Has Microsoft Defender’s impersonation protection become less reliable lately?

0
1
Asked By MellowCedar42 On

I manage several tenants using Business Premium. Protected senders are configured with quarantine as the action, and impersonation protection had worked reliably for months or even years. Over the past week or two, two different tenants allowed obvious display-name impersonation messages through. Both used an exact match for a protected user, and one also had several warning signs, including an urgent request and a reply-to address on an unrelated domain. The raw headers showed SCL 1, SFV NSPM, and CAT NONE, indicating the messages were scanned rather than bypassing filtering, but the impersonation classifier still did not flag them. Has anyone else noticed a recent drop in detection accuracy? I've reported it through our cloud service provider, who mentioned receiving similar reports.

2 Answers

Answered By QuietHarbor19 On

It’s worth submitting a formal bug report and keeping the headers and message samples available for the support case. If multiple organizations are reporting the same behavior, Microsoft may need to correct the detection service or classifier rather than having admins change their policies.

Answered By OrbitingPine7 On

Yes, I’ve seen several similar failures since last week. Messages that would previously have been caught are suddenly making it through, so this may be a broader service-side regression rather than a tenant-specific configuration issue.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.