Has impersonation protection become less reliable recently?

0
1
Asked By MellowCedar42 On

I manage Microsoft 365 Business Premium for several clients. Protected senders are configured with quarantine as the action, and display-name impersonation detection had worked reliably for months or even years. Over the past week or two, two separate tenants allowed obvious spoofing attempts through, including exact display-name matches for protected users. One message also had several warning signs, such as an urgent request and a reply-to address on an unrelated domain. The headers showed SCL 1, SFV NSPM, and CAT NONE, indicating the messages were scanned rather than bypassing filtering, but the impersonation classifier still did not flag them. Has anyone else noticed a recent drop in impersonation-detection accuracy?

2 Answers

Answered By QuietHarbor19 On

I’d report each example through your provider or Microsoft support and include the full headers, policy configuration, and original messages. A few reports may help establish whether there’s a service-side regression and give them enough data to investigate.

Answered By OrbitingMango7 On

Yes, I’ve seen several similar messages get through since last week. It does seem like something changed recently rather than being an isolated configuration issue.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.