{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/defender-safe-attachments-precedence-delivery-testing/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
        "slug": "defender-safe-attachments-precedence-delivery-testing",
        "url": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/defender-safe-attachments-precedence-delivery-testing/"
        },
        "title": "Test Safe Attachments precedence and delivery behavior before custom rollout",
        "summary": "Defender for Office 365 Safe Attachments uses preset and custom policies with recipient filtering and priority; an apparently valid custom policy may not control users already covered by a higher-precedence preset policy.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:35:18+00:00",
        "modified_at": "2026-08-25T21:43:55+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 3,
        "word_count": 466,
        "potentially_affected": "Organizations licensed for Microsoft Defender for Office 365 and configuring Safe Attachments for Exchange Online recipients.",
        "dse_recommendation": "Map preset and custom policy precedence, select delivery behavior deliberately, test target and exception recipients, and preserve message-level evidence before expanding scope.",
        "primary_source": {
            "name": "Set up Safe Attachments policies in Microsoft Defender for Office 365",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> Safe Attachments adds virtual-environment analysis of supported attachments after antimalware scanning. The effective result depends on preset-policy membership, custom-policy priority, recipient filters, exceptions, and the selected action when analysis detects a file or cannot complete. Verify the effective policy, not merely the custom policy&#8217;s existence.</p>\n<h2>Source fact: what Microsoft documents</h2>\n<p>Microsoft&#8217;s <a href=\"https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Safe Attachments configuration guide</a> says Safe Attachments detonates files in a virtual environment to observe behavior before delivery. Microsoft documents Built-in protection, Standard and Strict preset security policies, and custom Safe Attachments policies.</p>\n<p>The source explains that preset policy membership can take precedence over custom policy targeting and exceptions. In PowerShell, a Safe Attachments policy contains the behavior settings while a separate rule contains recipient conditions, priority, and enabled state. The portal creates and manages the pair together. Microsoft documents propagation time, supported recipient filters, administrative permissions, configuration verification, and reports. It also distinguishes email Safe Attachments policy from global settings for SharePoint, OneDrive, Teams, and Safe Documents.</p>\n<h2>What the source does not establish</h2>\n<p>Safe Attachments does not guarantee detection of every malicious or novel file, and an undetected attachment is not certified safe. A portal view of a policy does not prove it applied to a particular message. Detonation can affect delivery timing and application workflows. The guide does not decide whether fail-open, fail-closed, dynamic delivery, redirect, or quarantine behavior fits an organization&#8217;s risk and continuity needs.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>Which recipients are in Built-in, Standard, Strict, or custom policies, and where do groups overlap?</li>\n<li>Which action and delivery experience is appropriate for ordinary users, executives, shared mailboxes, automated ingestion, and operational mailboxes?</li>\n<li>Which legitimate encrypted, large, uncommon, or machine-processed attachments must be tested?</li>\n<li>Who reviews detections and false positives, and what is the safe release process?</li>\n<li>Are SharePoint, OneDrive, Teams, and Safe Documents protections being assessed separately?</li>\n</ul>\n<h2>DSE recommendation: controlled next steps</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<ol>\n<li>Export or document preset and custom policy membership, custom rule priority, recipient filters, exclusions, and actions.</li>\n<li>Build an effective-policy matrix for representative recipients. Resolve unexpected overlap before changing protection.</li>\n<li>Pilot the selected action with test mailboxes and real business file types. Include delayed analysis, detection, false positive, and service-failure scenarios where safely testable.</li>\n<li>Define quarantine review, release authorization, sender and recipient communication, and escalation for business-critical attachments.</li>\n<li>Expand through controlled groups and monitor delivery latency, detection reports, quarantines, and user impact.</li>\n</ol>\n<h2>Verification and evidence</h2>\n<ul>\n<li>Preserve policy and rule configuration, preset membership, scope, priority, and change approval.</li>\n<li>Use Microsoft&#8217;s documented verification methods and message evidence to show which policy handled a test.</li>\n<li>Record benign and approved test-file outcomes without introducing live malware.</li>\n<li>Review reports and quarantine actions after rollout; investigate recipients whose effective policy differs from design.</li>\n</ul>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure\" target=\"_blank\" rel=\"noopener noreferrer\">Set up Safe Attachments policies in Microsoft Defender for Office 365</a> — Microsoft</li>\n</ul>",
