Message Center
Updated September 29, 2026: We have updated the content. Thank you for your patience.
What and why:
As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.
Scope: This change is only applicable to Outlook web (OWA) and New Outlook.
Rollout schedule:
Available now.
Impact on your organization:
Action required / Recommendations:
Appendix:
Excluding attachments from a policy
Attachment operations are handled by an application named OwaDownloadAttachments (application Id: e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64 ). Before you can exclude it from a Conditional Access policy, a service principal for it must exist in your tenant. This is a one-time step you'll need to complete first.
Step 1: Create the service principal
You'll need the Cloud Application Administrator or Global Administrator role.
POST https://graph.microsoft.com/v1.0/servicePrincipals
Request body: { "appId": "e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64" }
Consent to Application.ReadWrite.All scope is required.
A successful request returns 201 Created with a display name of OwaDownloadAttachments. If the request reports that the service principal already exists, continue to Step 2.
Step 2: Exclude it from the policy
Repeat Step 2 for each policy you want attachment operations exempted from.
What and why:
As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.
Rollout schedule:
Available now.
Impact on your organization:
Action required / Recommendations: