{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
        "slug": "dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/"
        },
        "title": "Investigate OWA PDF preview failures without removing the download block",
        "summary": "Why can a Cloud Apps download-blocking policy also prevent an Outlook on the web PDF preview?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:10+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 268,
        "potentially_affected": "Outlook on the web sessions where Defender for Cloud Apps session policy blocks downloads.",
        "dse_recommendation": "Check the user's effective OWA mailbox policy before weakening the Cloud Apps download restriction.",
        "primary_source": {
            "name": "Troubleshooting access and session controls for end-users - Microsoft Defender for Cloud Apps | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Some PDF preview or print operations initiate a file download, which can trigger Defender for Cloud Apps download blocking. For Outlook on the web, Microsoft&#8217;s documented adjustment disables direct file access on both private and public computers in the applicable OWA mailbox policy. Its expected test result removes the Download option while allowing preview. Custom or additional OWA policies may apply to particular users, so changing only the default policy may not cover them. <a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this branch for an OWA PDF-preview symptom under an identified download-blocking session policy. Determine the user&#8217;s effective mailbox policy and preserve the original settings. Do not generalize this Exchange-specific adjustment to every application that renders PDFs or every blocked-file event.</p>\n<h2>DSE recommendation</h2>\n<p>Check the user&#8217;s effective OWA mailbox policy before weakening the Cloud Apps download restriction. Have the Exchange and security owners agree which users need preview and which download restriction must remain. Review the documented direct-file-access parameters and their intended scope in a test policy. Prepare the prior configuration for recovery and communicate the expected user experience before applying any production change.</p>\n<h2>Verification</h2>\n<p>With a non-sensitive PDF and the download-blocking session policy still active, test preview for a representative affected user. Confirm both the preview result and the absence of the prohibited Download option. Repeat against any distinct OWA policy assignments in scope rather than assuming the default represents all users. Retain the effective policies and observed results, and investigate other failure causes if the documented combination does not produce the expected behavior.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Troubleshooting access and session controls for end-users</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nSome PDF preview or print operations initiate a file download, which can trigger Defender for Cloud Apps download blocking. For Outlook on the web, Microsoft’s documented adjustment disables direct file access on both private and public computers in the applicable OWA mailbox policy. Its expected test result removes the Download option while allowing preview. Custom or additional OWA policies may apply to particular users, so changing only the default policy may not cover them. Microsoft Learn.\nApplicability\nUse this branch for an OWA PDF-preview symptom under an identified download-blocking session policy. Determine the user’s effective mailbox policy and preserve the original settings. Do not generalize this Exchange-specific adjustment to every application that renders PDFs or every blocked-file event.\nDSE recommendation\nCheck the user’s effective OWA mailbox policy before weakening the Cloud Apps download restriction. Have the Exchange and security owners agree which users need preview and which download restriction must remain. Review the documented direct-file-access parameters and their intended scope in a test policy. Prepare the prior configuration for recovery and communicate the expected user experience before applying any production change.\nVerification\nWith a non-sensitive PDF and the download-blocking session policy still active, test preview for a representative affected user. Confirm both the preview result and the absence of the prohibited Download option. Repeat against any distinct OWA policy assignments in scope rather than assuming the default represents all users. Retain the effective policies and observed results, and investigate other failure causes if the documented combination does not produce the expected behavior.\nOfficial references\nMicrosoft Learn: Troubleshooting access and session controls for end-users. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nSome PDF preview or print operations initiate a file download, which can trigger Defender for Cloud Apps download blocking. For Outlook on the web, Microsoft’s documented adjustment disables direct file access on both private and public computers in the applicable OWA mailbox policy. Its expected test result removes the Download option while allowing preview. Custom or additional OWA policies may apply to particular users, so changing only the default policy may not cover them. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users).\n\n## Applicability\n\nUse this branch for an OWA PDF-preview symptom under an identified download-blocking session policy. Determine the user’s effective mailbox policy and preserve the original settings. Do not generalize this Exchange-specific adjustment to every application that renders PDFs or every blocked-file event.\n\n## DSE recommendation\n\nCheck the user’s effective OWA mailbox policy before weakening the Cloud Apps download restriction. Have the Exchange and security owners agree which users need preview and which download restriction must remain. Review the documented direct-file-access parameters and their intended scope in a test policy. Prepare the prior configuration for recovery and communicate the expected user experience before applying any production change.\n\n## Verification\n\nWith a non-sensitive PDF and the download-blocking session policy still active, test preview for a representative affected user. Confirm both the preview result and the absence of the prohibited Download option. Repeat against any distinct OWA policy assignments in scope rather than assuming the default represents all users. Retain the effective policies and observed results, and investigate other failure causes if the documented combination does not produce the expected behavior.\n\n## Official references\n\n[Microsoft Learn: Troubleshooting access and session controls for end-users](https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Investigate OWA PDF preview failures without removing the download block",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/",
                "headline": "Investigate OWA PDF preview failures without removing the download block",
                "description": "Why can a Cloud Apps download-blocking policy also prevent an Outlook on the web PDF preview?",
                "abstract": "Why can a Cloud Apps download-blocking policy also prevent an Outlook on the web PDF preview?",
                "articleBody": "Source facts\nSome PDF preview or print operations initiate a file download, which can trigger Defender for Cloud Apps download blocking. For Outlook on the web, Microsoft’s documented adjustment disables direct file access on both private and public computers in the applicable OWA mailbox policy. Its expected test result removes the Download option while allowing preview. Custom or additional OWA policies may apply to particular users, so changing only the default policy may not cover them. Microsoft Learn.\nApplicability\nUse this branch for an OWA PDF-preview symptom under an identified download-blocking session policy. Determine the user’s effective mailbox policy and preserve the original settings. Do not generalize this Exchange-specific adjustment to every application that renders PDFs or every blocked-file event.\nDSE recommendation\nCheck the user’s effective OWA mailbox policy before weakening the Cloud Apps download restriction. Have the Exchange and security owners agree which users need preview and which download restriction must remain. Review the documented direct-file-access parameters and their intended scope in a test policy. Prepare the prior configuration for recovery and communicate the expected user experience before applying any production change.\nVerification\nWith a non-sensitive PDF and the download-blocking session policy still active, test preview for a representative affected user. Confirm both the preview result and the absence of the prohibited Download option. Repeat against any distinct OWA policy assignments in scope rather than assuming the default represents all users. Retain the effective policies and observed results, and investigate other failure causes if the documented combination does not produce the expected behavior.\nOfficial references\nMicrosoft Learn: Troubleshooting access and session controls for end-users. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:22:10+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-586-investigate-owa-pdf-preview-failures-without-removing-the-download-block/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Investigate OWA PDF preview failures without removing the download block"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 268,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Troubleshooting access and session controls for end-users - Microsoft Defender for Cloud Apps | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-cloud-apps/troubleshooting-proxy-end-users"
                }
            }
        ]
    }
}