Enhanced security and access controls for Outlook attachments

🚨 The Signal: Outlook attachments now enforce Conditional Access policies, blocking non-compliant users from downloading, previewing, or uploading. This enhances data protection by extending existing CA policies to attachment operations.

The Impact

All users are affected; non-compliant users face blocked attachment access, reducing data exfiltration risk.

  • End-users: May be blocked from attachments if their device or session is non-compliant.
  • Security Teams: Enhanced control over attachment access, reducing data leakage risks.
  • Admins: Existing Conditional Access policies now automatically cover attachments.
  • Organisation: Improved data security posture for email attachments.

The Action

  1. Review existing Conditional Access policies scoped to 'Exchange Online' and 'Office 365' cloud apps to understand their impact on attachment access.
  2. Communicate to users that non-compliant devices or sessions will prevent attachment interaction in Outlook.
  3. Monitor Conditional Access sign-in logs for blocks related to attachment operations to identify user impact.

Domain: Entra · Impact: high · Workload: Exchange Online · Essential Eight: Multi-Factor Authentication, User Application Hardening · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1412, ISM-1485, ISM-1486, ISM-1504, ISM-1505, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1823, ISM-1824, ISM-1859, ISM-1860, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907