I manage several tenants using Business Premium. Protected senders are configured with quarantine as the action, and impersonation protection had worked reliably for months or even years. Over the past week or two, two different tenants allowed obvious display-name impersonation messages through. Both used an exact match for a protected user, and one also had several warning signs, including an urgent request and a reply-to address on an unrelated domain. The raw headers showed SCL 1, SFV NSPM, and CAT NONE, indicating the messages were scanned rather than bypassing filtering, but the impersonation classifier still did not flag them. Has anyone else noticed a recent drop in detection accuracy? I've reported it through our cloud service provider, who mentioned receiving similar reports.
2 Answers
It’s worth submitting a formal bug report and keeping the headers and message samples available for the support case. If multiple organizations are reporting the same behavior, Microsoft may need to correct the detection service or classifier rather than having admins change their policies.
Yes, I’ve seen several similar failures since last week. Messages that would previously have been caught are suddenly making it through, so this may be a broader service-side regression rather than a tenant-specific configuration issue.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures