Attachment Cleaning (Threat Extraction) Clean Attachments and Workflows
Clean Attachments
Threat Extraction cleans an attachment and executes the configured workflow when these conditions are met:
-
The attachment is of a supported file type.
-
The attachment contains one of the Original Attachments vs Cleaned Attachments.
-
The attachment is not detected as malicious (if malicious, the Anti-Malware workflow will take effect).
In addition, Threat Extraction excludes an attachment from cleaning when these conditions are met:
-
Other attachments in the same email are password-protected.
-
The workflow for password-protected attachments is configured as Require end-user to enter a password.
When an attachment is not cleaned, its original version is included in the email sent to the end user, and no restoration is required by the user.
For standard email security actions like removing potentially risky attachments and to help maintain the integrity of digitally signed messages, Email Security offers the ability to avoid security modifications for S/MIME-signed emails. See Support for S/MIME-Signed Emails.
Workflows
The administrators can select any of these workflows for attachment cleaning in emails.
| Workflow | Description |
|---|---|
| User is allowed to request a restore for any attachment (admin must approve) | The use is allowed to request for restoring the original attachments. The attachments are restored only after the admin approves. |
| User is allowed to restore benign attachments only | The user can request to restore the attachments. If the attachments are benign, they are restored immediately. |
| User is allowed to restore any attachment | The user can request to restore the attachments and they are restored immediately. |