        "content_text": "Bottom line: Safe Attachments adds virtual-environment analysis of supported attachments after antimalware scanning. The effective result depends on preset-policy membership, custom-policy priority, recipient filters, exceptions, and the selected action when analysis detects a file or cannot complete. Verify the effective policy, not merely the custom policy’s existence.\nSource fact: what Microsoft documents\nMicrosoft’s Safe Attachments configuration guide says Safe Attachments detonates files in a virtual environment to observe behavior before delivery. Microsoft documents Built-in protection, Standard and Strict preset security policies, and custom Safe Attachments policies.\nThe source explains that preset policy membership can take precedence over custom policy targeting and exceptions. In PowerShell, a Safe Attachments policy contains the behavior settings while a separate rule contains recipient conditions, priority, and enabled state. The portal creates and manages the pair together. Microsoft documents propagation time, supported recipient filters, administrative permissions, configuration verification, and reports. It also distinguishes email Safe Attachments policy from global settings for SharePoint, OneDrive, Teams, and Safe Documents.\nWhat the source does not establish\nSafe Attachments does not guarantee detection of every malicious or novel file, and an undetected attachment is not certified safe. A portal view of a policy does not prove it applied to a particular message. Detonation can affect delivery timing and application workflows. The guide does not decide whether fail-open, fail-closed, dynamic delivery, redirect, or quarantine behavior fits an organization’s risk and continuity needs.\nApplicability questions\n\nWhich recipients are in Built-in, Standard, Strict, or custom policies, and where do groups overlap?\nWhich action and delivery experience is appropriate for ordinary users, executives, shared mailboxes, automated ingestion, and operational mailboxes?\nWhich legitimate encrypted, large, uncommon, or machine-processed attachments must be tested?\nWho reviews detections and false positives, and what is the safe release process?\nAre SharePoint, OneDrive, Teams, and Safe Documents protections being assessed separately?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nExport or document preset and custom policy membership, custom rule priority, recipient filters, exclusions, and actions.\nBuild an effective-policy matrix for representative recipients. Resolve unexpected overlap before changing protection.\nPilot the selected action with test mailboxes and real business file types. Include delayed analysis, detection, false positive, and service-failure scenarios where safely testable.\nDefine quarantine review, release authorization, sender and recipient communication, and escalation for business-critical attachments.\nExpand through controlled groups and monitor delivery latency, detection reports, quarantines, and user impact.\n\nVerification and evidence\n\nPreserve policy and rule configuration, preset membership, scope, priority, and change approval.\nUse Microsoft’s documented verification methods and message evidence to show which policy handled a test.\nRecord benign and approved test-file outcomes without introducing live malware.\nReview reports and quarantine actions after rollout; investigate recipients whose effective policy differs from design.\n\nOfficial references\n\nSet up Safe Attachments policies in Microsoft Defender for Office 365 — Microsoft",
        "content_markdown": "Bottom line: Safe Attachments adds virtual-environment analysis of supported attachments after antimalware scanning. The effective result depends on preset-policy membership, custom-policy priority, recipient filters, exceptions, and the selected action when analysis detects a file or cannot complete. Verify the effective policy, not merely the custom policy’s existence.\n\n## Source fact: what Microsoft documents\n\nMicrosoft’s [Safe Attachments configuration guide](https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure) says Safe Attachments detonates files in a virtual environment to observe behavior before delivery. Microsoft documents Built-in protection, Standard and Strict preset security policies, and custom Safe Attachments policies.\n\nThe source explains that preset policy membership can take precedence over custom policy targeting and exceptions. In PowerShell, a Safe Attachments policy contains the behavior settings while a separate rule contains recipient conditions, priority, and enabled state. The portal creates and manages the pair together. Microsoft documents propagation time, supported recipient filters, administrative permissions, configuration verification, and reports. It also distinguishes email Safe Attachments policy from global settings for SharePoint, OneDrive, Teams, and Safe Documents.\n\n## What the source does not establish\n\nSafe Attachments does not guarantee detection of every malicious or novel file, and an undetected attachment is not certified safe. A portal view of a policy does not prove it applied to a particular message. Detonation can affect delivery timing and application workflows. The guide does not decide whether fail-open, fail-closed, dynamic delivery, redirect, or quarantine behavior fits an organization’s risk and continuity needs.\n\n## Applicability questions\n\n- Which recipients are in Built-in, Standard, Strict, or custom policies, and where do groups overlap?\n\n- Which action and delivery experience is appropriate for ordinary users, executives, shared mailboxes, automated ingestion, and operational mailboxes?\n\n- Which legitimate encrypted, large, uncommon, or machine-processed attachments must be tested?\n\n- Who reviews detections and false positives, and what is the safe release process?\n\n- Are SharePoint, OneDrive, Teams, and Safe Documents protections being assessed separately?\n\n## DSE recommendation: controlled next steps\n\nThe following steps are DSE recommendations based on the cited source.\n\n- Export or document preset and custom policy membership, custom rule priority, recipient filters, exclusions, and actions.\n\n- Build an effective-policy matrix for representative recipients. Resolve unexpected overlap before changing protection.\n\n- Pilot the selected action with test mailboxes and real business file types. Include delayed analysis, detection, false positive, and service-failure scenarios where safely testable.\n\n- Define quarantine review, release authorization, sender and recipient communication, and escalation for business-critical attachments.\n\n- Expand through controlled groups and monitor delivery latency, detection reports, quarantines, and user impact.\n\n## Verification and evidence\n\n- Preserve policy and rule configuration, preset membership, scope, priority, and change approval.\n\n- Use Microsoft’s documented verification methods and message evidence to show which policy handled a test.\n\n- Record benign and approved test-file outcomes without introducing live malware.\n\n- Review reports and quarantine actions after rollout; investigate recipients whose effective policy differs from design.\n\n## Official references\n\n- [Set up Safe Attachments policies in Microsoft Defender for Office 365](https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
