Forum Discussion

Robert Woods's avatar
Robert Woods
Steel Contributor
Oct 11, 2016

Advanced threat protection - Whitelist Users/Internal Mail Servers?

Greetings, 

Since implementing advanced threat protection we have recieved many complaints from end users across the organizaton that use a printer to scan a file in and email it to themselves. After looking at the Safe Attachements Policy it seems there is no way to whitelist a sender, or set a safe senders list. Is this something that is being considered for future addition?

 

Victor_Ungureanu

 

 
  • Hi Robert,

     

    Please check this out:

    https://office365.uservoice.com/forums/289138-compliance-protection/suggestions/9292590-advanced-threat-protection-whitelist

     

    For simplicity, I'll also quote the answer from there:

    "We believe that most of the widespread performance issues with ATP have been addressed. That said, we have even more features scheduled that will allow you the flexibility to decide what to do when it takes too long.

    In the meantime, you may also consider creating an Exchange Transport Rule that adds the header X-MS-Exchange-Organization-SkipSafeAttachmentProcessing to value of 1.

    Just be careful with any such rules, as it will essentially disable ATP safe attachment scanning for rules which meet the criteria."

    • Robert Woods's avatar
      Robert Woods
      Steel Contributor

      Hello Victor,

      I did find that thread and implemented the workaround. Thanks for the reference. Is this something you plan on building into the ATP Settings Page any time?

       

      • Victor_Ungureanu's avatar
        Victor_Ungureanu
        Icon for Microsoft rankMicrosoft
        I'm not aware of such a plan and, even if it exists, I don't think that's a priority because there is this possibility to use a transport rule.

        I'm guessing that the delay in receiving the emails is the reason for which you would like to be able to exclude some senders from scanning. I know that it's not a good solution for your scenario, but there is a new feature called Dynamic Delivery for Safe Attachments (https://blogs.office.com/2016/01/14/leading-the-way-in-the-fight-against-dangerous-email-threats/) which was designed exactly for this purpose, to mitigate the impact of the delayed delivery, so there were some investments done in this area.

Resources