Message Center
Microsoft Defender for Office 365 will introduce an opt-in Safe Attachments policy to quarantine emails with password-protected attachments that cannot be scanned. Administrators can control release, users can self-release with passwords, and the feature supports various file types. Rollout begins August 2026 worldwide.
What and Why:
Organizations commonly use encrypted or password-protected attachments to securely share sensitive information through email. However, when Microsoft Defender for Office 365 cannot obtain the attachment password during scanning or detonation, the content cannot be fully analyzed for threats.
To help organizations reduce risk from unscanned content, Microsoft is introducing a new opt-in setting in Safe Attachments policies. This setting allows administrators to automatically quarantine email messages that contain password-protected attachments when Microsoft Defender for Office 365 cannot complete scanning or detonation. This enhancement provides administrators with greater control over potentially risky content while preserving business workflows through controlled release options.
Rollout Schedule:
Impact on Your Organization:
Who is affected:
Platforms/Services:
What will happen:
Important:








SecOps teams:
EmailAttachmentInfo
| where AdditionalFields contains "IsPasswordProtectedItem"
Action Required/Recommendations:
No action is required unless you want to use this capability.
Compliance considerations:
The change modifies how password-protected email attachments may be processed and accessed when organizations enable the feature. Administrators gain new controls through Safe Attachments policies and can identify affected content using Advanced Hunting. No other compliance considerations were identified.