Changes › MC1472591

Enhanced security and access controls for Outlook attachments

Exchange Online Stay informed
Published
15 Sep 2026
Last modified
15 Sep 2026 23:00 UTC
Act by
Ends
23 Nov 2026
First archived
16 Sep 2026
Revisions
1
Tags
New featureAdmin impact

Full post

What and why

As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.

Rollout schedule

Available now.

Impact on your organization

  • Your existing policies now cover attachments. Conditional Access policies you have already scoped to Exchange and Office cloud applications will be enforced for attachment scenarios as well. No new policies need to be created.
  • Users out of compliance will be blocked from attachments. If a user's session no longer satisfies a Conditional Access policy — for example, a non-compliant device, a blocked location, or a network change that triggers CAE re-evaluation — attachment operations will be blocked.
  • Policy setup. We’re not supporting CA policies exclusive for attachments; these are expected to be shared by configuring them under the existing Exchange and Office cloud applications.
  • These are separate follow-up changes we expect to land in the upcoming weeks. We’ll keep you updated on the readiness and rollout of these enhancements:
    • User sign in prompt for remediation. We're currently working on a solution to prompt the user for sign in to recover functionalities when possible. This will depend on the policy configuration; if the user is not compliant, they won’t be able to use attachment-related tasks. We’ll provide an update to customers once we start rolling out this enhancement.
    • Enable Continuous Access Evaluation (CAE). CAE isn’t supported for this new application configuration yet. We’ll update this message with additional content when it becomes available.  

Action required / Recommendations

  1. Review the scope of your Conditional Access policies for Outlook and confirm that the access conditions you enforce are what you intend to apply to attachment scenarios.
  2. Update your help desk documentation. Support staff should know that attachment access failures may now result from a Conditional Access policy, and that the remediation is the same as for Outlook — return to a compliant device or network and re-authenticate.
  3. Notify users if you enforce strict Conditional Access policies, so they understand attachment actions may now be blocked under the same conditions that already block access to their mailbox.

Related messages

Discussion

No messages yet — start the thread.

Sign in with your email to join the discussion — we send a one-time link, no password.

© Microsoft — archived from the Microsoft 365 Message Center. Content notice