| Message Content |
Updated September 23, 2026: We have updated the content. Thank you for your patience.
[What and why:]
As part of our overall security initiatives, we’ve created a separate internal application configuration for Outlook attachments, therefore, all standard security and authentication flows will be handled separately. Moreover, Conditional Access policies are now enforced for Outlook attachment operations. Users who don’t meet company policies won’t be able to download, preview, or upload classic attachments (this includes inline images). Policies assigned to Exchange and Office cloud applications will be inherited by the attachment application by default. Continuous Access Evaluation is not included in the initial rollout but will follow up soon.
[Rollout schedule:]
Available now.
[Impact on your organization:]
- Your existing policies now cover attachments. Conditional Access policies you have already scoped to Exchange and Office cloud applications will be enforced for attachment scenarios as well. No new policies need to be created.
- Users out of compliance will be blocked from attachments. If a user’s session no longer satisfies a Conditional Access policy ― for example, a non-compliant device, a blocked location, or a network change that triggers CAE re-evaluation ― attachment operations will be blocked.
- These are separate follow-up changes we expect to land in the upcoming weeks. We’ll keep you updated on the readiness and rollout of these enhancements:
- User sign in prompt for remediation. We’re currently working on a solution to prompt the user for sign in to recover functionalities when possible. This will depend on the policy configuration; if the user is not compliant, they won’t be able to use attachment-related tasks. We’ll provide an update to customers once we start rolling out this enhancement.
- Enable Continuous Access Evaluation (CAE). CAE isn’t supported for this new application configuration yet. We’ll update this message with additional content when it becomes available.
[Action required / Recommendations:]
- Review how your Office and Exchange policies apply to attachments.
- Attachment operations are now handled by their own application, which by default inherits the Conditional Access policies you’ve assigned to Office and Exchange. Confirm those conditions are what you intend to enforce for attachments.
- If you’ve intentionally excluded Exchange online from a policy, that exclusion doesn’t carry over to attachments, so users in scope can reach their mail but will be blocked from downloading, previewing, or uploading attachments.
- To manage attachment policies separate from mail, you can either exclude the attachment application from a policy or target it in a policy of its own. Both require a one-time setup step in your tenant ― see Appendix: Excluding attachments from a policy.
- Update your help desk documentation. Support staff should know that attachment access failures may now result from a Conditional Access policy, and that the remediation is the same as for Outlook ― return to a compliant device or network and re-authenticate.
- Notify users if you enforce strict Conditional Access policies, so they understand attachment actions may now be blocked under the same conditions that already block access to their mailbox.
[Appendix:]
Excluding attachments from a policy
Attachment operations are handled by an application named OwaDownloadAttachments (application Id: e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64 ). Before you can exclude it from a Conditional Access policy, a service principal for it must exist in your tenant. This is a one-time step you’ll need to complete first.
Step 1: Create the service principal
You’ll need the Cloud Application Administrator or Global Administrator role.
- Open Graph Explorer and sign in as an administrator of your tenant.
- Run:
POST graph.microsoft.com/v1.0/servicePrincipals
Request body: { “appId”: “e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64” }
Consent to Application.ReadWrite.All scope is required.
A successful request returns 201 Created with a display name of OwaDownloadAttachments. If the request reports that the service principal already exists, continue to Step 2.
Step 2: Exclude it from the policy
- Click on View or Edit on the Conditional Access Policy you want to update.
- Under Target resources, select the Exclude tab.
- Choose Select resources, search for OwaDownloadAttachments, and select it.
- Save the policy.
Repeat Step 2 for each policy you want attachment operations exempted from.
