Attachment Cleaning (Threat Extraction)
Attachment Cleaning (Threat Extraction) is a Content Disarm and Reconstruction (CDR) engine that serves as an additional layer of security for email attachments on top of the Anti-Malware engine.
After the Anti-Malware security engine determines an attachment is not malicious, Attachment Cleaning (Threat Extraction) delivers a secure version of the attachment to the end user, removing hyperlinks behind text, macros, and other active content that may contain malware.
Administrators can allow end-users to retrieve the original version of the attachment. This action does not require the help desk's intervention. To configure the attachment cleaning workflow, see Configuring Attachment Cleaning (Threat Extraction) for Office 365 Mail or Gmail.
File Sanitization Modes
Attachment Cleaning (Threat Extraction) can create a safe version of an email attachment in these ways:
-
Clean - removes macros, embedded objects, and any active content from the attachment while maintaining the file type.
For example, if a DOC file is cleaned, the end user will get a modified DOC file.
-
Convert - the file is converted into PDF format, regardless of its original file type, ensuring no active content can ever be a part of it.
For example, if a DOC file is converted, the end user will get the file in PDF format.
-
While the Convert option is considered to be secure, it has an impact on user experience and productivity. Unless there are strict regulatory or organizational policy requirements, we recommend using the Clean option to deliver only PDF files.
-
The Convert option is available only for attachment cleaning in emails.