 is required.
Administrators find the new option at the end of Safe Attachments policies and can exclude selected attachment types from the setting if needed. Supported attachment types for this protection include ZIP, GZIP, 7z, RAR, PDF, and Office file formats.

New option to quarantine unscanned attachments automatically
New option to quarantine unscanned attachments automatically

Organizations that want to test the setting before broad adoption can pilot it using a separate, scoped Safe Attachments policy rather than applying it tenant-wide immediately. Once enabled, messages containing unscannable password-protected attachments are quarantined.

Email with a password-protected attachment quarantined
Email with a password-protected attachment quarantined

Releasing such mails from quarantine can happen in two ways:

  1. Users can self-release eligible messages by providing the attachment password (if allowed by the quarantine policy), which triggers a just-in-time detonation before release.
Providing the attachment password releases the mail from quarantine
Providing the attachment password releases the mail from quarantine
  1. Security administrators can release quarantined messages directly, without needing the password.

The rollout for blocking unscanned attachments should be completed between August and October 2026.

More information

Avatar photo

Tobias Asböck

Tobias is a Senior System Engineer with more than 10 years of professional experience with Microsoft 365 products such as SharePoint Online, SharePoint Premium, OneDrive for Business, Teams Collaboration, Entra ID, Information Protection, Universal Print, and Microsoft 365 Licensing. He also has 15+ years of experience planning, administering, and operating SharePoint Server environments. Tobias is a PowerShell Scripter with certifications for Microsoft 365 products. In his spare time, Tobias is busy with updates in the Microsoft 365 world or on the road with his road bike and other sports activities. If you have additional questions, please contact me via LinkedIn or [email protected].

Leave a Comment