Microsoft is now applying existing Conditional Access rules directly to Outlook attachment actions. If a user or device does not satisfy the organisation’s policies, Outlook may block the preview, download or upload of an attachment — including inline images. This does not necessarily mean Outlook is broken or Microsoft 365 is experiencing an outage.
The change is available now and requires no new policy to be created. That is useful for security, but it also means an existing policy can begin affecting attachment handling in a way users and support teams were not expecting.
What has Microsoft changed?
Microsoft has created a separate internal application configuration for Outlook attachments. According to Microsoft 365 Message Center notice MC1472591, the Conditional Access policies already assigned to Exchange and Office cloud applications are inherited by this attachment service.
Microsoft says users who do not meet those policies can be prevented from downloading, previewing or uploading traditional file attachments. The rule also covers inline images placed inside an email.
No separate “attachments policy” is available. Administrators continue to manage the relevant rules through the existing Exchange and Office cloud application assignments.
When is the Outlook attachment change happening?
Microsoft describes the initial change as available now. It was announced to Microsoft 365 administrators on 15 September 2026.
Two related parts are not included in the initial release:
- Continuous Access Evaluation support for the new attachment application configuration is due later.
- A sign-in prompt to help users recover access is also planned for a future update.
Until those improvements arrive, the reason for a blocked attachment may not be particularly obvious to the person using Outlook.
Who could be affected?
The change matters to organisations that use Microsoft Entra Conditional Access policies scoped to Exchange Online or Office 365. Microsoft 365 Business Premium includes the Conditional Access capability used by many SMEs to require compliant devices, trusted access conditions or stronger authentication.
It may affect:
- employees using an unmanaged or non-compliant computer;
- users connecting from a location or network blocked by company policy;
- people whose device has fallen out of compliance;
- contractors or temporary workers with restricted access;
- users whose session no longer meets an existing access rule.
Businesses using Microsoft 365 Business Basic or Standard without the necessary Entra licensing may not have Conditional Access configured. Security Defaults are different and should not be confused with a custom Conditional Access deployment.
What will users notice in Outlook?
A user may be able to see an email but find that its attachment will not open, preview, download or upload. An image embedded in a message may also fail because Microsoft treats inline images as part of the attachment operation.
The exact experience depends on the Outlook client, the policy and the access condition that failed. Microsoft’s public guidance already explains how organisations can limit Outlook attachment access on unmanaged devices.
The important support distinction is that an attachment block can now be an intentional security decision. Reinstalling Outlook, clearing the browser cache or repeatedly downloading the file will not correct a device-compliance or location-policy failure.
A realistic small-business example
An employee usually works on a company-managed laptop. One evening, they open Outlook on the web from a personal computer to retrieve a spreadsheet sent by a customer. They can read the message, but the attachment will not preview or download.
From the employee’s perspective, “Outlook attachments are broken”. In reality, the personal computer does not meet the company’s Conditional Access requirements. The policy is doing what the business intended: allowing limited access to email while preventing company files from being downloaded to an unmanaged device.
The correct response is to use the managed work computer or follow the organisation’s approved access process — not to weaken the policy simply to remove the error.
Why does this matter to a UK SME?
Email attachments routinely contain customer records, quotations, accounts information and commercially sensitive documents. Applying access rules to the file action can reduce the chance of that information being copied onto an unmanaged or risky device.
The operational risk is poor preparation. If nobody has reviewed the policies or briefed the support team, legitimate users may lose access to attachments and the issue may be misdiagnosed as an Outlook fault.
Conditional Access is powerful precisely because it can block access automatically. It should therefore be reviewed as part of wider Microsoft 365 security hardening, with clear ownership, exclusions and support procedures.
What should Microsoft 365 administrators check?
- Review policy scope. Confirm which Conditional Access policies target Exchange Online, Office 365 or all cloud resources.
- Check the intended conditions. Review device compliance, location, authentication strength and client-app requirements.
- Test realistic scenarios. Check attachment preview, download and upload from managed and unmanaged devices using the Outlook clients your staff actually use.
- Review Entra sign-in logs. When an attachment is blocked, identify which policy was applied and which requirement failed.
- Update helpdesk guidance. Staff should know that attachment failures may be caused by Conditional Access rather than an Outlook outage.
- Keep emergency access accounts protected. Follow Microsoft’s recommendation to exclude properly controlled break-glass accounts from policies that could lock administrators out.
- Use report-only mode for new rules. Microsoft recommends testing policy impact before enforcement. Its report-only guidance explains how results appear in sign-in logs.
Do not disable a policy just because one user cannot retrieve a file. First establish whether the block is intended, whether the device should be compliant and whether a narrowly scoped correction is appropriate.
Microsoft 365 security and access
Are Outlook attachments being blocked unexpectedly?
KES can review your Conditional Access policies, check the affected sign-in and establish whether the block is intentional or the result of an incorrect configuration.
- Conditional Access policy review
- Managed and unmanaged device testing
- Microsoft Entra sign-in investigation
- Clear recommendations without weakening security
Need help with a live Outlook problem?
Tell us what the user sees, which device they are using and when the problem started.
Contact KES →What happens if the business does nothing?
Where the existing policies are correct, doing nothing may simply leave users surprised by a security control that is working as designed. That still creates avoidable support calls and lost time.
Where a policy is incorrectly scoped, attachment access could be blocked for legitimate staff, contractors or devices. The business may then face pressure to disable a useful protection urgently, without understanding the consequences.
The safer approach is to review the current policies, test common working arrangements and give users a clear route for resolving device-compliance or access problems.
Does this mean Outlook itself is faulty?
Not necessarily. If email opens but an attachment action is blocked, Conditional Access should now be included in the investigation. Administrators can use Microsoft Entra sign-in information to determine whether a policy applied.
Ordinary Outlook problems still occur, so the policy is not automatically the cause of every attachment error. The timing, affected users, device state and sign-in logs should be considered together.
Should businesses remove Conditional Access restrictions?
Usually not. A restriction may be preventing business information from reaching an unmanaged device or untrusted location. Correct an unintended policy configuration where necessary, but do not trade away security simply to make the symptom disappear.
Does Microsoft 365 Business Premium include Conditional Access?
Yes. Microsoft identifies Microsoft 365 Business Premium as an eligible licence for Conditional Access features. Businesses still need appropriate policies, device management and testing; the licence alone does not guarantee a suitable configuration. See Microsoft’s Conditional Access prerequisites and managed-policy guidance.
The practical next step
Ask whoever manages your Microsoft 365 tenant to review Conditional Access policies assigned to Exchange and Office applications, then test attachment handling from both a managed work device and a typical unmanaged device.
If the organisation does not know which policies are active, that is the first issue to correct. Our guide to securing Microsoft 365 accounts before compromise explains the wider controls that should sit around access decisions.
For help reviewing the configuration or diagnosing a live attachment problem, contact KES.