Password-Protected Attachment Handling

Password-protected files are not accessible without the correct password and can therefore carry security risks that pass undetected. By attempting to find a password in an email message with password-protected attachments, Cloud App Security can try to decrypt the attachments in the message for scanning. This helps maximize protection against threats in password-protected files.

This feature does not require manual configuration. It is enabled automatically after you turn on the Malware Scanning filter or Virtual Analyzer filter.

Cloud App Security supports the feature for the following services, attachment file types, and email languages.


Attachment File Types

Email Languages

  • Exchange Online

  • Gmail

  • ZIP (by 7-Zip or PKZIP)

  • RAR

  • PDF

  • Microsoft Office files (.doc, .xls, .ppt, .docx, .xlsx, .pptx)


Cloud App Security detects the true file types of files instead of using the file extensions.

  • English

  • Portuguese

  • German

  • Spanish

  • Italian

  • Russian

  • Czech

  • Polish

  • Bengali

  • Hindi

  • Chinese

  • Japanese

  • Korean

  • Vietnamese

  • Arabic

  • Hebrew


If Cloud App Security does not find a password to decrypt the attached files:

  • In the Malware Scanning filter, Cloud App Security takes the action specified for Password-protected compressed files or Other password-protected files, depending on whether the files are compressed.

  • In the Virtual Analyzer filter, Cloud App Security takes action based on the risk level returned by the Virtual Analyzer.