As part of Microsoft Defender Secure Score’s recommended actions, enabling the Turn on Safe Attachments in block mode feature is paramount in fortifying your organization’s email security. Let’s bolster your defense against malicious email attachments and stay ahead of potential threats.

Note: “Recommended action” Remediations as identified by “Microsoft 365 admin center Portal (https://portal.microsoft.com) \ Security \ Secure score \ Recommended actions” in a pristine baseline environment.

Rank Recommended action

97 Turn on Safe Attachments in block mode

Microsoft Security Score

Before Mitigation:

A black text with black letters Description automatically generated

After Mitigation:

A black text with black text Description automatically generated

Secure Score Improvement: +0.76%

General

Description

Safe Attachments in block mode prevents messages with detected malware attachments from being delivered. These messages are quarantined and only admins (not regular users) can review, release, or delete them. This will also automatically block future malware attachments.

MDO Built-in protection policy provides safe attachments protection for everyone by default. You could also create additional Safe Attachment policies for customized Safe Attachment operations.

Implementation status

100% of users are affected by policies that are configured securely

  • Strict Preset Security Policy1705599895932 – 1 users (100%)

Implementation

Prerequisites

You have Microsoft Defender for Office 365 P1.

Next steps

Ensure that all users have an assigned ‘Safe Attachments’ policy in Block mode by either updating your existing policies or creating new ones.

Learn more

Set up Safe Attachments policies in Microsoft Defender for Office 365 | Microsoft Learn