dani
Goto Top

Changes to File Types Blocked in Outlook on the web

Moin,
We will soon be adding several additional file extensions to the BlockedFileTypes property of existing OwaMailboxPolicy objects. This change will prevent Outlook on the web users from downloading attachments that have those file extensions.

Why are we making this change?
We’re always evaluating ways to improve security for our customers, and so we took the time to audit the existing blocked file list and update it to better reflect the file types we see as risks today.

How does this affect me?
The newly blocked file types are rarely used, so most organizations will not be affected by the change. However, if your users are sending and receiving affected attachments, they will report that they are no longer able to download them.

What file extensions will be added to the BlockedFileTypes list with this change?
The following extensions are used by the Python scripting language:
".py", ".pyc", ".pyo", ".pyw", ".pyz", ".pyzw"

The following extensions are used by the PowerShell scripting language:
".ps1", ".ps1xml", ".ps2", ".ps2xml", ".psc1", ".psc2", ".psd1", ".psdm1", ".psd1", ".psdm1"

The following extensions are used for digital certificates:
".cer", ".crt", ".der"

The following extensions are used by the Java programming language:
".jar", ".jnlp"

The following extensions are used by various applications. While the associated vulnerabilities have been patched (for years, in most cases), they are being blocked for the benefit of organizations that might still have older versions of the application software in use:
".appcontent-ms", ".settingcontent-ms", ".cnt", ".hpj", ".website", ".webpnp", ".mcf", ".printerexport", ".pl", ".theme", ".vbp", ".xbap", ".xll", ".xnk", ".msu", ".diagcab", ".grp"

How can I prepare for this change?
If your organization requires that users be able to download attachment of these types from OWA, you should first ensure that our organization's operating systems and application software are up-to-date (in the case files that are opened by application software) or ensure that your users are familiar with the risks associated with the file types (in the case of files that are interpreted by scripting software). Mehr dazu im Link...

Quelle: Changes to File Types Blocked in Outlook on the web


Gruß,
Dani

Content-Key: 498200

Url: https://administrator.de/contentid/498200

Printed on: April 25, 2024 at 00:04 o'clock