Jarrad_McMullen I'm aware of the clause Secure by Default, but that implies you can CHANGE those settings. The correct term is locked down because you cannot change them. You've attempted to 'parent' your customers and 'grounded' their messages...
Message Center is not functional because the correct configuration is to have global admins without license accounts, and therefore, incapable of receiving emails; yet those are the accounts that get the messages.... Factor in the hundreds of meaningless notifications being sent from it and it becomes white noise. Viva? Yammer? Exchange outages in small parts of the world? Small percentage of users can't get their distribution lists updated? It's all so cluttered and obfuscated by design.
Anti-phishing policies need to go in the anti-phishing category instead of being secretly tucked away in anti-spam and overriding existing anti-phishing policies.
Impersonation and Spoofing emails are not a category of Phishing email. You have miscategorized these. Impersonation and Spoofing are tactics or mechanics; Phishing is an intention to gain credentials or information. SPAM is an inundation of emails from a source. Words matter. Moreso, you are categorizing things like multiple emails in short periods of time or emails with certain keywords or even hyperlinks that aren't 'Safe Links' all as phishing which they certainly aren't. I had one message from a customer trying to get around the anti-phishing problems created by Microsoft so they could test their users knowledge, and they sent me an Excel sheet with the domains to include for whitelisting for the test, and THAT got labeled anti-phishing... So it's the language that is key, understanding that the tactics are different from the intention, and that you are consistently miscategorizing email across the board. Simply because Safe Links is something you want people to use doesn't mean it's something they have to use, and by blocking everything except those and disallowing access to fix the problem at the tenant level, you've created an incredibly intrusive system that's blocking the service people are paying you for. They aren't paying you to filter their mail, they're paying you to deliver it and are relying on other vendors or methods to eliminate those they don't want.
Just bring back Junk Mail already....