How fast is Abnormal’s post-delivery remediation in practice?

0
0
Asked By MellowPine47 On

I'm evaluating Abnormal against keeping a traditional mail gateway. We're moving away from relying on Microsoft Defender alone because of repeated misses, especially business email compromise and no-payload attacks that an API-based behavioral system appears better at catching.

I found an older discussion describing several-minute delays when removing malicious messages, including one account takeover that was detected only after a support ticket and a message that reportedly remained in Microsoft audit data for many hours. For organizations using Abnormal recently, what does automatic remediation look like in practice? Is the usual delay measured in seconds, and have the older reports been resolved? Were those incidents caused by bugs, configuration, Microsoft-side latency, or normal behavior?

I'm also interested in how the post-delivery exposure compares with Microsoft ZAP. Is the remaining window effectively negligible, or can users realistically open and act on a message before it is removed?

4 Answers

Answered By BlueCedar14 On

Some account-takeover detections can take 20–40 minutes, but that is a different delay from removing an already identified message. The longer interval may be caused by waiting for identity-provider sign-in data to become available, so it should not be used as the normal remediation latency.

Answered By QuietHarbor8 On

For most messages, remediation happens within roughly one or two seconds, although a small number can take longer. The occasional outlier seems to be the exception rather than the normal experience.

Answered By CopperLynx29 On

A more realistic figure is about three to five seconds from Abnormal receiving the notification that Microsoft has delivered the message to Abnormal sending the removal request back. Microsoft’s own processing can add a little time, and the mail client may take another several seconds to refresh.

Users can very occasionally see a message appear and then disappear, but it is uncommon. A user clicking during that short interval is possible in theory, though generally unlikely. No product is perfect, so the delay should be treated as a small residual exposure rather than zero risk.

NorthVale62 -

The important distinction is the average versus the tail. Most messages disappear quickly, but a few unusually slow cases are worth measuring instead of assuming they cannot happen.

Answered By IvoryMaple31 On

The best answer will come from your own tenant. Compare the message-received timestamp with the soft-delete or quarantine timestamp using message trace and Microsoft 365 audit data across a representative batch. That captures your actual Graph, Exchange, and client-side latency rather than relying on a product claim.

In practice, API-based remediation is generally a few seconds for most messages, while ZAP can take minutes or occasionally longer because it relies on later rescanning and detection workflows. The post-delivery gap is usually small, but it is not literally zero. If eliminating that window is more important than catching additional BEC and no-payload attacks, an inline gateway still has a role.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.