Built-in virus protection in SharePoint Online, OneDrive, and Microsoft Teams - Microsoft Defender for Office 365 (2024)

Tip

Did you know you can try the features in Microsoft Defender XDR for Office 365 Plan 2 for free? Use the 90-day Defender for Office 365 trial at the Microsoft Defender portal trials hub. Learn about who can sign up and trial terms on Try Microsoft Defender for Office 365.

Microsoft 365 uses a common virus detection engine for scanning files that users upload to SharePoint Online, OneDrive, and Microsoft Teams. This protection is included with all subscriptions that include SharePoint Online, OneDrive, and Microsoft Teams.

Important

The built-in anti-virus capabilities are a way to help contain viruses. They aren't intended as a single point of defense against malware for your environment. We encourage all customers to investigate and implement anti-malware protection at various layers and apply best practices for securing their enterprise infrastructure.

The Microsoft 365 virus detection engine scans files asynchronously (at some time after upload). If a user tries to download a file in a web browser or from Teams that hasn't been scanned, a scan is triggered before the download is allowed. All file types are not automatically scanned. Heuristics determine the files to scan. When a file is found to contain a virus, the file is flagged.

Here's what happens:

  1. A user uploads a file to SharePoint Online.
  2. SharePoint Online, as part of its virus scanning processes, later determines if the file meets the criteria for a scan.
  3. If the file meets the criteria for a scan, the virus detection engine scans the file.
  4. If a virus is found within the scanned file, the virus engine sets a property on the file that indicates the file is infected.

What happens when a user tries to download an infected file by using the browser?

By default, users can download infected files from SharePoint Online. Here's what happens:

  1. In a web browser, a user tries to download a file from SharePoint Online that happens to be infected.
  2. The user is shown a warning that a virus was detected in the file. The user is given the option to proceed with the download and attempt to clean it using anti-virus software on their device.

To change this behavior so users can't download infected files, even from the anti-virus warning window, admins can use the DisallowInfectedFileDownload parameter on the Set-SPOTenant cmdlet in SharePoint Online PowerShell. The value $true for the DisallowInfectedFileDownload parameter completely blocks access to detected/blocked files for users.

For instructions, see Use SharePoint Online PowerShell to prevent users from downloading malicious files.

Can admins bypass DisallowInfectedFileDownload and extract infected files?

SharePoint admins and global admins* are allowed to do forensic file extractions of malware-infected files in SharePoint Online PowerShell with the Get-SPOMalwareFileContent cmdlet. Admins don't need access to the site that hosts the infected content. As long as the file is marked as malware, admins can use Get-SPOMalwareFileContent to extract the file.

For more information about the infected file, admins can use the Get-SPOMalwareFile cmdlet to see the type of malware that was detected and the status of the infection.

Important

* Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

What happens when the OneDrive sync client tries to sync an infected file?

When a malicious file is uploaded to OneDrive, the file is synced to the local machine before being marked as malware. After the file is marked as malware, the user can't open the synced file from their local machine.

Extended capabilities with Microsoft Defender for Office 365

Microsoft 365 organizations that have Microsoft Defender for Office 365 included in their subscription or purchased as an add-on can enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams for enhanced reporting and protection. For more information, see Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.

Related articles

Malware and ransomware protection in Microsoft 365

Turn on Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.

Built-in virus protection in SharePoint Online, OneDrive, and Microsoft Teams - Microsoft Defender for Office 365 (2024)
Top Articles
Difference between Node require and ES6 import and export - GeeksforGeeks
Global Macro Strategy
Dairy Queen Lobby Hours
Kevin Cox Picks
Pieology Nutrition Calculator Mobile
Mackenzie Rosman Leaked
What happened to Lori Petty? What is she doing today? Wiki
Jeremy Corbell Twitter
Holly Ranch Aussie Farm
How Far Is Chattanooga From Here
Evita Role Wsj Crossword Clue
My.doculivery.com/Crowncork
Jessica Renee Johnson Update 2023
Used Wood Cook Stoves For Sale Craigslist
3472542504
Troy Athens Cheer Weebly
Ts Lillydoll
Unlv Mid Semester Classes
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Snow Rider 3D Unblocked Wtf
Razor Edge Gotti Pitbull Price
Pekin Soccer Tournament
U Break It Near Me
Account Suspended
X-Chromosom: Aufbau und Funktion
Understanding Genetics
12 Top-Rated Things to Do in Muskegon, MI
Best Nail Salons Open Near Me
Pearson Correlation Coefficient
Cpt 90677 Reimbursem*nt 2023
Https E22 Ultipro Com Login Aspx
Marquette Gas Prices
Bay Area Craigslist Cars For Sale By Owner
Regina Perrow
Lovindabooty
27 Modern Dining Room Ideas You'll Want to Try ASAP
4 Methods to Fix “Vortex Mods Cannot Be Deployed” Issue - MiniTool Partition Wizard
Worthington Industries Red Jacket
Persona 4 Golden Taotie Fusion Calculator
Mega Millions Lottery - Winning Numbers & Results
Tra.mypatients Folio
Tds Wifi Outage
Case Funeral Home Obituaries
Gpa Calculator Georgia Tech
Craigslist en Santa Cruz, California: Tu Guía Definitiva para Comprar, Vender e Intercambiar - First Republic Craigslist
Nina Flowers
6576771660
Cabarrus County School Calendar 2024
Kjccc Sports
Espn Top 300 Non Ppr
Publix Store 840
Latest Posts
Article information

Author: Sen. Ignacio Ratke

Last Updated:

Views: 6364

Rating: 4.6 / 5 (56 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Sen. Ignacio Ratke

Birthday: 1999-05-27

Address: Apt. 171 8116 Bailey Via, Roberthaven, GA 58289

Phone: +2585395768220

Job: Lead Liaison

Hobby: Lockpicking, LARPing, Lego building, Lapidary, Macrame, Book restoration, Bodybuilding

Introduction: My name is Sen. Ignacio Ratke, I am a adventurous, zealous, outstanding, agreeable, precious, excited, gifted person who loves writing and wants to share my knowledge and understanding with you.