Struggling with O365 Quarantine Issues for Legit Emails

0
2
Asked By BluePenguin42 On

We're having a frustrating problem where our O365 system is marking known good emails as high confidence phishing and quarantining them. We've tried several solutions, like setting the SCL to -1 for all emails, turning off anti-phishing and anti-spam policies, and even creating a security operations mailbox, but nothing seems to work. We're considering completely disabling the O365 mail filtering since we have another product that does a better job. Any advice on how to handle this?

5 Answers

Answered By CloudWarrior01 On

We faced a similar issue and set our filtering to -1 for emails coming from our on-premises IPs and made sure it was the first transport rule. However, if you're in a hybrid setup without an on-prem IP, that could be tricky.

BluePenguin42 -

Yeah, we don’t have an on-prem service to direct things to. Our filtering setup is kind of in limbo.

Answered By ServerWhisperer77 On

If that doesn't do it, you might consider resetting your settings back to default. Sometimes, troubleshooting helps reset any underlying issues. If you're still stuck after that, opening a ticket with Microsoft could be your best bet.

Answered By ExpertNerd22 On

Just a heads up, from my experience, the High Confidence Phish setting can't be overridden. You could potentially look into using tools like Avanan that allow you to release emails without needing admin approval. It’s annoying, but their filtering is strict for a reason. Just wish we had more flexibility in setting our protection levels!

RealTalkFan -

Exactly! I feel you on that one! We should have more options for how much protection we want.

Answered By NetSleuth99 On

Is your filtering tool Proofpoint? If so, that might be causing the issue due to URL rewriting, which can mess with your DMARC and SPF rules.

BluePenguin42 -

Nope, we're using Mimecast, which is cloud-based.

Answered By TechGuru93 On

One thing you could try is moving your rules around. Make sure the one you're using to allow legitimate emails is the very first rule in the list. That could help prioritize it over the others.

EagerBeaver88 -

Done! We'll see if that makes a difference.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.