{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
        "slug": "dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/"
        },
        "title": "Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine",
        "summary": "What happens when a user supplies an attachment password for a quarantined Password protected item?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:00+00:00",
        "modified_at": "2026-09-10T02:11:18+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 247,
        "potentially_affected": "Cloud mailbox recipients offered the documented release workflow for Safe Attachments Password protected item quarantine.",
        "dse_recommendation": "Have the recipient validate an expected sender and use only the attachment password in the documented portal workflow.",
        "primary_source": {
            "name": "Find and release quarantined messages as a user - Microsoft Defender for Office 365 | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For a quarantined Password protected item, Defender for Office 365 uses the supplied attachment password to rescan before release; it does not retain the password. A malicious attachment or one that remains unscannable stays quarantined for administrator review. Multiple protected attachments must share the same password. This release requires the portal rather than direct release from a notification email, and user release authority still depends on the quarantine policy. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>This is the documented encrypted-attachment quarantine path, not a reason to approve an unexpected message. Microsoft warns users to provide only the attachment password, never unrelated account credentials, and to escalate unexpected protected messages. <a href=\"https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>DSE recommendation</h2>\n<p>Have the recipient validate an expected sender and use only the attachment password in the documented portal workflow. Prepare help-desk guidance that distinguishes an attachment secret from a sign-in credential. Do not instruct users to work around the quarantine or treat possession of a password as proof that the file is harmless. Route unavailable release actions or unsuccessful rescans to the authorized mail-security reviewer.</p>\n<h2>Verification</h2>\n<p>Use an approved benign protected attachment to rehearse the recipient experience where policy permits it. Record the quarantine reason, available action and resulting status without recording the password. Confirm the support instructions send the recipient to the portal and preserve administrator review when scanning cannot complete. State the observed outcome accurately rather than promising release simply because a password was entered.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: User quarantine management</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nFor a quarantined Password protected item, Defender for Office 365 uses the supplied attachment password to rescan before release; it does not retain the password. A malicious attachment or one that remains unscannable stays quarantined for administrator review. Multiple protected attachments must share the same password. This release requires the portal rather than direct release from a notification email, and user release authority still depends on the quarantine policy. Microsoft Learn.\nApplicability\nThis is the documented encrypted-attachment quarantine path, not a reason to approve an unexpected message. Microsoft warns users to provide only the attachment password, never unrelated account credentials, and to escalate unexpected protected messages. Microsoft Learn.\nDSE recommendation\nHave the recipient validate an expected sender and use only the attachment password in the documented portal workflow. Prepare help-desk guidance that distinguishes an attachment secret from a sign-in credential. Do not instruct users to work around the quarantine or treat possession of a password as proof that the file is harmless. Route unavailable release actions or unsuccessful rescans to the authorized mail-security reviewer.\nVerification\nUse an approved benign protected attachment to rehearse the recipient experience where policy permits it. Record the quarantine reason, available action and resulting status without recording the password. Confirm the support instructions send the recipient to the portal and preserve administrator review when scanning cannot complete. State the observed outcome accurately rather than promising release simply because a password was entered.\nOfficial references\nMicrosoft Learn: User quarantine management. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nFor a quarantined Password protected item, Defender for Office 365 uses the supplied attachment password to rescan before release; it does not retain the password. A malicious attachment or one that remains unscannable stays quarantined for administrator review. Multiple protected attachments must share the same password. This release requires the portal rather than direct release from a notification email, and user release authority still depends on the quarantine policy. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user).\n\n## Applicability\n\nThis is the documented encrypted-attachment quarantine path, not a reason to approve an unexpected message. Microsoft warns users to provide only the attachment password, never unrelated account credentials, and to escalate unexpected protected messages. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user).\n\n## DSE recommendation\n\nHave the recipient validate an expected sender and use only the attachment password in the documented portal workflow. Prepare help-desk guidance that distinguishes an attachment secret from a sign-in credential. Do not instruct users to work around the quarantine or treat possession of a password as proof that the file is harmless. Route unavailable release actions or unsuccessful rescans to the authorized mail-security reviewer.\n\n## Verification\n\nUse an approved benign protected attachment to rehearse the recipient experience where policy permits it. Record the quarantine reason, available action and resulting status without recording the password. Confirm the support instructions send the recipient to the portal and preserve administrator review when scanning cannot complete. State the observed outcome accurately rather than promising release simply because a password was entered.\n\n## Official references\n\n[Microsoft Learn: User quarantine management](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/",
                "headline": "Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine",
                "description": "What happens when a user supplies an attachment password for a quarantined Password protected item?",
                "abstract": "What happens when a user supplies an attachment password for a quarantined Password protected item?",
                "articleBody": "Source facts\nFor a quarantined Password protected item, Defender for Office 365 uses the supplied attachment password to rescan before release; it does not retain the password. A malicious attachment or one that remains unscannable stays quarantined for administrator review. Multiple protected attachments must share the same password. This release requires the portal rather than direct release from a notification email, and user release authority still depends on the quarantine policy. Microsoft Learn.\nApplicability\nThis is the documented encrypted-attachment quarantine path, not a reason to approve an unexpected message. Microsoft warns users to provide only the attachment password, never unrelated account credentials, and to escalate unexpected protected messages. Microsoft Learn.\nDSE recommendation\nHave the recipient validate an expected sender and use only the attachment password in the documented portal workflow. Prepare help-desk guidance that distinguishes an attachment secret from a sign-in credential. Do not instruct users to work around the quarantine or treat possession of a password as proof that the file is harmless. Route unavailable release actions or unsuccessful rescans to the authorized mail-security reviewer.\nVerification\nUse an approved benign protected attachment to rehearse the recipient experience where policy permits it. Record the quarantine reason, available action and resulting status without recording the password. Confirm the support instructions send the recipient to the portal and preserve administrator review when scanning cannot complete. State the observed outcome accurately rather than promising release simply because a password was entered.\nOfficial references\nMicrosoft Learn: User quarantine management. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:23:00+00:00",
                "dateModified": "2026-09-10T02:11:18+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 247,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Find and release quarantined messages as a user - Microsoft Defender for Office 365 | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user"
                }
            }
        ]
    }
}