Safe Attachments - Microsoft Defender for Office 365 (original) (raw)

Safe Attachments in Microsoft Defender for Office 365 provides an additional layer of protection for email attachments that have already been scanned by Anti-malware protection. Specifically, Safe Attachments uses a virtual environment to check attachments in email messages for harmful attachments (for example, malware, ransomware, and phishing) before they're delivered to recipients (a process known as detonation).

Tip

Typically, email attachment scanning completes within 15 minutes. Sometimes, it takes longer due to retry delays and processing time to analyze the file in the virtual environment.

Safe Attachments protection for email messages is controlled by Safe Attachments policies. Although there's no default Safe Attachments policy, the Built-in protection preset security policy provides Safe Attachments protection to all recipients (users who aren't defined in the Standard or Strict preset security policies or in custom Safe Attachments policies). For more information, see Preset security policies. You can also create Safe Attachments policies that apply to specific users, group, or domains. For instructions, see Set up Safe Attachments policies in Microsoft Defender for Office 365.

The following table describes scenarios for Safe Attachments in Microsoft 365 and Office 365 organizations that include Microsoft Defender for Office 365 (in other words, lack of licensing is never an issue in the examples).

Scenario Result
Pat's Microsoft 365 E5 organization has no Safe Attachments policies configured. Pat is protected by Safe Attachments due to the Built-in protection preset security policy that applies to all recipients who aren't otherwise defined in Safe Attachments policies.
Lee's organization has a Safe Attachments policy that applies only to finance employees. Lee is a member of the sales department. Lee and the rest of the sales department are protected by Safe Attachments due to the Built-in protection preset security policy that applies to all recipients who aren't otherwise defined in Safe Attachments policies.
Yesterday, an admin in Jean's organization created a Safe Attachments policy that applies to all employees. Earlier today, Jean received an email message that included an attachment. Jean is protected by Safe Attachments due to that custom Safe Attachments policy. Typically, it takes about 30 minutes for a new policy to take effect.
Chris's organization has long-standing Safe Attachments policies for everyone in the organization. Chris receives an email that has an attachment, and then forwards the message to external recipients. Chris is protected by Safe Attachments. If the external recipients are in a Microsoft 365 organization, then the forwarded messages are also protected by Safe Attachments.

Safe Attachments scanning takes place in the same region where your Microsoft 365 data resides. For more information about datacenter geography, see Where is your data located?

Safe Attachments policy settings

This section describes the settings in Safe Attachments policies:

Dynamic Delivery in Safe Attachments policies

Note

Dynamic Delivery works only for Exchange Online mailboxes.

The Dynamic Delivery action in Safe Attachments policies seeks to eliminate any email delivery delays that might be caused by Safe Attachments scanning. The body of the email message is delivered to the recipient with a placeholder for each attachment. The placeholder remains until the attachment is found to be safe, and then the attachment becomes available to open or download.

If an attachment is found to be malicious, the message is quarantined.

Most PDFs and Office documents can be previewed in safe mode while Safe Attachments scanning is underway. If an attachment is not compatible with the Dynamic Delivery previewer, the recipients see a placeholder for the attachment until Safe Attachments scanning is complete.

If you're using a mobile device, and PDFs aren't rendering in the Dynamic Delivery previewer on your mobile device, try opening the message in Outlook on the web (formerly known as Outlook Web App) using your mobile browser.

Here are some considerations for Dynamic Delivery and forwarded messages:

There are scenarios where Dynamic Delivery is unable to replace attachments in messages. These scenarios include:

Submit files for analysis