# Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine

> What happens when a user supplies an attachment password for a quarantined Password protected item?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:00+00:00
- Modified: 2026-09-10T02:11:18+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

What happens when a user supplies an attachment password for a quarantined Password protected item?

## Potentially affected

Cloud mailbox recipients offered the documented release workflow for Safe Attachments Password protected item quarantine.

## DSE recommendation

Have the recipient validate an expected sender and use only the attachment password in the documented portal workflow.

## Article

## Source facts

For a quarantined Password protected item, Defender for Office 365 uses the supplied attachment password to rescan before release; it does not retain the password. A malicious attachment or one that remains unscannable stays quarantined for administrator review. Multiple protected attachments must share the same password. This release requires the portal rather than direct release from a notification email, and user release authority still depends on the quarantine policy. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user).

## Applicability

This is the documented encrypted-attachment quarantine path, not a reason to approve an unexpected message. Microsoft warns users to provide only the attachment password, never unrelated account credentials, and to escalate unexpected protected messages. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user).

## DSE recommendation

Have the recipient validate an expected sender and use only the attachment password in the documented portal workflow. Prepare help-desk guidance that distinguishes an attachment secret from a sign-in credential. Do not instruct users to work around the quarantine or treat possession of a password as proof that the file is harmless. Route unavailable release actions or unsuccessful rescans to the authorized mail-security reviewer.

## Verification

Use an approved benign protected attachment to rehearse the recipient experience where policy permits it. Record the quarantine reason, available action and resulting status without recording the password. Confirm the support instructions send the recipient to the portal and preserve administrator review when scanning cannot complete. State the observed outcome accurately rather than promising release simply because a password was entered.

## Official references

[Microsoft Learn: User quarantine management](https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user). Source reviewed September 9, 2026.

## Primary reference

- Name: Find and release quarantined messages as a user - Microsoft Defender for Office 365 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-office-365/quarantine-end-user
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Use attachment-password rescanning instead of bypassing an encrypted-attachment quarantine,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-536-use-attachment-password-rescanning-instead-of-bypassing-an-encrypted-attachment/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
