Skip to Content

MC1472591 Enhanced security and access controls for Outlook attachments

Summary

Outlook attachments now have enhanced security with a separate application configuration enforcing existing Conditional Access policies from Exchange and Office apps. Non-compliant users are blocked from attachment actions. No new policies are needed. Continuous Access Evaluation and user sign-in prompts will be added later. Review policies and update support documentation.

Message ID: MC1472591
Service: Exchange Online
Category: Stay informed
Tags: New feature, Admin impact
Rollout: September 2026

Microsoft Message

As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.

Rollout schedule

Available now.

Impact on your organization

  • Your existing policies now cover attachments. Conditional Access policies you have already scoped to Exchange and Office cloud applications will be enforced for attachment scenarios as well. No new policies need to be created.
  • Users out of compliance will be blocked from attachments. If a user’s session no longer satisfies a Conditional Access policy — for example, a non-compliant device, a blocked location, or a network change that triggers CAE re-evaluation — attachment operations will be blocked.
  • Policy setup. We’re not supporting CA policies exclusive for attachments; these are expected to be shared by configuring them under the existing Exchange and Office cloud applications.
  • These are separate follow-up changes we expect to land in the upcoming weeks. We’ll keep you updated on the readiness and rollout of these enhancements:
    • User sign in prompt for remediation. We’re currently working on a solution to prompt the user for sign in to recover functionalities when possible. This will depend on the policy configuration; if the user is not compliant, they won’t be able to use attachment-related tasks. We’ll provide an update to customers once we start rolling out this enhancement.
    • Enable Continuous Access Evaluation (CAE). CAE isn’t supported for this new application configuration yet. We’ll update this message with additional content when it becomes available.

Action required / Recommendations

  1. Review the scope of your Conditional Access policies for Outlook and confirm that the access conditions you enforce are what you intend to apply to attachment scenarios.
  2. Update your help desk documentation. Support staff should know that attachment access failures may now result from a Conditional Access policy, and that the remediation is the same as for Outlook — return to a compliant device or network and re-authenticate.
  3. Notify users if you enforce strict Conditional Access policies, so they understand attachment actions may now be blocked under the same conditions that already block access to their mailbox.