Summary
Details
[What and why:]
As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.
[Rollout schedule:]
Available now.
[Impact on your organization:]
- Your existing policies now cover attachments. Conditional Access policies you have already scoped to Exchange and Office cloud applications will be enforced for attachment scenarios as well. No new policies need to be created.
- Users out of compliance will be blocked from attachments. If a user's session no longer satisfies a Conditional Access policy — for example, a non-compliant device, a blocked location, or a network change that triggers CAE re-evaluation — attachment operations will be blocked.
- Policy setup. We’re not supporting CA policies exclusive for attachments; these are expected to be shared by configuring them under the existing Exchange and Office cloud applications.
- These are separate follow-up changes we expect to land in the upcoming weeks. We’ll keep you updated on the readiness and rollout of these enhancements:
- User sign in prompt for remediation. We're currently working on a solution to prompt the user for sign in to recover functionalities when possible. This will depend on the policy configuration; if the user is not compliant, they won’t be able to use attachment-related tasks. We’ll provide an update to customers once we start rolling out this enhancement.
- Enable Continuous Access Evaluation (CAE). CAE isn’t supported for this new application configuration yet. We’ll update this message with additional content when it becomes available.
[Action required / Recommendations:]
- Review the scope of your Conditional Access policies for Outlook and confirm that the access conditions you enforce are what you intend to apply to attachment scenarios.
- Update your help desk documentation. Support staff should know that attachment access failures may now result from a Conditional Access policy, and that the remediation is the same as for Outlook — return to a compliant device or network and re-authenticate.
- Notify users if you enforce strict Conditional Access policies, so they understand attachment actions may now be blocked under the same conditions that already block access to their mailbox.
Change History
Never Miss a Microsoft 365 Update
Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.