

"Admins can configure whether users can bypass and ‘Enable Editing’ for malicious scenarios in the Admin portal," Microsoft explains. If the document is deemed unsafe, the users will be warned and blocked from exiting Protected View. If the files are found as being free of malicious content, users will be able to exit the Protected View. On endpoints where the Safe Documents feature is enabled, all untrusted files opened in Protected View will be uploaded and scanned by Microsoft Defender ATP, following the privacy and data handling rules detailed here.ĭuring active scans of untrusted documents originating from outside the enterprise users' organizations, the customers will be blocked from leaving Protected View and from editing the content. "To improve this trust promotion experience for Microsoft 365 Apps, Safe Documents takes away the guesswork by automatically verifying the document against the latest known risks and threat profiles before allowing users to leave the Protected View container." "Although Protected View helps secure documents originating outside the organization, people too often exit the protection sandbox without considering if the document is safe – leaving their organizations vulnerable," Microsoft said. Protected View is a read-only Office mode for opening documents deemed as potentially unsafe where most editing features are disabled to protect the users' from threats. Safe Documents - launched in private preview in February - uses Microsoft Defender Advanced Threat Protection (ATP) to scan documents opened in Protected view and block users from editing them until a verdict is available.

Microsoft today announced the general availability of the Office 365 Safe Documents security feature which expands the protection provided by Protected View by checking untrusted documents for risks and known threats.
