Malware attachment in mail

Anil Diwan 0 Reputation points
2025-12-07T19:50:39.8033333+00:00

We have receive every day multiple emails in my organisation that contain malware attachments. I do not want these emails to be delivered to end users or placed in quarantine. Instead, I want them to fail during processing so the system rejects them completely.how can I do this i have E5 licence rest all are have MDO plan 1.


Moved from: Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365

Outlook | Web | Outlook on the web for business | Security
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vy Nguyen 7,840 Reputation points Microsoft External Staff Moderator
    2025-12-07T22:20:55.3533333+00:00

    Hi @Anil Diwan

    Thank you for reaching out to the Microsoft Q&A forum. 

    Based on your description, you receive several emails daily containing malware attachments and want these messages to be rejected entirely instead of being delivered or quarantined. We truly appreciate the details you provided and your ongoing efforts to maintain a secure environment for your users. 

    This situation occurs because Microsoft Defender for Office 365 (MDO) processes messages that include malware by quarantining them according to your organization’s security and compliance policies. The system’s default behavior is designed to protect end users while allowing administrators to review quarantined messages before final disposition. To make the service reject malware messages completely, a configuration change must be applied in your anti-malware policy. 

    Please follow the steps below to enforce message rejection for malware: 

    1/ Start by enforcing the anti‑malware policy to block and remove detected threats (Admin Only)

    • Go to the Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Anti‑malware. Edit the applicable policy. 
    • Under Malware detection response, set Action = Block (Delete the message). This ensures malware messages are dropped and never delivered or quarantined.  

    User's image

    For your reference: Configure anti-malware policies for email - Microsoft Defender for Office 365 | Microsoft Learn 

    2/ Proceed by enforcing Safe Attachments policies to block threats throughout the organization (Admin only).

    • In the Defender portal → Email & collaboration → Policies & rules → Threat policies → Safe Attachments. Create or edit your policy. 
    • Set Action = Block so messages with detonated malware are removed before delivery. Apply to all intended recipients (you can use preset protection or a custom policy targeting users/groups). 

    User's image

    For your reference: Safe Attachments - Microsoft Defender for Office 365 | Microsoft Learn 

    3/ As your account is managed by your organization, please contact your IT administrator to check your permission and policies. For a more efficient resolution, we recommend using your administrator account or contacting your IT administrator to submit a support request directly to Microsoft Support team.    

    They can raise a support ticket by visiting: Get support - Microsoft 365 admin | Microsoft Learn 

    With Microsoft 365 E5 (which includes Defender for Office 365 Plan 2), these steps can be implemented directly. Users with MDO Plan 1 will need an admin-defined anti-malware policy since threat investigation automation differs between plans. 

    For your information that you can concern: Anti-malware protection for email In Microsoft 365 - Microsoft Defender for Office 365 | Microsoft … 

    As community moderators, we appreciate your understanding that our access to internal development details is limited. Our primary role is to guide users toward the appropriate resources and support channels. While we may not have visibility into deeper backend analysis, we’ll continue doing our best to support you within the scope of our responsibilities.  

    I hope this information is helpful. Please follow these steps and let me know if it works for you. If you have any updates regarding the issue, please feel free to share them with me.   

    Thank you for your patience and your understanding. If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.   

    I look forward to continuing the conversation. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.