                "url": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Test Safe Attachments precedence and delivery behavior before custom rollout",
                        "item": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/#article",
                "identifier": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
                "url": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/",
                "headline": "Test Safe Attachments precedence and delivery behavior before custom rollout",
                "description": "Defender for Office 365 Safe Attachments uses preset and custom policies with recipient filtering and priority; an apparently valid custom policy may…",
                "abstract": "Defender for Office 365 Safe Attachments uses preset and custom policies with recipient filtering and priority; an apparently valid custom policy may not control users already covered by a higher-precedence preset policy.",
                "articleBody": "Bottom line: Safe Attachments adds virtual-environment analysis of supported attachments after antimalware scanning. The effective result depends on preset-policy membership, custom-policy priority, recipient filters, exceptions, and the selected action when analysis detects a file or cannot complete. Verify the effective policy, not merely the custom policy’s existence.\nSource fact: what Microsoft documents\nMicrosoft’s Safe Attachments configuration guide says Safe Attachments detonates files in a virtual environment to observe behavior before delivery. Microsoft documents Built-in protection, Standard and Strict preset security policies, and custom Safe Attachments policies.\nThe source explains that preset policy membership can take precedence over custom policy targeting and exceptions. In PowerShell, a Safe Attachments policy contains the behavior settings while a separate rule contains recipient conditions, priority, and enabled state. The portal creates and manages the pair together. Microsoft documents propagation time, supported recipient filters, administrative permissions, configuration verification, and reports. It also distinguishes email Safe Attachments policy from global settings for SharePoint, OneDrive, Teams, and Safe Documents.\nWhat the source does not establish\nSafe Attachments does not guarantee detection of every malicious or novel file, and an undetected attachment is not certified safe. A portal view of a policy does not prove it applied to a particular message. Detonation can affect delivery timing and application workflows. The guide does not decide whether fail-open, fail-closed, dynamic delivery, redirect, or quarantine behavior fits an organization’s risk and continuity needs.\nApplicability questions\n\nWhich recipients are in Built-in, Standard, Strict, or custom policies, and where do groups overlap?\nWhich action and delivery experience is appropriate for ordinary users, executives, shared mailboxes, automated ingestion, and operational mailboxes?\nWhich legitimate encrypted, large, uncommon, or machine-processed attachments must be tested?\nWho reviews detections and false positives, and what is the safe release process?\nAre SharePoint, OneDrive, Teams, and Safe Documents protections being assessed separately?\n\nDSE recommendation: controlled next steps\nThe following steps are DSE recommendations based on the cited source.\n\nExport or document preset and custom policy membership, custom rule priority, recipient filters, exclusions, and actions.\nBuild an effective-policy matrix for representative recipients. Resolve unexpected overlap before changing protection.\nPilot the selected action with test mailboxes and real business file types. Include delayed analysis, detection, false positive, and service-failure scenarios where safely testable.\nDefine quarantine review, release authorization, sender and recipient communication, and escalation for business-critical attachments.\nExpand through controlled groups and monitor delivery latency, detection reports, quarantines, and user impact.\n\nVerification and evidence\n\nPreserve policy and rule configuration, preset membership, scope, priority, and change approval.\nUse Microsoft’s documented verification methods and message evidence to show which policy handled a test.\nRecord benign and approved test-file outcomes without introducing live malware.\nReview reports and quarantine actions after rollout; investigate recipients whose effective policy differs from design.\n\nOfficial references\n\nSet up Safe Attachments policies in Microsoft Defender for Office 365 — Microsoft",
                "datePublished": "2026-08-25T21:35:18+00:00",
                "dateModified": "2026-08-25T21:43:55+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/defender-safe-attachments-precedence-delivery-testing/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Test Safe Attachments precedence and delivery behavior before custom rollout"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 466,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set up Safe Attachments policies in Microsoft Defender for Office 365",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-policies-configure"
                }
            }
        ]
    }
}