This site is for Avast Business products only. For articles on AVG Business products, see AVG Business Help. If you are in the right place but cannot find what you are looking for, please contact Avast Business Support for further assistance.

Exchange Shield

This Article Applies to:

  • Avast Business Hub


The Exchange component for Windows Servers is specifically meant to protect your Exchange Server from threats without interfering in its function. It scans and filters emails for viruses at the Exchange server level, stopping potential attacks before they spread to the network.

Supported Email Servers

Microsoft Exchange server versions 2010 and later are supported.


Exchange must be installed prior to installing Avast Business Antivirus in order for the application to be detected and the plugin installed.

If Exchange is installed afterward, the Exchange component would need to be added via policies.

Configuring Exchange Shield Settings

To access Exchange Shield settings:

  1. Open the Policies page
  2. Click the desired policy to open its Detail drawer
  3. Click the Settings tab, then Antivirus
  4. Expand the Exchange section (under Data Protection)

Three sets of settings are available here:

  • Scanning
  • Actions
  • Blocking

Scanning Tab

Here, you can configure basic scanning parameters:

  • Scan messages on-access: On-access scanner scans messages upon downloading, and remains active even if scanning messages in the background and proactive scanning options are off.
  • Scan messages in the background (Exchange 2010 only): Background scanning works when an item that has not been scanned with the latest Avast virus definitions is encountered in the users’ mailbox folders. Scanning and searching for not examined objects runs in parallel. A specific low priority thread is used for each database, which guarantees other tasks (e.g. email messages storage in the Microsoft Exchange database) are always carried out preferentially.
  • Enable proactive scanning (Exchange 2010 only): Proactive scanning works when an item is delivered to a folder, but a request has not been made by a client. As messages are submitted to the Exchange store, they enter the global scanning queue as low priority (maximum of 30 items). They are scanned on the first in, first out (FIFO) basis. If an item is accessed while still in the queue, it is changed to high priority.
  • Scan at transport level: Enables scanning of emails at the Exchange Hub Transport level.
  • Scan RTF message bodies: Enables scanning of messages in rich text format.
  • Try to clean infected objects: infected objects will be cleaned (e.g. remove malicious code only); if unsuccessful, they will be removed.

Note that Exchange Shield can only scan messages (on-access and in the background) on IS level.

Actions Tab

The Actions settings allow you to configure how untestable and infected items are handled. In both cases, you can choose to allow full access to the item, overwrite the item with a warning, or delete the whole message.

You can also change the infected object's icon (if possible).

Blocking Tab

Use these settings to block attachments with specified filename masks (characters and wildcards used to match folder and file names) that are found in messages coming through Exchange.

To enable and configure attachment blocking:

  1. Tick the Enable attachment blocking by name checkbox
  2. Click + Add mask
  1. In the pop-up dialog, enter the filename mask(s), then click Add mask

The list will then get populated with your entries, which you can edit/delete anytime using the pencil/trash bin icon in the Actions column.

At the bottom of the settings, you can also choose what the file name is replaced by, and the content of the .txt file that will replace the blocked file.