Safe Attachments

What is Safe Attachments?

Safe Attachments is a feature of Microsoft Defender for Office 365 (formerly known as Office 365 Advanced Threat Protection - ATP). It protects users from malicious attachments like Excel, Word or PDF's containing ransomware, by scanning every email attachment in a safe "sandbox" to determine if it contains any malicious intentions before delivering it to your inbox. Attachment scanning will be performed on attachments that are common targets for malicious content, such as Office documents, PDFs, executable file types, and Flash files.

You will notice that it will take some time to scan the attachments after you received the email message before you can access to the attachments. Please wait for a short while before access to the attachments for best security protection:

If an attachment is safe, the message with the attachments are delivered. If an attachment is unsafe, the user will receive the email, but not the attachment. They will be informed the attachment has been removed and replaced with a text file called “Malware Alert Text.txt” that contains the following:
 
“Malware was detected by Safe Attachments in one or more attachments included with this email message.
 
Action: All attachments have been removed.”
 
Safe Attachments works on email coming from both external and internal sources, meaning it can protect HKUST users from internal threats such as a compromised computer or email account. Attachment scanning is not available for encrypted mail / attachments, users should ensure they were expecting mail from the sender before opening encrypted attachments.