Microsoft is introducing a new Microsoft 365 security control designed to deal with a long-standing problem: password-protected email attachments that Microsoft Defender cannot properly inspect.
The new Microsoft Defender for Office 365 feature can automatically quarantine emails containing password-protected files when Safe Attachments is unable to scan or detonate the content.
That includes common business file types such as password-protected PDFs, ZIP files, Microsoft Office documents and other encrypted archives.
For businesses that regularly receive protected documents from accountants, solicitors, payroll providers, suppliers or customers, this could provide an additional layer of protection against malicious attachments.
However, there is an important point to understand before assuming Microsoft has simply switched the protection on for everyone:
The feature is off by default and has to be enabled by an administrator.
Why are password-protected email attachments difficult to scan?
Password protection creates a problem for email security systems because the security service may be unable to see what is actually inside the file.
Microsoft Defender for Office 365 normally uses Safe Attachments to analyse email attachments before they reach users.
Safe Attachments provides another layer of protection beyond traditional malware scanning. Suspicious files can be opened in an isolated virtual environment — a process often called detonation — so Microsoft can observe how they behave without exposing the recipient's computer.
But if a document or archive is encrypted with a password that Defender does not know, that analysis may not be possible.
That creates an obvious security gap.
A criminal can potentially place malicious content inside a password-protected archive or document and provide the password somewhere in the email message, attempting to prevent automated security tools from examining the content properly.
Microsoft's new protection is designed to give organisations more control over what happens when Defender encounters that situation.
What is Microsoft changing?
Microsoft is adding a new opt-in setting within Safe Attachments policies.
When enabled, Microsoft Defender for Office 365 can quarantine an email if it contains a password-protected attachment that Defender cannot successfully scan or detonate.
The idea is simple:
- An email arrives with a password-protected attachment.
- Microsoft Defender attempts to analyse the file.
- If Defender cannot access the content and therefore cannot complete its security analysis, the configured policy can place the message into quarantine.
- The attachment can then go through a controlled release process rather than being delivered directly to the user's inbox.
This does not mean Microsoft is blocking every encrypted document.
It gives Microsoft 365 administrators the option to decide whether unscannable password-protected attachments should be quarantined rather than automatically delivered.
Which attachment types are supported?
Microsoft currently lists support for several commonly used encrypted file formats, including:
- ZIP
- GZIP
- 7z
- RAR
- Microsoft Office file formats
Administrators can also exclude selected file categories where there is a legitimate business requirement to do so.
What happens if a legitimate attachment is quarantined?
This is where Microsoft's implementation becomes particularly useful.
Businesses often receive perfectly legitimate password-protected files.
An accountant might send payroll information in an encrypted ZIP file. A solicitor may send a protected document. A financial organisation might issue a password-protected PDF.
Microsoft therefore isn't treating every protected attachment as malicious.
Instead, eligible users can be allowed to release the quarantined message by supplying the password for the attachment.
Microsoft Defender can then perform a just-in-time security analysis of the attachment before it is released.
Security administrators can also release quarantined messages without needing the attachment password, depending on how the organisation has configured its quarantine policies.
Users need to understand what password Microsoft is asking for
There is an important security training point here.
If employees are allowed to release these messages themselves, they need to understand that Microsoft is asking specifically for the password used to unlock the attachment.
They should never enter:
- Their Microsoft 365 password
- Their computer login password
- Banking credentials
- Any unrelated account password
Users should also only release protected attachments that they were expecting and where they recognise and trust the sender.
An unexpected password-protected attachment should still be treated cautiously, even if the email appears to come from a known organisation.
Which Microsoft 365 customers can use this protection?
The new capability forms part of Microsoft Defender for Office 365 Safe Attachments.
Safe Attachments is available with Microsoft Defender for Office 365 Plan 1 and Plan 2.
For SMEs, one of the most relevant licences is Microsoft 365 Business Premium, because Microsoft Defender for Office 365 Plan 1 is already included with Business Premium.
That means many organisations may already have the necessary licensing without realising that this additional email-security capability is available to them.
If you're currently using Business Basic or Business Standard and are considering whether Business Premium's additional security capabilities would benefit your organisation, see our comparison of Microsoft 365 Business Basic vs Standard vs Premium.
You can also read more about the additional security and device-management features included in Microsoft 365 Business Premium.
Are You Getting the Security You've Already Paid For?
Microsoft 365 includes powerful security controls, but having the licence doesn't automatically mean those protections are configured correctly. KES can review your Microsoft 365 environment and identify security gaps, unnecessary risk and settings that should be improved.
Microsoft continually adds new security features. Unless someone is reviewing and managing those settings, useful protections can remain disabled or incorrectly configured.
Learn about Microsoft 365 Security Hardening →Is the new Microsoft 365 attachment protection worth enabling?
For many businesses using Microsoft Defender for Office 365, the answer is likely to be yes — but after testing it properly.
Password-protected attachments create a genuine challenge for automated email security because Defender may not be able to inspect what is inside them.
Giving organisations the option to quarantine those messages rather than delivering unscanned content directly to users adds another useful layer of control.
The ability to release legitimate documents after supplying the attachment password also means the protection doesn't have to prevent businesses from exchanging encrypted information.
But like many Microsoft 365 security features, the value depends on how it is configured.
Businesses should understand their existing email workflows, review their Defender policies, decide appropriate quarantine permissions and make sure employees know how to respond when a protected attachment is held.
If you are unsure whether Microsoft Defender, Safe Attachments and the other security features within your Microsoft 365 environment are configured appropriately, our Microsoft 365 Security Assessment can identify where improvements may be needed.