A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Defender for storage is able to scan the password protected PDF files, is that expected behaviour?
We have Microsoft Defender for Storage (on upload scan) enabled on our storage account. We noticed that it is able scan the password protected PDF files successfully. Even though on MS documentations implies that it shouldn't be able to do that. During our tests, password protected Word, Excel, Zip, RAR, etc... files fails as expected, however PDF files are successful.
Could you kindly clarify whether this behaviour is a bug or a feature?
Many thanks, Min 😊
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
-
Anonymous
2025-09-24T06:01:02.2366667+00:00 Hello Min,
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
To clarify your doubt, this behavior is a feature, not a bug. Defender for Storage on-upload malware scanning can, under specific circumstances, scan password-protected PDF files, while other file types like Word and Zip fail as expected. This is because of differences in how various file formats handle encryption and metadata.
Technically, the issue lies in the distinction between file level encryption and the way password protection is implemented in different file formats.
Microsoft Office and ZIP/RAR files typically use strong, file-level encryption that makes the file's content unreadable without the password. The on-upload malware scanner, being an external, cloud-native service, cannot decrypt this content, so the scan fails as documented.
PDF files can be password protected in two ways:
- Open Password: This requires a password to open the file.
- Permissions Password: This allows anyone to open the file but restricts actions like printing, copying, or editing. While both methods use encryption, the metadata and file structure of many PDF documents remain accessible even with an open password. Defender for Storage's malware scanner, which uses Microsoft Defender Antivirus engines, may be able to scan this non-encrypted metadata and certain parts of the file stream to detect malicious code, even if the primary content is protected. This is why the scan may report success while other file types fail.
So, to handle a situation where a password-protected PDF should be considered a security risk and flagged as such, you should implement additional measures using Azure Policy and Azure Functions.
Create a Logic App or Azure Function: You can use a blob trigger in an Azure Function or Logic App that runs whenever a new file is uploaded to the storage account.
Check the File Type: The function can inspect the file's metadata to check if it is a PDF.
Check File Status: If the file is a PDF, the function can check if it has a password using a third-party library or a dedicated script.
Create an Alert: If the file is a password-protected PDF, the function can then trigger a custom alert in Microsoft Defender for Cloud or send a notification to a security team for manual review.
Please refer below documents for better understanding:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/introduction-malware-scanning
https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-demand-malware-scanning
Hope this clarify your doubt.
Kindly let us know if the above helps or you need further assistance on this issue.Please "Accept the answer" if the information helped you and 'upvote' for it. This will help us and others in the community as well. Happy to help!
Regards,
Monalisha
-
Anonymous
2025-09-25T13:50:42.3533333+00:00 Hi Monalisha,
Thanks for your reply, for PDF files with "Open Password", should the defender for cloud scan fail?
Best regards,
Min
-
Anonymous
2025-09-26T10:10:31.87+00:00 Yes, Microsoft Defender for Storage can return a "successful scan" result for a PDF file protected with an Open Password.
No, this does not mean the file was fully scanned in the traditional sense.
PDFs protected with an Open Password still expose parts of their metadata and structure, which may include:
- Document metadata (title, author, etc.)
- Embedded scripts or objects outside the encrypted content stream
The Defender for Storage scanner leverages Microsoft Defender Antivirus engines, which can analyze these accessible portions. If no threats are found in those areas, the scan result is marked as "success".
However, the core content the encrypted portion is not decrypted or scanned, meaning:
- The file could still contain malicious payloads hidden in the protected content.
- From a security posture perspective, the file should be treated as not fully scanned. https://learn.microsoft.com/en-us/azure/defender-for-cloud/introduction-malware-scanning https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-upload-malware-scanning
Hope this help!
-
Anonymous
2025-09-26T10:56:28.88+00:00 Thanks for clarification, that was really helpful 😊
However, the core content the encrypted portion is not decrypted or scanned
Which unfortunately means we cannot 100% rely on defender scan status.
Is there any place where we can request for a feature, e.g. in defender for storage settings, to fail the file if it is not completely scanned?
-
Anonymous
2025-09-26T16:25:16.5733333+00:00 Hello Min,
Thanks for your follow-up! You're absolutely right to be thinking critically about the implications of a "successful" scan result when the core content of a password-protected file like a PDF with an Open Password is not actually scanned.
As of now, Microsoft Defender for Storage does not offer a built-in setting to automatically fail or flag a scan result when the file content is only partially scanned (e.g., due to encryption or password protection). This limitation is acknowledged in Microsoft documentation, which explains that scan results may still show as "successful" if accessible metadata or non-encrypted portions are clean even if the main content remains unscanned.
We can recommend use Custom Enforcement via Azure Functions or Logic Apps
To enforce stricter controls, Microsoft recommends implementing custom logic using Azure-native tools:
Blob-triggered Azure Function or Logic App: Detect when a new file is uploaded.
File inspection logic: Use a script or third-party library to determine if the file is password-protected.
Custom alerting: If the file is protected and cannot be fully scanned, trigger an alert or move the file to a quarantine container.
Again, this approach allows you to treat partially scanned files as potential risks, even if Defender for Storage reports them as clean.
Unfortunately, there is currently no direct toggle or setting in Defender for Storage to enforce scan failure on partial scans. However, you can post your feedback in our Azure feedback portal regarding the feature.
https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789
This channel is directly monitored by our PM's. They will look into this request and revert back to you directly with an update on this feature.
Hope I was able to clarify your doubt somehow. Happy to help!Regards,
Monalisha
-
Anonymous
2025-09-29T13:56:44.0433333+00:00 Hi Monalisha,
Thank you for taking your time to reply.
Could you kindly give me the documentation link for the following please?acknowledged in Microsoft documentation, which explains that scan results may still show as "successful" if accessible metadata or non-encrypted portions are clean even if the main content remains unscanned"
Thank you so much again. Min
-
Anonymous
2025-09-29T14:07:45.4666667+00:00 Hello Min,
Refer the below document:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/understand-malware-scan-resultsthis includes some points
- Scan results fall into two categories: successful states and error states.
- A scan result may show “successful” even if the blob was not scanned due to encryption or unsupported file types.
- Specifically, the documentation notes:
“Not scanned – the blob couldn't be scanned due to unsupported type or encryption.”
This means that even if the core content is encrypted or inaccessible, the scan may still return a "successful" status if metadata or non-encrypted portions are clean and no errors were triggered during the scan process.
Thanks!
-
Anonymous
2025-10-01T04:32:09.2433333+00:00 Hello Min,
just checking if you had a chance to see my previous reply, please let us know if it somehow helpful!
Sign in to comment