Microsoft is rolling out a Windows 11 change that restores limited access to File Explorer's Preview pane for files marked with Mark of the Web after previously disabling previews by default to mitigate NTLM hash leakage risks. The original restriction, introduced in late 2025, affected files downloaded from the internet, email attachments, and some cloud-synced content, requiring users to manually unblock trusted files before previewing them.
The updated behavior adds a "Preview anyway" button in File Explorer, letting users override the warning for trusted files while keeping the safer default in place. The feature appeared earlier in Windows Insider Release Preview builds 26100.8313 and 26200.8313, and broader availability is expected as Microsoft balances usability complaints with protections against unsafe file previews.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft documented in Windows Insider release notes that File Explorer would add a "Preview anyway" button for files downloaded from the internet after showing a warning. The feature was presented as a way to let users override the warning for trusted files while keeping the protection enabled by default.
Microsoft disabled File Explorer Preview pane previews by default for files carrying Mark of the Web after identifying a risk that previewing unsafe files could leak NTLM hashes. The change affected downloaded PDFs, documents, images, email attachments, cloud-storage files, and other internet-sourced files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourceblogs.windows.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.