|
| Machine Translation |
2026年9月23日更新:内容を更新しました。ご辛抱いただきありがとうございます。
[何を、なぜ:]
全体的なセキュリティ策の一hとして、Outlook添付ファイル用のe社内O定を作成し、すべての实膜圣互濂辚匹¥瑜诱J^フロ`はe々にI理されます。さらに、Outlookの添付操作には条件付きアクセスポリシ`がm用されるようになりました。会社のポリシ`に合致しないユ`ザ`は、クラシックな添付ファイル(インライン画像も含む)をダウンロ`ド、プレビュ`、アップロ`ドできません。ExchangeおよびOfficeクラウドアプリケ`ションに割り当てられたポリシ`は、デフォルトで添付ファイルアプリケ`ションに@承されます。@A的アクセスu铣跗冥握归_には含まれていませんが、近日中にフォロ`アップされます。
[展_スケジュ`ル:]
F在入手可能です。
[Mへの影:]
- 既存のポリシ`はF在、添付ファイルをカバ`しています。 すでにExchangeやOfficeクラウドアプリケ`ションに限定している条件付きアクセスポリシ`も、添付シナリオにもm用されます。新しいポリシ`を作成する必要はありません。
- していないユ`ザ`は添付からブロックされます。 ユ`ザ`のセッションが条件付きアクセスポリシ`を氦郡丹胜胜盲龊(例えば、非デバイス、ブロックされた鏊蓼郡CAE再u蛞黏长攻庭氓去铹`ク涓胜)、添付操作はブロックされます。
- これらは今後数Lg以内にg施予定の e々のフォロ`アップ涓 です。これらの化の渥rと展_状rについては、随rお知らせします。
- ユ`ザ`サインインプロンプトによる修。 F在、C能回のためにユ`ザ`にサインインを促すソリュ`ションを_k中です。これはポリシ`O定によります。ユ`ザ`がしていなければ、添付vBタスクを利用できません。このC能化の展_が_始され次第、お客にアップデ`トをお届けします。
- @A的アクセスu(CAE)を有郡摔筏皮坤丹ぁ この新しいアプリケ`ション成では、CAEはまだサポ`トされていません。追加コンテンツが追加され次第、このメッセ`ジを更新します。
[必要な行/推X事:]
- OfficeおよびExchangeのポリシ`が添付ファイルにどのようにm用されるかを_Jしてください。
- 添付操作はF在、それぞれのアプリケ`ションによってI理されており、デフォルトでOfficeとExchangeに割り当てた条件付きアクセスポリシ`を@承します。その条件が添付ファイルにして制する意恧毪_Jしてください。
- もしExchangeオンラインを意淼膜衰荪辚珐`から除外した龊稀饯纬猡咸砀顶榨ˉぅ毪摔弦@がれないため、象ユ`ザ`はメ`ルにアクセスできますが、添付ファイルのダウンロ`ド、プレビュ`、アップロ`ドはブロックされます。
- メ`ルとはeに添付ポリシ`を管理するには、添付ファイルアプリケ`ションをポリシ`から除外するか、独自のポリシ`でタ`ゲットにすることができます。どちらもテナント内で一度きりのO定ステップが必要です。は付h「ポリシ`から添付ファイルを除外する」を参照してください。
- ヘルプデスクのドキュメントを更新してください。 サポ`トスタッフは、条件付きアクセスポリシ`によって添付ファイルアクセスの失・k生することがあり、はOutlookと同に、したデバイスやネットワ`クに盲圃僬J^するものであることを知っておくべきです。
- 格な条件付きアクセスポリシ`を施行する龊悉膝姗`ザ`に通知し、添付ファイル操作がすでにメ`ルボックスへのアクセスをブロックしている条件と同じ条件でブロックされる可能性があることを理解してもらいます。
[付h:]
ポリシ`からの添付ファイルの除外
添付操作は OwaDownloadAttachments というアプリケ`ション(アプリケ`ションID: e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64)によってI理されます。条件付きアクセスポリシ`から除外する前に、そのサ`ビスプリンシパルがテナント内に存在しなければなりません。これは一度きりのステップで、まず完了する必要があります。
ステップ1:サ`ビスプリンシパルを作成する
クラウドアプリケ`ション管理者またはグロ`バル管理者の役割が必要です。
- グラフエクスプロ`ラ`を_き、テナントの管理者としてサインインしてください。
- ラン:
ポスト graph.microsoft.com/v1.0/servicePrincipals
Request body: { “appId”: “e4f2bb2d-a4d0-4eab-aac6-a8b83471cf64” }
申への同意。ReadWrite。すべての欷匾扦埂
成功したリクエストは「201 Crcreated」を返し、表示名は OwaDownloadAttachmentsとなります。リクエストでサ`ビスプリンシパルが既に存在すると蟾妞丹欷龊悉稀攻匹氓2にMみます。
ステップ2:保から除外する
- 更新したい条件付きアクセスポリシ`の「表示」または「工颔辚氓筏皮坤丹ぁ
- 「タ`ゲットリソ`ス」の「除外」タブをxkしてください。
- 「リソ`スをxkし、 OwaDownloadAttachments」を仕鳏筏七xkしてください。
- 保を保存しましょう。
添付操作を除外したいポリシ`ごとにステップ2をRり返します。
|