Test Safe Attachments precedence and delivery behavior before custom rollout

Defender for Office 365 Safe Attachments uses preset and custom policies with recipient filtering and priority; an apparently valid custom policy may not control users already covered by a higher-precedence preset policy.

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudChecklist · 3 min read
Executive summary

What you need to know

Defender for Office 365 Safe Attachments uses preset and custom policies with recipient filtering and priority; an apparently valid custom policy may not control users already covered by a higher-precedence preset policy.

Potentially affected

Organizations licensed for Microsoft Defender for Office 365 and configuring Safe Attachments for Exchange Online recipients.

DSE recommendation

Map preset and custom policy precedence, select delivery behavior deliberately, test target and exception recipients, and preserve message-level evidence before expanding scope.

Bottom line: Safe Attachments adds virtual-environment analysis of supported attachments after antimalware scanning. The effective result depends on preset-policy membership, custom-policy priority, recipient filters, exceptions, and the selected action when analysis detects a file or cannot complete. Verify the effective policy, not merely the custom policy’s existence.

Source fact: what Microsoft documents

Microsoft’s Safe Attachments configuration guide says Safe Attachments detonates files in a virtual environment to observe behavior before delivery. Microsoft documents Built-in protection, Standard and Strict preset security policies, and custom Safe Attachments policies.

The source explains that preset policy membership can take precedence over custom policy targeting and exceptions. In PowerShell, a Safe Attachments policy contains the behavior settings while a separate rule contains recipient conditions, priority, and enabled state. The portal creates and manages the pair together. Microsoft documents propagation time, supported recipient filters, administrative permissions, configuration verification, and reports. It also distinguishes email Safe Attachments policy from global settings for SharePoint, OneDrive, Teams, and Safe Documents.

What the source does not establish

Safe Attachments does not guarantee detection of every malicious or novel file, and an undetected attachment is not certified safe. A portal view of a policy does not prove it applied to a particular message. Detonation can affect delivery timing and application workflows. The guide does not decide whether fail-open, fail-closed, dynamic delivery, redirect, or quarantine behavior fits an organization’s risk and continuity needs.

Applicability questions

  • Which recipients are in Built-in, Standard, Strict, or custom policies, and where do groups overlap?
  • Which action and delivery experience is appropriate for ordinary users, executives, shared mailboxes, automated ingestion, and operational mailboxes?
  • Which legitimate encrypted, large, uncommon, or machine-processed attachments must be tested?
  • Who reviews detections and false positives, and what is the safe release process?
  • Are SharePoint, OneDrive, Teams, and Safe Documents protections being assessed separately?

DSE recommendation: controlled next steps

The following steps are DSE recommendations based on the cited source.

  1. Export or document preset and custom policy membership, custom rule priority, recipient filters, exclusions, and actions.
  2. Build an effective-policy matrix for representative recipients. Resolve unexpected overlap before changing protection.
  3. Pilot the selected action with test mailboxes and real business file types. Include delayed analysis, detection, false positive, and service-failure scenarios where safely testable.
  4. Define quarantine review, release authorization, sender and recipient communication, and escalation for business-critical attachments.
  5. Expand through controlled groups and monitor delivery latency, detection reports, quarantines, and user impact.

Verification and evidence

  • Preserve policy and rule configuration, preset membership, scope, priority, and change approval.
  • Use Microsoft’s documented verification methods and message evidence to show which policy handled a test.
  • Record benign and approved test-file outcomes without introducing live malware.
  • Review reports and quarantine actions after rollout; investigate recipients whose effective policy differs from design.

Official references

Primary reference

Review the official source

Set up Safe Attachments policies in Microsoft Defender for Office 365 · Verified August 25, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE